Palenda Legal

Privacy Policy

Effective July 24, 2026 · Last updated July 24, 2026

The short version

  • Your workspace content is yours. We do not sell it, rent it, or share it with advertisers.
  • We do not use your workspace content to train artificial intelligence or machine-learning models.
  • We do not run third-party advertising or behavioral tracking in Palenda.
  • Palenda works local-first. You can use it without cloud sync, encrypt your cloud data end-to-end, and export a complete backup at any time.
  • You can permanently delete your workspace and your entire account yourself, from Settings.

This summary is provided for convenience. The full policy below governs.

1.Who we are

Palenda is a planning and project-management web application operated from Lawrence, Kansas, United States (“Palenda,” “we,” “us”).

For privacy questions, requests, or complaints: support@palenda.net

2.Scope

This policy describes how we handle information when you use the Palenda web application and the palenda.net website (together, the “Service”). It does not apply to third-party websites or services you may reach through links in the Service.

3.Information we process

Depending on how you use the Service, we process:

  • Account information. Your email address, authentication identifiers, and basic profile details you choose to provide.
  • Workspace content. The material you create in Palenda: categories, projects, phases, tasks, todos, notes, focus sessions, habits, and settings.
  • Operational data. Timestamps, sync metadata, and reliability and security logs generated in the course of running the Service.
  • Backup files. JSON backup files you export from, or import into, the Service.

We do not intentionally collect special categories of personal data (such as health, biometric, or financial information). Workspace content is free-form, so please do not enter information you would not want stored on our infrastructure.

4.How we use information

We process information in order to:

  • provide the Service, including account authentication and cross-device sync;
  • operate backup, import, and recovery workflows at your direction;
  • maintain reliability, diagnose faults, and prevent abuse and unauthorized access;
  • communicate with you about your account, security matters, and material changes to the Service;
  • comply with legal obligations.

Where the General Data Protection Regulation or a comparable law applies, our legal bases are: performance of a contract (delivering the Service you have requested); legitimate interests (reliability, security, abuse prevention, and product operations); consent, where required; and compliance with legal obligations.

5.What we do not do

  • We do not sell or rent your personal information or workspace content.
  • We do not use your workspace content to train artificial intelligence or machine-learning models, and we do not provide it to third parties for that purpose.
  • We do not serve third-party advertising in the Service, and we do not permit third-party behavioral advertising trackers in it.
  • We do not access your workspace content except where strictly necessary to operate the Service, to respond to a support request you have made, to investigate a suspected violation of our Terms of Service or a security incident, or where required by law. If you enable end-to-end encryption (section 11), your content is encrypted on your device and we cannot read it at all.

6.How and where data is stored

Palenda is designed to be local-first. Your workspace is held in your browser's local storage, and synced to our cloud database when you are signed in.

We rely on the service providers listed on our Sub-processors page for hosting, authentication, database, and email infrastructure. That page identifies each provider, its role, and its processing locations, and we maintain it as our provider arrangements change.

We will give at least 30 days' notice on the Sub-processors page before adding a new provider that processes workspace content or account information. If you have provided an email address and have not opted out of service notices, we will also notify you by email.

We architect storage and sync around account-scoped data isolation, so that one signed-in user cannot access another user's cloud workspace.

7.Disclosure to others

We disclose personal information only:

  • to the service providers described in section 6, acting on our instructions and bound by confidentiality obligations;
  • where you direct us to, or otherwise consent;
  • to comply with applicable law, legal process, or an enforceable governmental request. Where we are permitted to do so, we will notify you before disclosing your information in response to such a request;
  • to establish, exercise, or defend legal claims, or to protect the rights, safety, or property of Palenda, our users, or the public;
  • in connection with a merger, acquisition, financing, or sale of assets, in which case we will give notice before your information becomes subject to a different privacy policy, and the acquiring party will be bound by commitments no less protective than those in this policy.

8.International processing

Our infrastructure providers may process and store data in the United States and in other regions where they operate. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection law may differ from that of your jurisdiction. Where required, we rely on appropriate transfer safeguards, including the European Commission's Standard Contractual Clauses.

9.Retention and deletion

Deleting your workspace. You can permanently delete your workspace at any time from Settings. Deleting a workspace removes its contents — projects, phases, tasks, todos, notes, focus sessions, habits, and settings — from our cloud database and from the local storage of the device on which you perform the deletion.

Deletion is permanent and cannot be undone. We cannot restore a deleted workspace, and we do not retain a copy for your benefit. Export a backup from Settings before deleting if you want to keep your data.

Deleting your account. You can permanently delete your entire account yourself, from Settings — this removes your login, your email address, and your data everywhere we hold it. You can also ask us to do it for you by contacting support@palenda.net; we will complete the deletion within 30 days and confirm by email when it is done.

What deletion does not reach. Deleting a workspace or account does not remove:

  • Local copies stored in the browser of any other device where you have used Palenda. Clear that browser's site data to remove them.
  • Backup files you have previously exported. Those are yours to manage.
  • Encrypted infrastructure backups held by our hosting providers, which are retained for up to 30 days as part of routine disaster recovery and are then overwritten in the ordinary course. These backups are not accessible to us for individual record retrieval and are not used to restore deleted workspaces.
  • Operational and security logs, which contain limited metadata rather than workspace content and are retained for up to 90 days.
  • Records we are required to keep by law, which we retain only for as long as that obligation applies.

Retention while your account is active. We retain your cloud workspace data for as long as your account exists. We may delete inactive accounts and their contents after 24 months of no sign-in activity, after giving you at least 30 days' notice by email to the address on file.

10.Your choices and rights

Available to everyone:

  • Use Palenda in local-first mode without cloud sync, and manage your own backups.
  • Export a complete workspace backup from Settings, in JSON format.
  • Import a backup, with overwrite confirmation and schema validation.
  • Delete your workspace or your entire account from Settings.

Depending on where you live, you may also have the right to access the personal information we hold about you; to correct inaccurate information; to request deletion; to obtain a portable copy; to object to or restrict certain processing; and to withdraw consent where processing is based on consent.

To exercise any of these rights, contact support@palenda.net. We will respond within 30 days, or within any shorter period required by applicable law. We may need to verify your identity before acting, and we will not discriminate against you for exercising a privacy right.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

11.Security

We apply reasonable technical and organizational safeguards appropriate to the nature of the Service, including HTTPS transport encryption, encryption of data at rest by our infrastructure providers, account-scoped access controls, and the managed security controls of the providers listed on our Sub-processors page.

Optional end-to-end encryption. You can enable end-to-end encryption for your cloud workspace from Settings. When it is on, your workspace content is encrypted on your device with a key derived from your passphrase before it is synced, so it is stored as ciphertext that we cannot read. Keep your passphrase safe: because we never receive it, we cannot recover your data if you lose it.

No online service can be guaranteed to be perfectly secure, and we do not warrant that the Service will be free from unauthorized access. You are responsible for maintaining the confidentiality of your account credentials and for using a strong, unique password.

Breach notification. If we become aware of a security breach affecting your personal information, we will notify you without undue delay, and in any event within 72 hours of becoming aware of it where we are required to do so by applicable law. The notification will describe what we know about the incident, the categories of information involved, the steps we are taking, and what you can do.

12.Beta status and continuity

The Service is currently offered as a beta. It may change, be interrupted, or be discontinued. Your ability to export a complete backup at any time is a permanent feature of the Service, and we encourage you to use it regularly.

If we decide to discontinue the Service, we will give you at least 30 days' notice by email and on palenda.net, during which you will be able to export your data. This commitment does not create an obligation to continue operating the Service.

13.Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us with personal information, contact support@palenda.net and we will delete it.

14.Changes to this policy

We may revise this policy as the Service and our legal obligations evolve. The “Last updated” date at the top will reflect any revision.

If we make a material change — one that meaningfully reduces your rights or expands how we use your information — we will give at least 30 days' notice by email to the address associated with your account, and by notice in the Service, before the change takes effect. Continuing to use the Service after that date constitutes acceptance of the revised policy.

15.Contact

support@palenda.net
Lawrence, Kansas, United States

See also our Terms of Service and our Sub-processors page.