We respect your privacy. This policy explains clearly what data we collect, why we collect it, and how you can control it. We do not sell your personal data.
1. Who We Are
happen ("we", "us", or "our") is a personal productivity application that helps you manage tasks, schedule your day, and organise your goals. References to "the Service" mean the happen web application available at this domain.
For privacy enquiries, contact us at: privacy@happen.app
2. Information We Collect
2.1 Information you provide
- Account information: your email address and a hashed password when you register for an account.
- Task and productivity data: tasks, categories, hat labels, timebox schedules, loose threads, and any other content you enter into the Service.
- Payment information: if you subscribe to a paid plan, your payment is processed by Stripe. We do not receive or store your full card number — we only store your Stripe customer ID and subscription status.
2.2 Information collected automatically
- Usage data: Pomodoro counts, analytics data you generate through the app (task completion rates, etc.), stored server-side and associated with your account.
- Log data: standard server logs including IP address, browser type, pages visited, and timestamps. Logs are retained for up to 90 days for security and debugging purposes.
- Cookies and local storage: we use a session cookie to keep you logged in (JWT token). No third-party advertising cookies are set by us.
2.3 Guest mode
If you use the app without registering ("guest mode"), all data is stored only in your browser's session storage and is permanently deleted when you close your browser tab. We do not receive or store guest data on our servers.
3. How We Use Your Information
- To create and manage your account.
- To provide, maintain, and improve the Service.
- To process payments and manage your subscription via Stripe.
- To enforce our Terms of Service and detect abuse.
- To respond to support requests you send us.
- To send transactional emails (account creation, password reset, subscription receipts). We do not send marketing emails without your explicit opt-in.
4. Legal Basis for Processing (GDPR)
If you are located in the UK or European Economic Area, we process your personal data under the following legal bases:
- Contract: processing necessary to deliver the Service you signed up for (account data, task data, payment processing).
- Legitimate interests: server logging and security monitoring to protect the Service.
- Legal obligation: retaining certain financial records as required by law.
- Consent: optional communications where you have opted in.
5. Data Sharing
We do not sell, trade, or rent your personal data. We share data only with:
- Stripe: payment processing. Governed by Stripe's Privacy Policy.
- Railway (hosting): our infrastructure provider. Your data resides on Railway servers. See Railway's Privacy Policy.
- Law enforcement: when required by valid legal process or to protect the safety of users or the public.
6. Data Retention
We retain your account and task data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance (typically up to 7 years for billing records).
7. Your Rights
Depending on your location, you may have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate data.
- Erasure ("right to be forgotten"): request deletion of your account and associated data.
- Portability: export your task data using the in-app export feature (CSV or JSON).
- Restriction: ask us to stop certain processing of your data.
- Objection: object to processing based on legitimate interests.
- Withdrawal of consent: where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, email privacy@happen.app. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
8. Cookies
We use the following cookies:
- Authentication cookie (essential): stores your JWT session token so you stay logged in. This is strictly necessary for the Service to function and cannot be disabled.
We do not use analytics cookies (e.g. Google Analytics), advertising cookies, or any other non-essential tracking technologies at this time. If this changes, we will update this policy and ask for your consent where required.
9. Security
We implement appropriate technical and organisational measures to protect your data, including:
- Passwords stored as salted hashes (never in plain text).
- HTTPS encryption for all data in transit.
- JWT tokens with a 30-day expiry for session management.
- Rate limiting on authentication endpoints to prevent brute-force attacks.
No system is 100% secure. If you discover a security vulnerability, please report it responsibly by emailing security@happen.app.
10. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. International Transfers
Your data may be processed in the United States (our infrastructure provider Railway is based there). Where required, we rely on appropriate safeguards such as standard contractual clauses to ensure your data is protected.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email (if you have an account) and update the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13. Contact Us
For any privacy-related questions or requests: