Privacy Policy
Last updated: May 21, 2026
Not Tomorrow (“we”, “us”, “our”) operates the web application at nottomorrow.app. This policy explains what data we collect, why, and who else touches it.
What we collect
Account information
When you sign up, we store your email address and a user ID. If you sign in with Google, we receive your name and email from Google — we don’t get your Google password.
App data
Everything you create inside Not Tomorrow — habits, tasks, projects, journal entries, focus sessions, and your settings. This is stored in our database so you can access it from any device.
Billing information
If you upgrade to Premium, payment is handled entirely by Lemon Squeezy (our merchant of record). We store a customer ID and subscription status so we know your plan. We never see or store your credit card number, bank details, or full billing address.
AI-generated content
If you use the AI project generation feature, the goal description you provide is sent to OpenRouter (which routes to the DeepSeek language model) to generate a project plan. We don’t store your prompts beyond the current session.
Custom backgrounds
If you set a custom background image, it’s stored only in your browser (local storage) and never uploaded to our servers or shared with anyone. It stays on your device.
Technical data
Standard server logs (IP address, browser type, timestamps) kept by our hosting provider Vercel. We don’t run behavioral analytics or track you across the web. If we add a privacy-respecting analytics tool in the future, we’ll update this policy first.
How we use your data
- Run the app — show your habits, projects, journal, and stats.
- Authenticate you — verify you are who you say you are.
- Process payments — determine your plan and enforce free-tier limits.
- Generate AI plans — send your goal description to the AI model and stream back a plan.
- Send transactional emails — password resets, email confirmations. No marketing emails unless you explicitly opt in.
That’s it. We don’t sell your data, run ads, or build profiles for third parties.
Who we share data with
We use a small number of services to run Not Tomorrow. Each only gets the data it needs:
| Service | What it gets | Why |
|---|---|---|
| Supabase | Account info, app data | Database and authentication |
| Name and email (OAuth sign-in only) | Authentication via Google Sign-In | |
| Vercel | Server logs, request metadata | Hosting and deployment |
| Lemon Squeezy | Email, customer/subscription IDs | Payment processing |
| OpenRouter / DeepSeek | AI prompt text (goal descriptions) | AI project plan generation |
We don’t share data with anyone else unless required by law.
Cookies and tracking
We use essential cookies only — session tokens to keep you logged in. No advertising cookies, no third-party trackers, no fingerprinting.
Your rights
- Export your data. Data export is coming soon. In the meantime, email us and we’ll send you a copy of your data.
- Delete your account. Email us at andreasjackson805@gmail.com and we’ll delete your account and all associated data within 30 days. Deletion is permanent.
- Cancel anytime. Manage your subscription through the customer portal in Settings. Cancellation takes effect at the end of your current billing period.
If you’re in the EU/EEA, you also have rights under GDPR (access, rectification, portability, erasure, restriction, objection). Email us and we’ll handle it.
Data storage and security
Your data is stored in a PostgreSQL database hosted by Supabase (cloud infrastructure in the US/EU). All connections use TLS encryption. Access to production systems is restricted to the app operator.
We follow reasonable security practices but no system is 100% secure. If we discover a breach that affects your data, we’ll notify you promptly.
Children
Not Tomorrow is not intended for anyone under 13. We don’t knowingly collect data from children. If you believe a child has created an account, contact us and we’ll remove it.
Changes to this policy
If we make material changes, we’ll update the date at the top and post a notice in the app. Continued use after changes means you accept the updated policy.
Contact
Questions or requests? Email andreasjackson805@gmail.com.