PRIVACY NOTICE · UPDATED SEPTEMBER 11, 2026

Clear about your information.

This notice covers the ON ITT! private-beta app and planning services, getonitt.com, its original landing-page address, invitations, feedback and support.

Who to contact

ON ITT! is operated by Luke Crane, an individual based in Los Angeles, California, United States. For privacy questions or requests, email hello@getonitt.com. Please don’t include sensitive task contents, passwords or sign-in codes.

The short version

  • Your plan is stored on your device and, when you use Apple-device sync, in iCloud.
  • AI planning is optional and sends your input and relevant planning context through our service to OpenAI. It is not entirely on-device.
  • Voice transcription, AI planning and approving changes are separate steps.
  • Signing out, uninstalling, completing a task and deleting an account are different actions. Separate copies can remain.

Your account and saved plan

Supabase processes your email, account identifier, verification and beta-approval status, sessions and security records. Brevo delivers sign-in codes. Per-account request counters help prevent abuse. These services are not the task-sync database. Your ON ITT! login and your Apple Account are separate identities.

The app stores tasks, notes, dates, times, completion and repeat settings, tags, projects, areas, lists, preferences, drafts and recovery information. Completed work can remain in Logbook. Removing an item from a visible list does not necessarily remove recovery or synchronization records immediately.

Native sign-in credentials use protected device storage; the browser version uses browser storage. Protect access to your devices and invited email.

Voice and AI planning

The app asks before the first AI planning request. Declining leaves manual task entry available. You can revoke AI permission in Settings; this stops future requests until you agree again, but does not recall information already processed.

Planning requests can include your spoken or typed input, a limited selection of existing tasks and their dates, times, completion, repeat settings, tags and project associations, a proposed plan, project outcome or notes, preferences and relevant connected-calendar context. OpenAI receives this information through our hosted service to interpret your request and propose a plan or change.

The native app uses Apple speech recognition and does not require recognition to stay entirely on-device. Apple may process speech remotely depending on the service and device. Where browser voice is available, recorded audio goes through our Expo-hosted service to OpenAI for transcription. Typed AI requests send text and context without needing microphone access.

Our planning implementation requests that responses not be stored for later API retrieval. This is not zero retention: provider safety processing and hosting logs may still apply. See OpenAI’s API data controls. We do not promise that all processing stays on your device or that no provider retains information.

Review AI proposals before applying them. Avoid unnecessary sensitive information, passwords, payment credentials and information you do not have permission to share.

Calendar, sync, notifications and widgets

Calendar access is optional. Connected events help display commitments and plan around them; relevant titles and timing can be included in AI context when you allow planning. Approved timed tasks can be written to your chosen calendar. Disconnecting does not automatically delete events already written to an external calendar.

Apple-device sync stores plan information and sync metadata through iCloud, associated with your ON ITT! account and Apple Account. Use the same invited email and Apple Account for devices that should share a plan. Offline devices and older installations can retain separate copies until they reconnect.

Widgets receive a device-shared task snapshot. Notifications and widgets can expose task information to someone who sees your screen; manage their visibility in device settings. Cached widgets may not update immediately. Signing out or withdrawing beta access is not a remote wipe. The current beta allows limited offline access following an online access check, with a 24-hour access window.

When you request the beta

The signup service stores your email address, signup source and time, approval status, email preferences, and message status. These records let Luke manage invitations, honor opt-outs, and avoid sending the same message twice.

Abuse protection uses a changing hash derived from the request’s IP address and the current hour, plus request counters. The signup database does not save the raw IP address in your signup record. Hosting providers may separately process connection and security logs.

Emails and your choices

A new signup triggers a confirmation. Approval triggers an invitation. One optional check-in is scheduled about three days after the invitation only if you selected it. The email sequence does not use app first-open activity to decide when to send that check-in.

The preference link in each message lets you stop optional beta emails or leave the beta email list. Opening the link alone does not change your preference; you confirm on the page. Unsubscribing does not automatically erase the signup or the record needed to honor your choice.

Brevo processes recipient addresses, email contents, scheduling, delivery status, and related email-service data. Replies and support messages are handled in Luke’s mailboxes, including Google Workspace. Existing emails may still point to the earlier reply address or website; those links remain valid. Apple manages TestFlight invitations and notifications separately.

Email-service data can include opens and link clicks. Brevo’s tracking anonymization is not enabled, so do not assume these events are anonymous. Transactional email logs are configured for one-month retention and new message previews are not stored. Previously stored previews and provider backups may have different lifetimes.

Beta feedback and technical events

The app keeps a short local troubleshooting history. Voice diagnostics can include permission states, operating-system version, device class, build and error categories or numeric codes. Shared reports can also include task count and diagnostic preferences. These records are designed to exclude recordings, transcripts, task titles, notes and calendar contents. Review reports and screenshots before sharing.

Build 46 pauses automatic beta-event uploads, even if a prior diagnostic preference remains enabled. Explicitly submitted feedback is separate. Other supported builds may send the limited events described below. This notice does not represent that all testers send Sentry crash reports; Apple may separately collect TestFlight diagnostics under its own settings.

The site also receives technical events from supported beta builds: for example, a plan started or approved, an Undo, a voice error, or return usage. Records include an installation hash, event name, limited technical detail, device platform, app version/build, and timestamps. The event format does not request task titles, notes, transcripts, or calendar contents.

If you submit written feedback, we also receive the rating and comment you choose to send. Please leave personal task details out. These records help identify usability and reliability problems. The current service does not join an installation hash to your waitlist email address; hashed identifiers should not be treated as a guarantee of anonymity.

Supported builds provide analytics controls and deletion in Settings → Privacy. If you cannot find the control, contact Luke. Deleting diagnostic history is separate from leaving the email list.

Services and retention

The website runs on Sites hosting with Cloudflare infrastructure; Expo hosts app services, Supabase supplies authentication, Brevo provides automated email, Google Workspace handles support, OpenAI supplies AI processing and Apple supplies device services and iCloud. Providers process information needed for those services and their security, including connection and request metadata. They may process information outside your country; we do not promise US-only processing.

The beta currently keeps signup, preference, message-status, and diagnostic records without an automatic age-based deletion schedule. You can ask Luke to review or delete records associated with your request. We may need to verify the request, and service-provider logs or backups can have separate retention periods.

OpenAI privacy · Cloudflare privacy · Brevo privacy · Google privacy · Apple privacy

Your choices and deletion

You can decline AI, manage device permissions, change diagnostic preferences and stop optional emails. These choices affect different services. A local diagnostic clear does not necessarily remove a previously submitted report, and an email opt-out is not account deletion.

The current beta’s Delete all data control clears active tasks/projects and designated local records and queues sync changes. It is not a complete sign-in-account deletion service or a verified wipe of every older cloud copy. For account or broader data deletion, contact hello@getonitt.com. We may need to verify ownership and identify the records involved. Do not send passwords or sign-in codes.

Other devices need to reconnect for sync changes. External calendar events, exported files and other people’s copies may require separate action. We will explain any pending steps or information that must be retained for applicable legal obligations. We do not promise instant erasure of all backups.

Backups and security

Exported backups are readable JSON files, not password-encrypted by ON ITT!. Native exports and imports can leave app-cache copies. Protect your exports and remove copies you no longer need. The beta account database does not currently include scheduled project backups; this is separate from your iCloud plan copies.

No device, service or backup is completely secure. We do not promise end-to-end encryption or zero provider access. We may disclose information to comply with law, address fraud or security threats, or protect legal rights, subject to applicable law. A business transfer would be subject to applicable notice and safeguards.

Rights, age eligibility and changes

You can request access, correction, export or deletion of your information. Depending on your location and applicable law, additional rights may include objection, restriction, withdrawal of consent or a complaint to a regulator. Contact us to make a request; mandatory rights are not waived.

ON ITT! is intended for adults aged 18 and over. If you believe a child has supplied personal information, contact us so we can investigate. This does not mean existing testers have been age-verified.

We will update this notice when practices change and give notice or seek consent where required. Publication does not itself change the permissions or disclosures in an installed app. This update expands the earlier website notice to explain current app processing; it does not authorize new uses of your information.