Legal
Privacy policy
How Onstead handles your data. Last updated 8 September 2026.
The short version. Onstead stores the information you choose to use for planning, focus, and personal wellness on your device and in your account. Supported records sync across devices. We do not sell your data or use it for advertising. Optional AI and voice features send the relevant content to processing providers. Support access is limited to operating the service and handling your requests.
Who this covers
Onstead (Onstead: Daily Planner & Focus) is operated by Nathan Horowitz under the name Horowitz Labs. This policy covers the web, iOS, and Android apps; feature availability differs by platform. Beta distribution may be restricted to selected testers. Questions go to nhorowitz@pm.me.
What Onstead stores
- Account details. Your email address and a password hash, handled by Supabase Auth, plus your account ID and the display name you provide. Passwords are not stored in plain text.
- Workspace data. Everything you type into Onstead: tasks, projects, notes, events, goals, transactions, contacts, decisions, bookmarks, media, prompts, and schedule blocks.
- Health data. If you turn on Health: workouts and sets, meals and macros, sleep, weight and measurements, progress photos, recovery sessions, injuries, symptoms, supplements and medications you record, blood panel values you enter, and your circadian profile.
- Photos. Meal photos and progress photos are stored in a private Supabase storage bucket, namespaced to your user id.
- An audit log. A timestamped record of actions taken in your own workspace, visible only to you.
Onstead does not use analytics, tracking pixels, advertising identifiers, or third-party cookies. The only cookies set are the session cookies Supabase needs to keep you signed in.
Where it lives
Signed-in web workspace records use your account database. Browser preferences and some companion tools use local storage, separated by account. Web commitments, scenarios, automation rules, and Vault records do not sync across devices; when cloud services are not configured, the local web workspace stays in that browser. The native apps keep supported records on the device and sync them with your account. The native apps also cache supported health records locally. Web health features require the cloud database. Network connections to Onstead and its processing services use HTTPS encryption in transit.
Cloud workspace tables use row-level security policies that associate records with your user ID and restrict access to the owning account. These access controls are separate from local copies and exports that you keep on your devices.
Orion, the AI assistant
When you use the assistant, a food photo, the program generator, or the lab explanation, the relevant content is sent to OpenRouter, which routes it to Google’s configured Gemini model. That includes whatever you typed, the page context Onstead attaches, and any file or image you attached.
The content sent depends on the feature and your request. Orion can include page context and workspace records retrieved by its tools. A lab explanation includes marker values and ranges; a training program can include your goals, equipment, and injuries. You can turn off automatic page context in Settings; information you send and records needed to answer a tool request may still be processed.
Model providers have their own retention policies, which Onstead does not control. Treat anything you send to the assistant as leaving your own database. If something is too sensitive for that, don’t put it in a prompt.
Other services
- Supabase: database, authentication, and file storage.
- Vercel: hosting. Vercel keeps standard server logs, which include IP addresses.
- OpenRouter and Google, AI processing as described above.
- Deepgram: audio transcription when you use voice input. Audio is sent through the Onstead backend to produce text.
- Apple and Google Play: app distribution and optional subscription payments. Onstead uses purchase status to enable subscribed features; store payment details are handled by the store.
- Web search, when you ask the assistant to search, your query goes to a search provider.
Mobile permissions and focus protection
With your consent, Android Health Connect and iOS Apple Health provide steps, sleep, and weight for your wellness logs and daily summaries. Android can use the step-counter sensor as a fallback. Supported health refreshes run periodically, subject to system permission. iOS can also write weight entries to Apple Health when authorized. You can revoke health permissions in device settings. Health data is not sold or used for advertising.
Android focus protection uses usage access and display-over-other-apps permission to recognize user-selected apps during enabled protection windows and show a pause screen. A foreground service supports this feature. Onstead stores selected package names, daily usage totals, bypass decisions, and device enforcement state for your focus history and cross-device settings. iOS uses its supported Screen Time controls. These features are user-configured; they do not collect web browsing history.
Contact import asks for contacts permission and saves the contacts you choose in your Onstead account. Voice input asks for microphone access; photos and other material you submit to supported AI features are processed for the requested response. Notifications and scheduled reminders use the permissions you grant. Optional features can be left off.
Onstead stores app-generated device identifiers and device model information to coordinate device settings. Hosting and authentication services process connection and security logs, including IP addresses, to operate and protect the service. Onstead does not embed an advertising or third-party analytics SDK.
Health data specifically
Health entries: including anything you record about medications, symptoms, or lab results: are treated as ordinary user data in your own database. These features are for personal wellness and planning, not for clinical care. Record what you’re comfortable recording.
Onstead is not a medical device. Nothing it displays or generates is medical advice, a diagnosis, or a treatment recommendation.
Your control
For Onstead on iOS, Android, and web: request account deletion or delete selected data while keeping your account. These pages explain the request process, device copies, and retention.
- Export. Settings offers a JSON export of supported workspace records. Web workspace exports do not include every health record or uploaded file; contact support if you need help obtaining additional account data.
- Delete. Clearing data in Settings removes the categories described by that action; it does not by itself delete your login or every cloud record. To delete your account and every row attached to it, email nhorowitz@pm.me and it will be removed.
- Correct. You can edit supported records in the app or contact support for help correcting account data.
Retention
Data is kept until you delete it or ask for your account to be removed. There is no automatic expiry. Backups may persist for a short window after deletion before rotating out.
Children
Onstead is not intended for anyone under 16 and is not knowingly offered to them.
Changes
If this policy changes in a way that affects how your data is handled, the change will be reflected on this page with an updated date. Material changes may also be announced in the changelog.
Questions about a record, a connected service, or a privacy request? Contact nhorowitz@pm.me. Never send passwords or verification codes.