Privacy Policy
Last updated: 12 August 2026
Last updated: 12 August 2026
This Privacy Policy explains how Ikkendo ("Service") collects, uses, shares, and protects personal data.
1. Controller and contact#
The controller of personal data for Ikkendo is:
Žarko Dukić, Belgrade, Serbia (individual / fizicko lice) Contact email: hello@ikkendo.app
If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.
2. Scope#
This Policy applies to personal data processed when you:
- create or use an Ikkendo account,
- use web app functionality,
- contact support,
- subscribe to paid plans,
- receive service communications.
3. Data we collect, purpose, and legal basis#
Where GDPR/UK GDPR applies, we rely on one or more legal bases below.
| Data category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account and identity data | email, hashed password / social auth identifier | account creation, login, identity management | performance of contract |
| User content | notes, tasks, goals, questions, optional attachments | core functionality, sync, backup, collaboration features | performance of contract |
| AI interaction data | prompts, selected workspace context sent for AI features, model outputs, AI usage metadata | provide AI features (for example research/assist), safety and abuse prevention, usage enforcement | performance of contract; legitimate interest |
| Subscription and billing metadata | plan type, status, payment provider customer/subscription IDs, invoices metadata | billing, fraud prevention, entitlement enforcement | performance of contract; legal obligation |
| Device and technical data | IP, device/browser metadata, logs, error events, security events | security, reliability, abuse prevention, diagnostics | legitimate interest |
| Communications data | support emails, bug reports, feedback | support delivery, dispute handling, product quality | performance of contract; legitimate interest |
| Marketing preferences | opt-in state | send product updates where allowed | consent |
We do not sell personal data. We do not use private note/task content for third-party advertising.
We collect limited first-party product usage events (such as first note created, first task created, 7-day retention, onboarding completion) to understand how Ikkendo is used and improve the product. This data is stored in our own database, is never sold, shared with third parties, or used for advertising. It is processed under legitimate interest (GDPR Art. 6(1)(f)) for product improvement purposes. You may request deletion of this data via hello@ikkendo.app.
4. How we use personal data#
We use personal data to:
- provide and maintain the Service,
- authenticate users and enforce access controls,
- process subscriptions, billing, and plan limits,
- monitor performance, detect abuse, and secure infrastructure,
- respond to support requests and legal obligations,
- send service notices and (if opted in) product updates.
5. Processors and recipients#
We share data only when necessary, including with processors acting on our instructions:
- infrastructure and database provider (for example Supabase),
- hosting and website analytics — Vercel — hosting, CDN delivery, and Vercel Web Analytics for site traffic measurement,
- payment provider and Merchant of Record — Lemon Squeezy — which handles checkout, subscription billing, taxes, invoicing, and refund processing,
- AI model/API providers used to deliver AI features,
- transactional email and operational tooling providers,
- legal/compliance recipients when required by law.
We require processors to implement appropriate security and confidentiality obligations.
5.1 AI processing specifics#
When you use AI features, relevant inputs may be sent to third-party AI providers to generate responses.
Depending on the feature, this may include:
- your prompt/instruction,
- selected workspace context needed to answer the request,
- technical and usage metadata required for safety, abuse prevention, and quota enforcement,
- generated output returned to your workspace.
AI providers process this data under their own infrastructure and may store limited logs for reliability, security, abuse prevention, and legal compliance, subject to their contractual commitments with us.
You should avoid submitting unnecessary sensitive personal data to AI features unless required for your intended workflow. You should also avoid submitting confidential third-party data unless you have a valid legal basis and authorization to do so.
6. International transfers#
Some providers may process data outside your country, including outside the EEA/UK. When required, we rely on approved safeguards such as:
- adequacy decisions,
- Standard Contractual Clauses (SCCs),
- other lawful transfer mechanisms.
You may request additional information about transfer safeguards via contact email.
7. Retention#
We retain data only as long as needed for the purposes above:
- Account and content data: for the account lifetime, then deleted or anonymized within a reasonable period after valid deletion request, unless retention is legally required.
- Billing and accounting records: retained for mandatory accounting/tax/legal periods.
- Security and technical logs: retained for limited operational/security windows unless longer retention is required for incident investigation or legal defense.
- Support communications: retained as needed for support continuity and legal protection.
8. Security measures#
We apply organizational and technical measures, including:
- encryption in transit (HTTPS),
- access controls and account isolation (including row-level access constraints where applicable),
- least-privilege handling of infrastructure credentials,
- logging and monitoring for security events,
- optional local encryption/passcode features on supported clients.
No method of transmission or storage is 100% secure, but we continuously improve protections.
9. Your rights#
Depending on your jurisdiction (especially EEA/UK), you may have rights to:
- access,
- rectification,
- erasure,
- restriction,
- portability,
- objection (where processing is based on legitimate interest),
- withdrawal of consent (for consent-based processing),
- lodge a complaint with a supervisory authority.
To exercise rights, contact: hello@ikkendo.app. We may request identity verification before fulfilling requests. Where required by law, we respond to valid rights requests within applicable legal deadlines.
10. Cookies and similar technologies#
The Service uses essential cookies and/or local storage for:
- authentication/session handling,
- security and abuse prevention,
- core preferences and app functionality.
Your authentication session is stored in your browser's local storage (not as an HTTP cookie) and is strictly necessary for you to remain signed in.
We do not use third-party advertising cookies for profiling. If non-essential cookies are introduced, consent mechanisms will be implemented where legally required.
Website Analytics#
We use Vercel Web Analytics on this website (ikkendo.app) to understand site traffic and improve our content. Vercel Web Analytics is cookieless: it does not use cookies, browser storage, or cross-site identifiers. Visitor identification is based on a temporary hash generated from request metadata (such as IP address and user agent), which is discarded after 24 hours. Data collected includes page views, referrer, approximate geographic location (country/city), device type, browser, and operating system, presented to us only as aggregated statistics.
Because Vercel Web Analytics does not use cookies or browser storage, it does not fall under the cookie consent policy described elsewhere in this document, which applies specifically to non-essential cookies.
Vercel Inc. (United States) acts as a data processor for this website analytics data. Data may be transferred to and processed in the United States under Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework. For more information, see Vercel's Privacy Notice.
This section applies to website (landing) analytics only, and is separate from the first-party product usage analytics described elsewhere in this policy, which relates to your use of the Ikkendo application itself.
11. Children's data#
The Service is not directed to children under the minimum age required by applicable law to provide valid consent for data processing in your jurisdiction. If you believe a child provided personal data unlawfully, contact us for removal.
12. Changes to this Policy#
We may update this Policy from time to time. For material changes, we will provide reasonable notice (for example in-app and/or by email). The "Last updated" date indicates the latest revision.
13. Contact#
Privacy requests and questions: hello@ikkendo.app