1. Who operates Naremis

Naremis operates the Naremis daily to-do list at naremis.com. Questions and privacy requests can be sent to support@naremis.com.

2. This Device mode

When you use Naremis without signing in, tasks, dates, task outcomes, ordering information, and notebook preferences are stored in the browser on your device using IndexedDB, cookies, local storage, session storage, and service-worker caches as appropriate.

Naremis does not receive the content of a local-only notebook. It cannot recover local-only data after you clear browser storage, lose the device, remove the browser profile, or otherwise delete the local database.

3. Synchronized data

If you enable Sync, Naremis stores the content and structure needed to synchronize your notebook: task text, task dates, outcomes, order, history links, operation and revision identifiers, synchronization cursors, account preferences, and conflict records. Each supported client continues to keep a local copy for responsive and offline use.

Sync is not end-to-end encrypted. Naremis and its infrastructure processors must be able to store and process synchronized content to provide the service. Data is protected in transit and by the security controls of the service and its processors.

4. Google identity

Naremis uses Google OAuth through Supabase Auth when you choose Sync. Google provides identity information such as your email address, display name, profile image, and a provider account identifier. Naremis uses this information to authenticate and show the synchronized account.

Your task text is not sent to Google. Google sign-in is used for identity, not for storing or analyzing notebook content.

5. Service providers

Naremis uses Supabase for authentication, synchronized Postgres storage, and related account infrastructure; Vercel for website and application hosting, delivery, and operational logs; and Google Analytics 4 only after explicit analytics consent. These providers may process information in countries other than yours under their own safeguards and contractual commitments.

6. Analytics and consent

If you allow analytics, Naremis uses Google Analytics 4 to measure page views and coarse interactions such as opening the app, creating or completing a task, beginning or completing Sync, and changing appearance. Advertising features, Google Signals, cross-domain linking, and User-ID are disabled.

Naremis does not send task text, text length, task dates, selected dates, email addresses, display names, Google or Supabase identifiers, conflict content, error messages, or URL query strings to analytics. App views with a date query are reported only as /app.

Google Analytics is not loaded and Google is not contacted by Naremis analytics before you allow it. You can decline or later change the choice through Cookie settings. See the Cookie and Analytics Policy.

7. Essential browser storage

Naremis uses browser storage needed to remember authentication, consent, appearance, the local notebook, synchronization work waiting to be sent, and offline application files. Essential storage is used even if analytics is declined because the application cannot provide these functions without it.

8. Security and operational logs

Naremis and its hosting providers may record IP address, request time, route, device or browser characteristics, response status, authentication and rate-limit results, and security events. These logs support abuse prevention, debugging, availability, and protection of user accounts. They are not intended to contain task text.

9. Retention

Local-only information remains until you or the browser removes it. Synchronized notebook data remains while the account is active and for the time reasonably needed to complete a verified deletion request, backups, fraud prevention, dispute handling, and legal obligations. Security logs and limited account records may be retained for a proportionate period after content deletion. Analytics event retention is configured for two months.

10. Your controls

  • Use This Device without an account.
  • Decline or revoke optional analytics.
  • Remove local notebook data from the browser.
  • Sign out of Sync.
  • Request access, correction, export, or deletion of synchronized account information by contacting support.

Some rights depend on where you live. Naremis may need to verify your identity before acting on an account request.

11. Deletion

For local-only data, use the browser’s site-data settings for naremis.com. This is immediate from the selected browser and cannot be reversed by Naremis.

To delete a synchronized account, email support@naremis.com from the associated sign-in address. Naremis will verify the request and remove synchronized content, subject to limited backup, security, and legal retention.

12. Children

Naremis is not directed to children under 13, and people under 13 may not use the service. If you believe a child under 13 has provided account information, contact support.

13. Changes to this policy

Naremis may update this policy as the service or legal requirements change. The effective date will change after substantive revisions, and material changes may be announced in the service where appropriate.

14. Contact

Privacy questions and requests: support@naremis.com.