Last updated 16 August 2026
Privacy
Inora needs to know a lot about your week to schedule it. This page explains exactly what that means — what's stored, what leaves our servers, and what you can get rid of.
⚠ Placeholder — not yet in effect
This privacy policy is a working draft written to describe what Inora actually does today. It has not been reviewed by a lawyer and is not a binding agreement. Don't rely on it. Inora is currently in beta and a reviewed version will replace this page before Inora is generally available, if anything here matters to you in the meantime, please get in touch.
01What we collect
Account details. Your name, email address, and a hashed password. If you sign in with Google we receive your name, email, and profile picture instead. We also capture your time zone at sign-up, because every “today” in your schedule is computed in it.
Your life. The commitments you enter during onboarding and afterwards: classes, work shifts, gym sessions, sports, commutes, sleep times, and any recurring or one-off commitments. This is the raw material the scheduler works from.
Your goals. Project descriptions, deadlines, and any files you upload — course syllabi in particular. Plus the tasks Inora generates from them and the progress you record against each one.
Billing. Subscription status and period. Card details go to Stripe and never touch our servers.
02What we do with it
Build your schedule, and rebuild it when something changes. That is the whole purpose. Your commitments define when you're unavailable; your goals define what needs to fit in the gaps.
We also use your email to send account mail — verification, password resets, billing receipts. We do not send marketing email you didn't ask for, and we do not sell your data to anyone.
03Where your data goes
Inora relies on a small number of external services. These are the only places your data leaves our own infrastructure:
Anthropic — when you add a goal or upload a syllabus, the text of that goal or the contents of that file are sent to Anthropic's API so Claude can break it into tasks. This is the one place your project content is processed by a third party.
Stripe — payment details and billing history. We store only a customer reference and your subscription status.
Resend — delivers transactional email. Sees your email address and the message.
Google — only if you choose to sign in with Google or connect Google Calendar.
Google Cloud Platform — hosts the application and the database.
04Google Calendar
Connecting Google Calendar is entirely optional and Inora works without it. If you connect it, we store an encrypted access token and read your events so the scheduler can avoid them. We never write to, modify, or delete anything in your calendar. Disconnecting removes the token.
05Content safety
Goals are screened before they're planned. If something is flagged as harmful or illegal, the submitted text is recorded along with the reason so we can review the decision and correct it if the screen got it wrong. These records exist to resolve disputes, and are not used for anything else.
06How long we keep it
Your data stays for as long as your account does. When you delete your account it becomes inaccessible immediately and is permanently erased 14 days later. That window exists only so you can undo an accidental deletion — sign-in stays blocked throughout, and we email you a link to cancel if you ask for one.
Three exceptions. If our content-safety checks ever flagged something you submitted, we keep that record — what was submitted, why it was refused, and a one-way hash of your email address so we can find it if you contact us about it — for two years, then delete it. We also keep a permanent, minimal note of the deletion request itself: when it was made, the reason you picked from the list if you picked one, and that same one-way hash of your email — enough to show a deletion was asked for and honoured, and nothing more. Anything you typed in the optional comment box is discarded when the erasure runs. And deleted data survives in encrypted database backups for up to seven days before those age out; we do not use or restore it during that time.
Some billing records are kept longer where we're required to keep them. Those live with our payment processor, Stripe, under its own retention rules. You can request a copy of your data at any time and we'll provide it within 30 days.
07Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Depending on where you live you may have further rights under the GDPR, the CCPA, or equivalent law. Email us and we'll action it — we won't make you fight for it.
08Security
Traffic is encrypted in transit. Passwords are hashed, never stored in the clear. Third-party tokens are encrypted at rest. Sessions expire and can be revoked by signing out. No system is perfectly secure, and we won't pretend otherwise — if we ever discover a breach affecting your data, we will tell you.
09Cookies
Inora sets a cookie to keep you signed in and stores a small amount of preference data in your browser. There are no advertising or cross-site tracking cookies.
10Questions
Anything here that isn't clear, or anything you want removed: contact us.