Privacy policy
Last updated: 18 August 2026
Epitome is a tasks, calendar and planning app. This page explains what data we handle, why, where it lives, and — often the most telling part — what never leaves your phone.
1. Who handles your data
The data controller is Arthus Josephine, micro-entreprise (French sole trader) registered under number 108618067, with its registered office at 91 avenue de Toulon, 13005 MARSEILLE, FRANCE.
For any question about this policy or your data: contact@epitome-app.com.
2. What we process
| Data | Why | Legal basis |
|---|---|---|
| Email address | It is your account. We use it to send your one-time sign-in code — Epitome has no passwords. | Performance of a contract |
| The content you create tasks, lists, subtasks, due dates, time slots, planning profiles, reminders, events |
To sync it across your devices, and give it back to you if you change phone. | Performance of a contract |
| Addresses of calendars you attach the calendar URL, its name, its colour |
So your attached calendars follow you to your other devices. | Performance of a contract |
| Your subscription status state, plan, renewal date, order identifiers |
To know whether paid features are unlocked, on every one of your devices. | Contract · accounting obligation |
Calendar addresses deserve a warning. The secret address of a Google calendar is the key to that calendar: whoever holds it can read it. We store it on our servers so your devices can find it again. It grants read-only access to that one calendar, and you can revoke it at any time from Google Calendar.
3. What never leaves your phone
This is by design, not by omission:
- Your CalDAV credentials. If you attach a personal server — Nextcloud, Baïkal, SOGo — your username and password stay on the device where you entered them. They are never transmitted. That password belongs to an entire account: putting it on a server would betray the very reason people run their own. The cost is real: on a second device, you will have to enter them again.
- The contents of calendars you import. Events fetched from an external calendar are cached locally and never uploaded. Your work calendar does not end up on our servers.
- Your display preferences. Theme, accent colour, daily digest time, sorting and grouping. A dark screen on one phone has no business imposing itself elsewhere.
- Your payment details. We never see them. Payments are handled by Google Play; we only receive the subscription status.
4. What we do not do
- No advertising, and no ad networks.
- No behavioural analytics and no third-party trackers. The app ships with no tracking SDK.
- No selling or sharing of your data for commercial purposes.
- No profiling and no automated decision-making about you.
- No cookies on this website. It sets nothing and loads no external resources.
5. Crash reports
If the app closes unexpectedly, it writes the technical trace on your phone: class names and line numbers, never the content you wrote. That file goes nowhere on its own. Settings offer to email it to us, and nothing is sent without that action from you.
Google Play separately collects its own crash reports, according to your Android device settings.
6. Where your data lives, and who can reach it
We rely on the following processors:
| Processor | Role | Hosting |
|---|---|---|
| Supabase | Database, authentication, sending sign-in codes, application servers | European Union — Frankfurt, Germany |
| App distribution and payment processing (Google Play) | Per Google's terms |
Your application data is hosted in the European Union and does not leave it. Sign-in codes are currently sent by Supabase's built-in service; if we changed email provider, this page would be updated accordingly.
No other company has access to your data. We access it ourselves only where necessary to answer a support request from you or to fix a technical incident.
7. How long we keep it
- Your content and account: for as long as your account exists. Deleting it erases everything.
- Purchase records: kept for the period required by accounting and tax law, that is 10 years.
- Local data on your phone: erased when you sign out or uninstall the app.
8. Your rights
Under the General Data Protection Regulation you have the right to access, rectify, erase, restrict, object to and port your data. Write to contact@epitome-app.com and we will answer within one month.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority (CNIL), cnil.fr, or with your own country's supervisory authority.
Deleting your account
You can delete your account and everything in it from the app, under Settings → Account → Delete my account — it takes effect immediately. If you can no longer open the app, write to contact@epitome-app.com and we carry it out within 30 days. See the Delete my account page.
Deletion is permanent: the account and its data are erased from our systems, not merely disabled.
An active subscription is cancelled separately, through Google Play: deleting your Epitome account does not stop a recurring payment at Google.
9. Children
Epitome is intended for adults and is not directed at anyone under 15. We do not knowingly collect data about children. If you believe we have, write to us and we will erase it.
10. Changes
This policy may change alongside the app. The last-updated date appears at the top of this page, and any substantial change will be announced in the app or by email.
11. Contact
contact@epitome-app.com
Arthus Josephine — 91 avenue de Toulon, 13005 MARSEILLE, FRANCE