1. Who controls your data
LaterDone is operated by Sebastian Mraz, an independent developer based in Slovakia. For privacy questions or requests, email sebastianmraz@gmail.com.
2. Data we process
Account and device continuity
LaterDone creates an anonymous Supabase account. We process its user identifier, an app account token, entitlement status, and AI Token balances. The authentication session may be stored in iCloud Keychain so the same anonymous profile and server-side wallet can be available on your other Apple devices when iCloud Keychain is enabled.
Captures and generated content
Depending on what you choose to capture, we process text, URLs, readable webpage content, photos, screenshots, audio files, transcripts, generated action surfaces, checklist state, edits, reminder or calendar details, and source links. Do not submit information you do not have permission to process.
Purchases and usage
We process Apple product identifiers, signed transaction identifiers and verification results, subscription period information, token ledger entries, model usage, provider cost, and charge calculations. Apple handles your payment credentials; LaterDone does not receive your full card details.
Permissions
Camera, Photos, and Microphone access is requested only when you use those capture methods. Calendar and Reminders access is requested only when you confirm an action that writes to those apps. LaterDone does not upload your existing calendar or reminder database.
3. Why we process data
- Provide capture analysis, action surfaces, sync, editing, search, and account deletion.
- Transcribe voice captures and analyze selected media.
- Verify purchases, maintain balances, prevent duplicate grants, and provide support.
- Protect the service, investigate failures or abuse, and comply with legal obligations.
For users in the EEA, UK, and Switzerland, processing is based on performing the service you request, your consent for optional device permissions, legitimate interests in security and reliable operation, and legal obligations related to transactions.
4. Service providers and transfers
- Supabase provides anonymous authentication, database storage, private object storage, and Edge Functions. See the Supabase Privacy Policy and Data Processing Addendum.
- OpenAI processes capture content through its API to create structured results. OpenAI states that API inputs and outputs are not used to train its models by default. See OpenAI business data privacy.
- Apple provides StoreKit billing, TestFlight/App Store distribution, iCloud Keychain, and on-device permissions. See Apple Privacy.
These providers may process data outside your country. Their contractual and legal transfer safeguards apply where required.
5. Retention and security
Captures and generated surfaces are generally kept until you delete your data. Purchase records, token ledgers, security logs, and transaction verification records may be retained as needed to prevent fraud, resolve disputes, satisfy accounting or legal requirements, and protect the service. Provider logs and backups may persist for limited periods under provider policies and legal obligations.
LaterDone uses encrypted network connections, private storage, row-level access controls, server-side secret handling, and verified Apple transactions. No system can guarantee absolute security.
6. Your choices
- You control which capture methods and device permissions you use.
- You can edit, complete, archive, or delete captured content in the app.
- Delete My Data in Settings requests deletion of LaterDone captures and app account data.
- Deleting LaterDone data does not cancel an Apple subscription. Manage billing separately in Apple Subscriptions.
7. Privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, and to withdraw consent. You may also complain to your local data protection authority. California residents may request access, correction, or deletion and information about data practices. LaterDone does not sell or share personal information for cross-context behavioral advertising.
We may need enough information to verify that a request relates to the correct anonymous account.
8. Children
LaterDone is not directed to children under 13 or the higher minimum age required in their country. If you believe a child provided personal data without valid permission, contact us.
9. Changes
We may update this policy as LaterDone changes. The effective date at the top identifies the current version. Material changes will be communicated where required.
10. Contact
Email sebastianmraz@gmail.com with the subject “LaterDone Privacy Request.”