Privacy

Privacy policy.

How Edgethink collects, uses, discloses, and protects information when you use drifty.

On this page

Information we collect Optional device sync How we use information AI features & generated content Third-party services Data sharing & disclosure Planned team features Data retention Security International users Children's privacy Your privacy rights Changes Contact
Effective · September 13, 2026 Entity · Edgethink

Edgethink ("drifty", "we", "our", or "us") recognizes that your privacy is important. This Privacy Policy explains how we collect, use, disclose, and protect information when you access the drifty website, the drifty desktop application, or any related services (collectively, the "Platform").

By accessing or using the Platform, creating an account, signing in, downloading the app, or continuing through an account flow, you acknowledge the collection, use, and storage of information as described in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use the Platform.

If you have any questions, please contact support.

Information we collect

Account information

When you create an account, we may collect information such as:

  • Name
  • Email address
  • Password authentication data handled by our authentication provider
  • Authentication provider information (such as Google login details)

We use this information to create and manage your account, authenticate access, and communicate with you about the Platform.

When you sign in with Google, Google and our authentication provider may provide a Google account identifier, email address, name, and profile image. We use this basic identity data only to create, authenticate, secure, and display your drifty account. Basic Google sign-in does not by itself give drifty access to Gmail, Google Drive, Google Calendar, or other Google product content, and drifty does not use provider tokens from the basic sign-in flow to call those Google APIs.

Optional Google Calendar connection

If you choose to connect Google Calendar during a supported Google onboarding flow or later in Settings, drifty separately asks for permission to see events on Google calendars you own. You can decline this optional permission and continue using your drifty account.

The Mac app reads only your primary calendar for the date range needed to show calendar context in drifty. It requests a limited set of event fields: event identifiers, status, titles, start times, and end times. Calendar information is kept separate from your tracked activity and productivity totals.

The Calendar refresh credential is stored locally in the macOS Keychain. Calendar event data is processed in memory and is not written to drifty Cloud, Supabase, the local tracker database, PostHog or other analytics, Sentry, or AI provider requests.

Disconnecting Google Calendar in Settings deletes the Calendar credential and Calendar data held by drifty on that Mac and stops future Calendar API requests. It does not revoke the authorization recorded in your Google Account; you can revoke that authorization separately from your Google Account permissions.

Activity and usage data

drifty is a productivity and activity tracking platform. Depending on your settings and permissions, we may collect:

  • Application names
  • Window titles
  • Website domains
  • Website URLs and page titles available to the local Mac tracker when browser permissions allow
  • Derived content context, such as workspace, project, parent page, section heading, tag, status, or document metadata, when available through app permissions, local context, or supported integrations
  • Active application usage duration
  • Website usage duration
  • Timestamps and activity metadata
  • Productivity categorizations and labels
  • Device and operating system information
  • Interaction and feature usage data

We may also generate summaries, analytics, insights, categorizations, or productivity-related outputs based on this information.

drifty does not intentionally collect keystroke contents, passwords, secrets, API keys, raw document bodies, message bodies, OCR text, or screenshot text for activity classification. Raw Mac activity history is stored locally on your device by default, and the complete local timeline remains the source of truth.

Optional Device Sync Preview

The paid Device Sync Preview is separate from public sharing and is off by default. If you enable it for a signed-in account on a Mac, drifty copies raw activity segments into private, account-scoped sync storage so that the same account owner's Macs can merge their activity. You must enable sync separately on each Mac.

Synced activity rows are not used for a public profile, leaderboard, team, analytics, or other shared surface. Turning sync off does not change the local database's role as the source of truth. You can use the in-app device-sync controls to review, pause, or purge the remote copy.

Cookies and similar technologies

We may use cookies, local storage, analytics SDKs, and similar technologies to:

  • Maintain user sessions
  • Remember preferences
  • Improve Platform functionality
  • Measure usage and performance
  • Analyze user behavior and product adoption

Website analytics on drifty.so uses PostHog with limited browser storage for visitor and event measurement. Website session replay is disabled by default.

The production Mac app sends limited, named product events to PostHog using a dedicated random analytics install identifier. When a user is signed in, account-level active-user measurement uses a deterministic one-way digest of the Supabase account identifier so the same account can be counted across launches and devices. Desktop product analytics is enabled by default and can be disabled at any time in Settings → Privacy. Disabling it stops future desktop product analytics events and does not affect core app functionality.

Desktop product analytics may include one bounded summary for the previous completed calendar day measuring whether an eligible intervention occurred, whether the cat experience was enabled or attempted, intervention route and outcome counts, return within ten minutes, petting and dragging sessions, one-hour hides, and cat preference changes. The summary also includes its reporting date and measurement version. Each count is capped at 100 and an overflow flag indicates whether a cap was reached.

This desktop analytics path does not send the source account identifier, email address, name, Cloud device identifier, raw intervention or interaction ledger rows, app or site name, URL, window or page title, segment identifier, source activity timestamp, drift duration, raw interaction properties, or raw app, site, window, session, or timeline history. PostHog person-profile processing is disabled for these desktop events, and the project is configured to discard client IP data.

Account authentication, checkout, app preferences, and security features may also rely on cookies, local storage, or similar browser storage where needed.

You can modify your browser settings to manage cookies and storage, although some Platform features may not function properly without them.

How we use information

We may use collected information to:

  • Provide and maintain the Platform
  • Authenticate users and secure accounts
  • Generate productivity insights and analytics
  • Improve Platform performance and reliability
  • Develop and improve algorithms, AI systems, and machine learning features
  • Conduct internal research and product analysis
  • Monitor usage trends and user engagement
  • Detect abuse, fraud, or security issues
  • Communicate updates, announcements, and support information

We may use aggregated, anonymized, or de-identified data for analytics, benchmarking, research, and model improvement purposes.

We may also use certain user data to improve our internal algorithms and AI-powered features. However, we do not sell personal data to third parties.

AI features and generated content

The Platform may use AI models and automated systems to generate productivity summaries, categorizations, recommendations, or other outputs ("Generated Content").

For a product-level overview of AI classification, see AI time tracking.

You retain ownership of your data and Generated Content to the extent permitted by applicable law.

AI classification may transmit minimized activity fields, such as app name, domain or host, page or window title, duration, and optional sanitized work-profile context, to configured AI providers for that request. When additional context is needed to improve classification quality, drifty may include sanitized derived context such as workspace, project, parent page, section heading, tag, status, or short metadata hints after local filtering and redaction. The classification service is not designed to send or store raw prompts, full URLs, full local timeline rows, raw session history, local tracker databases, raw document or message bodies, OCR or screenshot text, passwords, secrets, API keys, or provider API keys.

We may process User Data and Generated Content to improve Platform functionality, recommendation quality, categorization accuracy, and related machine learning systems.

We do not permit third parties to use identifiable customer data for their own independent advertising purposes.

Third-party services

We use third-party infrastructure and service providers to operate the Platform. These providers may process information on our behalf. These services may include:

  • Supabase for authentication, account data, Edge Functions, database services, and private account-scoped raw activity segments when the paid Device Sync Preview is enabled
  • PostHog for website analytics and privacy-minimized, pseudonymous product analytics
  • Google services for Google sign-in, the optional local Google Calendar connection, and Google AI/Gemini classification providers
  • OpenRouter for AI model routing when configured for Cloud AI classification
  • Polar for paid subscription checkout and billing records
  • Resend for transactional email when configured
  • Cloudflare Turnstile for abuse prevention when enabled
  • GitHub Releases for public Mac app downloads and update metadata
  • Static hosting and content delivery providers for drifty.so

These third parties may collect or process information in accordance with their own privacy policies and terms.

Data sharing and disclosure

We do not sell personal information to data brokers or advertisers. We may disclose information:

  • To service providers and infrastructure partners that help operate the Platform
  • To comply with legal obligations or lawful requests
  • To protect our rights, users, systems, or security
  • In connection with a merger, acquisition, financing, restructuring, or sale of assets
  • With your consent or at your direction

Planned team and workspace features

drifty may introduce team or workspace functionality in the future. If such features are introduced, workspace administrators may be able to access organization-level productivity reports, aggregated analytics, and approved workspace data depending on role permissions.

Additional disclosures regarding workspace access and permissions may be provided when such features become available.

Data retention

We retain information for as long as reasonably necessary to provide the Platform, comply with legal obligations, resolve disputes, enforce agreements, and improve our services.

Local Mac tracker data remains on your device unless you delete it, export it, or choose a feature that intentionally shares or syncs data. If you enable the Device Sync Preview, the private account-scoped remote copy remains until you purge it through the in-app device-sync controls or the applicable account-deletion process. Pausing sync stops that feature from continuing to merge activity but does not replace the local database as the source of truth. Local intervention and cat-interaction measurement records are kept on the device and pruned toward a ceiling of 90 days or 10,000 records per ledger.

Our current PostHog plan retains desktop product analytics events and keeps them queryable for up to 7 years from collection. Disabling product analytics stops future transmission but does not retroactively delete previously sent events. Because most desktop events use an install-scoped identifier rather than the source account identifier, deleting a drifty account does not automatically delete those prior events. You may contact support@drifty.so about a deletion request, which we will process where the relevant analytics can be identified.

Cloud account, billing, profile, support, and opt-in aggregate data may be retained according to the purpose for which it was collected.

You may request deletion of your account by contacting support.

Security

We implement commercially reasonable administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, or destruction.

However, no method of electronic storage or transmission over the internet is completely secure, and we cannot guarantee absolute security.

International users

drifty operates globally. Your information may be transferred to and processed in countries other than your own, which may have different data protection laws.

Desktop product analytics

  • Recipient and location: PostHog, Inc., United States (US Cloud in Virginia)
  • Timing and method: by encrypted HTTPS when a named event occurs and, for the bounded cat-effect summary, at most once per reporting day
  • Information: the random analytics install identifier, limited app/build/platform metadata, allowlisted named events, and the bounded previous-day summary described above
  • Purpose: product quality, reliability, adoption, and feature-effect measurement
  • Analytics retention period: up to 7 years from collection under the current PostHog plan
  • How to refuse: disable product analytics in Settings → Privacy; core app functionality remains available

Children's privacy

The Platform is not directed toward children under the age required by applicable law in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law.

If you believe a child has provided personal information to us unlawfully, please contact us and we will take reasonable steps to remove such information.

Your privacy rights

Depending on your location, you may have rights under applicable privacy laws, including the right to:

  • Access personal information
  • Correct inaccurate information
  • Request deletion of personal information
  • Object to certain processing activities
  • Request data portability
  • Withdraw consent where applicable

To exercise these rights, contact support.

Changes to this privacy policy

We may update this Privacy Policy from time to time. If material changes are made, we may notify users through the Platform, by email, or by updating the Effective Date above.

Continued use of the Platform after changes become effective constitutes acceptance of the revised Privacy Policy.

Change history

  • September 13, 2026: Documented the paid Device Sync Preview and its controls, and corrected the desktop product analytics retention period to match the current PostHog plan of up to 7 years from collection.
  • September 2, 2026: Documented the optional Google Calendar connection, its limited read scope and event fields, local Keychain credential storage, local processing boundary, and disconnect behavior.
  • September 1, 2026: Clarified that desktop product analytics is enabled by default and can be disabled, documented the bounded previous-day cat-effect summary, its exclusions, retention, and PostHog processing location.
  • July 31, 2026: Published the previous version of this Privacy Policy.

Contact us

If you have any questions about this Privacy Policy or our data practices, please contact support.