Privacy Policy & Data Processing

Quick Overview

ImpactTracker.ai helps professionals track their work activities and outcomes. We take your privacy seriously and have implemented EU-compliant data protection measures.

Key Points:

  • • We process your activity data to provide AI insights
  • • Data is stored in EU-hosted infrastructure (Supabase)
  • • AI processing uses third-party services (OpenAI, US-based)
  • • You control your data - delete or export anytime
  • • We do not sell or share your personal data
What Data We Collect

Account Information

Email address for authentication and account management.

Activity Data

Work activities and outcomes you submit through our natural language input system. This includes descriptions of tasks, meetings, results, and metrics.

Usage Analytics

Basic usage statistics to improve our service (pages visited, features used, error logs).

How We Process Your Data

AI Analysis

Your activity descriptions are sent to OpenAI's API (US-based) for natural language processing and insight generation. We implement PII detection to minimize sensitive data exposure.

Data Storage

Data is stored in Supabase (EU-hosted PostgreSQL) with encryption at rest and row-level security ensuring you can only access your own data.

Sensitive Data Protection

We automatically detect and mask potentially sensitive information (emails, phone numbers, etc.) before processing. Description fields are encrypted in our database.

Third-Party Services
ServicePurposeLocationData Shared
SupabaseDatabase & AuthenticationEUAll user data
OpenAIAI ProcessingUSActivity descriptions (PII-filtered)
Vercel AnalyticsUsage Analytics & PerformanceUSAnonymous page views, performance metrics
Google FontsWeb TypographyUSIP address (for font delivery)

Cookie Usage & Consent

We use cookies and similar technologies to provide essential functionality and, with your consent, to analyze usage patterns. All cookies are categorized and managed according to GDPR requirements.

Essential Cookies

Required for authentication, security, and basic functionality. Cannot be disabled.

  • • Supabase authentication tokens
  • • Session management
  • • CSRF protection
  • • Cookie consent preferences
Analytics Cookies

Help us understand usage patterns. Requires your explicit consent.

  • • Vercel Analytics tracking
  • • Page view statistics
  • • Performance monitoring
  • • Error tracking
Functional Cookies

Enable enhanced features and personalization. Optional.

  • • User preferences
  • • UI customizations
  • • Enhanced security features
  • • Accessibility options
Your Cookie Rights
  • • You can accept or reject non-essential cookies
  • • Withdraw consent at any time through cookie settings
  • • Essential cookies cannot be disabled as they are necessary for website functionality
  • • Cookie preferences are remembered for up to 13 months

You can manage your cookie preferences at any time using the cookie settings section below.

Your Rights Under GDPR

Access

Request a copy of all your personal data

Rectification

Correct inaccurate personal data

Erasure

Delete your account and all associated data

Portability

Export your data in machine-readable format

Restriction

Limit how we process your data

Objection

Object to certain types of processing

Data Retention

Active Accounts

We retain your data as long as your account is active and for legitimate business purposes.

Account Deletion

When you delete your account, all personal data is permanently removed within 30 days, including from backups.

Legal Requirements

Some data may be retained longer if required by law or for legitimate interests (e.g., fraud prevention, legal claims).

Security Measures
  • • Encryption in transit (HTTPS) and at rest
  • • Row-level security ensuring data isolation
  • • PII detection and masking before external processing
  • • Regular security audits and monitoring
  • • EU-hosted infrastructure for GDPR compliance
  • • Access controls and authentication
Contact & Complaints

Data Protection Officer

For privacy-related questions or to exercise your rights:
Email: []
Response time: Within 30 days

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data properly.

Policy Updates

This privacy policy may be updated to reflect changes in our practices or legal requirements. We will notify users of material changes via email or through the application.

Last updated: 9/24/2025

Manage Your Cookie Preferences

Control which cookies and tracking technologies we use on your device. Your preferences will be saved and remembered for future visits.

Essential Cookies
Always Active

These cookies are strictly necessary for the website to function properly. They enable core functionality such as security, network management, and accessibility.

Authentication Cookies

  • • Supabase session tokens
  • • Login state management
  • • CSRF protection tokens

Security Cookies

  • • Cookie consent preferences
  • • Security headers
  • • Basic functionality
Analytics Cookies

These cookies help us understand how you interact with our website by collecting anonymous information about your visit, helping us improve our services.

Vercel Analytics

Collects anonymous page views, navigation patterns, and performance metrics.

  • • Page views and session duration
  • • Geographic location (country level)
  • • Device type and browser information
  • • Performance metrics and error tracking

Data retention: 90 days | Provider: Vercel Inc. (US) |Privacy Policy

Your Rights: You can opt out of analytics at any time. This will not affect the functionality of the website.

Functional Cookies

These cookies enable enhanced functionality and personalization. The website will function without them, but some features may not be available.

Enhanced Features

  • • User interface preferences (theme, language)
  • • Personalized dashboard settings
  • • Enhanced accessibility options
  • • Feature usage optimization

Data retention: 1 year or until withdrawn

Data Management

You can clear all stored cookie preferences and website data. This will remove all non-essential cookies and reset your preferences.

This action will reload the page and you'll need to set your preferences again.

Legal Basis for Processing

Essential cookies: Legitimate interest (necessary for website functionality)

Analytics cookies: Your explicit consent (GDPR Article 6(1)(a))

Functional cookies: Your explicit consent (GDPR Article 6(1)(a))

You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.