Privacy Policy

Last updated: August 31, 2026

Not Tomorrow (“we”, “us”, “our”) operates the web application at nottomorrow.app. This policy explains what data we collect, why, and who else touches it.

What we collect

Account information

When you sign up, we store your email address and a user ID. If you sign in with Google, we receive your name and email from Google — we don’t get your Google password.

App data

Everything you create inside Not Tomorrow — habits, tasks, projects, journal entries, focus sessions, and your settings. This is stored in our database so you can access it from any device.

Billing information

If you upgrade to Premium, payment is handled entirely by Lemon Squeezy (our merchant of record). We store a customer ID and subscription status so we know your plan. We never see or store your credit card number, bank details, or full billing address.

AI-generated content

If you use the AI project generation feature, the goal description you provide is sent to OpenRouter (which routes to the DeepSeek language model) to generate a project plan. We don’t store your prompts beyond the current session.

Custom backgrounds

If you set a custom background image, it’s stored only in your browser (local storage) and never uploaded to our servers or shared with anyone. It stays on your device.

Technical data

Standard server logs (IP address, browser type, timestamps) kept by our hosting provider Vercel.

Product analytics

We use PostHog to understand how the app is actually used — which pages get opened, which features get used, and where people drop off while signing up or upgrading. These events are linked to your user ID, so we can answer questions like “of the people who sign up, how many complete their first habit?”

PostHog sets a cookie in your browser so return visits aren’t counted as a new person each time. We use PostHog’s US-hosted service, so these events are processed in the United States.

This is analytics about your use of Not Tomorrow, and nothing else. We don’t run advertising pixels, we don’t track you across other websites, and we don’t sell or share this data with advertisers.

Where you came from

If you arrive from an ad, a shared link, or a search result, we record the campaign tags in that link (utm_source, utm_campaign, and similar), the ad click identifier some platforms append (such as fbclid or gclid), the site that referred you, and the page you landed on.

This is kept in your browser’s local storage on your first visit and saved to your account if you go on to sign up. We keep only the first one we ever see and never overwrite it. It tells us which channels actually bring people to Not Tomorrow so we know where to spend effort — it isn’t used to build a profile of you, and it isn’t shared with advertisers.

How we use your data

  1. Run the app — show your habits, projects, journal, and stats.
  2. Authenticate you — verify you are who you say you are.
  3. Process payments — determine your plan and enforce free-tier limits.
  4. Generate AI plans — send your goal description to the AI model and stream back a plan.
  5. Send transactional emails — password resets, email confirmations. No marketing emails unless you explicitly opt in.
  6. Improve the app — see which features get used and where signup or upgrade flows lose people, so we can fix them.

That’s it. We don’t sell your data, run ads, or build profiles for third parties.

Who we share data with

We use a small number of services to run Not Tomorrow. Each only gets the data it needs:

ServiceWhat it getsWhy
SupabaseAccount info, app dataDatabase and authentication
GoogleName and email (OAuth sign-in only)Authentication via Google Sign-In
VercelServer logs, request metadataHosting and deployment
Lemon SqueezyEmail, customer/subscription IDsPayment processing
OpenRouter / DeepSeekAI prompt text (goal descriptions)AI project plan generation
PostHogUser ID, pages visited, feature usage eventsProduct analytics (US-hosted)

We don’t share data with anyone else unless required by law.

Cookies and tracking

We use two kinds of cookies:

  • Essential — session tokens that keep you logged in. The app doesn’t work without them.
  • Analytics — a PostHog cookie that recognises your browser between visits, so one person visiting twice isn’t counted as two.

No advertising cookies, no cross-site tracking, no fingerprinting, and no selling your data.

Opting out: we honour your browser’s “Do Not Track” setting — turn it on and we won’t capture analytics events. Any standard tracker blocker will also stop them. Neither affects the app itself, which works exactly the same either way.

Your rights

  • Export your data. Data export is coming soon. In the meantime, email us and we’ll send you a copy of your data.
  • Delete your account. Email us at andreasjackson805@gmail.com and we’ll delete your account and all associated data within 30 days. Deletion is permanent.
  • Cancel anytime. Manage your subscription through the customer portal in Settings. Cancellation takes effect at the end of your current billing period.

If you’re in the EU/EEA, you also have rights under GDPR (access, rectification, portability, erasure, restriction, objection). Email us and we’ll handle it.

Data storage and security

Your data is stored in a PostgreSQL database hosted by Supabase (cloud infrastructure in the US/EU). All connections use TLS encryption. Access to production systems is restricted to the app operator.

We follow reasonable security practices but no system is 100% secure. If we discover a breach that affects your data, we’ll notify you promptly.

Children

Not Tomorrow is not intended for anyone under 13. We don’t knowingly collect data from children. If you believe a child has created an account, contact us and we’ll remove it.

Changes to this policy

If we make material changes, we’ll update the date at the top and post a notice in the app. Continued use after changes means you accept the updated policy.

Contact

Questions or requests? Email andreasjackson805@gmail.com.