Privacy policy
Last updated: 6 October 2026
The short version: we keep your email, your password (which we never see in readable form) and the tasks you add. We use them to run Izndo for you. We don’t sell them, we don’t advertise to you, and you can download or delete everything yourself.
1. Who we are
Soda Creative Studios Ltd (“Soda”, “we”, “us”) is the data controller for personal data handled through Izndo at app.izndo.com and the website at izndo.com. Soda is registered in England and Wales under company number 16573747, with its registered office at 3rd Floor, 86-90 Paul Street, London, EC2A 4NE. Contact us at [email protected].
2. What we collect and why
| What | Why we use it | Our lawful basis |
|---|---|---|
| Account details. Your email address and your password. The password is passed to our sign-in provider and stored there in hashed form. We can’t read it. | To create your account, sign you in, confirm your email and send password-reset links. | Contract (providing the Service you asked for) |
| Your content. Tasks, notes, client names, time entries, habits, workout logs and settings that you add. | To show your board, timer, timesheet and history back to you, and to keep them in step across your devices. | Contract |
| Assistant tokens. If you connect an assistant, we store a one-way hash of each token, its permission level and when it was made. | To check that a connection is allowed, and to let you revoke it. | Contract |
| Sign-in cookies. Two essential cookies that keep you signed in. | To keep you signed in securely. They are not used for tracking. | Strictly necessary (no consent needed) |
| Security counters. Short-lived counters linked to your IP address or a hash of your email address. | To limit repeated sign-in attempts and stop abuse. They expire automatically, usually within 15 minutes. | Legitimate interests (keeping the Service secure) |
| Messages you send us. Anything you email to us. | To reply and keep a record of the conversation. | Legitimate interests |
Our hosting provider also processes technical information such as IP addresses and request details to deliver and protect the site.
We don’t use advertising or cross-site tracking cookies, and we don’t build advertising profiles. The Izndo website and app don’t load third-party analytics or advertising scripts.
3. Who we share it with
We use a small number of providers to run Izndo. They process personal data only on our instructions, to provide their service:
- Cloudflare hosts the website and app, and stores your content and security counters.
- Supabase provides sign-in: it stores your email address and hashed password and sends account emails on our behalf.
- Our email sending provider, where we use one for account emails such as confirmations and password resets.
If you connect an AI assistant, the tasks it reads or changes are shared with that assistant’s provider because you asked it to. That provider is a separate controller under its own policy. We don’t sell personal data, and we don’t share it for advertising. We may disclose it if the law requires, or to protect our rights or others’ safety.
4. International transfers
Our providers may process data in the UK, the European Economic Area and other countries, including the United States. Where data leaves the UK, we rely on adequacy regulations or appropriate safeguards such as the UK International Data Transfer Addendum or standard contractual clauses.
5. How long we keep it
- While you have an account: we keep your account details and content so the Service works.
- When you delete your account: we permanently delete your content and assistant tokens straight away. We also remove your sign-in record. If that doesn’t happen automatically, email us and we’ll remove it.
- Security counters: they expire on their own, usually within 15 minutes.
- Emails you send us: we keep them for as long as needed to deal with your request and for reasonable business records.
- Backups held by our providers: these can persist for a short time after deletion before they are overwritten.
6. Your rights
Under UK data protection law you have the right to:
- be told what we hold about you and get a copy (you can download your data from your account page);
- have inaccurate data corrected;
- have your data deleted (you can delete your account yourself from the account page);
- restrict or object to some uses of your data, and receive your data in a portable format; and
- withdraw consent, where we rely on it.
To use any right, or if you have a question, email [email protected]. We’ll respond within one month. If you aren’t happy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk. We’d appreciate the chance to put things right first.
7. Security
Passwords are hashed by our sign-in provider. Sessions use secure, HttpOnly cookies, and each account’s data is kept separate from every other account’s. No online service can promise perfect security, but we take reasonable technical and organisational steps to protect your data, and we’ll tell you and the ICO about a breach where the law requires.
8. Children
Izndo is for people aged 18 and over. We don’t knowingly collect data from children. If you think a child has given us data, please contact us and we’ll delete it.
9. Changes
We may update this policy. We’ll post the new version here with a new date and, for changes that matter, tell you by email or in the app.