Legal
Privacy policy
Last updated 3 August 2026. Effective 3 August 2026.
Please read. This policy is written in good faith and in plain English. It is not legal advice. It should be reviewed by a qualified solicitor before launch, and checked against how the product actually behaves at the time you read it.
Easier Now helps you plan your day. To do that we handle some of your information. This page explains what we collect, why we collect it, who we share it with, and what you can ask us to do about it.
1. Who we are
Easier Now is a subscription productivity web app operated by Easier Agency (Anthony Stratton), based in the United Kingdom. In data protection terms we are the controller of the personal data described here.
Our marketing site is at website.easiernow.co and the app is at app.easiernow.co. You can reach us at any time on hello@easiernow.co.
In this policy, "we" and "us" mean Easier Now. "You" means the person using the service.
2. What we collect
Account data
Your name, email address, password (stored as a secure hash, never in plain text), your plan, your workspace or team membership if you have one, and your settings and preferences.
Your content
The things you put into the app. Tasks, projects, notes, time estimates, due dates, priorities, completion history, and anything else you type in. If you connect Google Calendar, this also includes the calendar events we read and write on your behalf.
Usage data
How the app is used. Pages and features opened, actions taken, timings, device and browser type, approximate location derived from your IP address, and error or crash reports. We use this to keep the service working and to make it better.
Payment metadata
Payments are processed by Stripe. We never see or store your full card number. Stripe gives us a customer reference, the last four digits and card brand, your billing country, your subscription status, your invoices and your renewal dates. That is what we hold.
Support and email
If you email us, or reply to one of our emails, we keep that correspondence so we can answer you and refer back to it later. We also record whether our service emails were delivered.
3. How we use it, and our lawful bases
Under UK GDPR and EU GDPR we need a lawful basis for everything we do with your data. Here is ours.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | So you can log in and use the app | Contract |
| Store and sync your tasks and plan | This is the core of the product | Contract |
| Take payment and manage your subscription | So we charge the right amount and honour refunds | Contract, and legal obligation for tax records |
| Send service emails (receipts, renewals, security notices) | You need to know what is happening with your account | Contract |
| Keep the service secure and prevent abuse | To protect you and us | Legitimate interests |
| Product and site analytics | To understand what works and fix what does not | Legitimate interests, and consent where cookies require it |
| Google Calendar sync | Only to provide the calendar feature you turned on | Consent, given when you connect the integration |
| AI features | To suggest scheduling and summaries from your task text | Contract for features built into the product, consent for optional ones |
| Marketing emails | To tell you about Easier Now | Consent, withdrawable in one click |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and we think it is not. You can object at any time. See section 12.
We do not sell your personal data. We never have and we will not.
4. Google Calendar
Connecting Google Calendar is optional. The app works without it. If you do connect it, you authorise us through Google OAuth and Google shows you exactly what you are granting before you agree.
What we access
- Your calendar list, so you can choose which calendars to sync.
- Event details on those calendars: title, description, start and end times, attendees and busy status.
- Permission to create, update and delete events that the scheduling feature manages for you.
What we do with it
- We read your events so the app can plan around your real commitments.
- We write events back so your plan shows up in your calendar.
- We store the minimum needed to keep the two sides in sync, plus a securely stored access token.
What we do not do
- We do not sell or transfer Google user data to anyone.
- We do not use Google user data to train, retrain or improve any AI or machine learning model.
- We do not use Google user data for advertising.
- We do not let people read your calendar data, except where you have asked us to (for example a support request), where it is needed for security or to fix a fault, or where the law requires it.
Our use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect
Disconnect the integration in your Easier Now account settings, or revoke access directly at myaccount.google.com/permissions. When you disconnect we stop syncing straight away, delete the stored access token, and delete the calendar data we cached within 30 days. Events already written to your calendar stay there and remain yours to edit or delete.
5. AI features
Some features use AI to help you. For example, suggesting how long a task might take, ordering your day, or summarising a list. To do this we send the relevant task text, and sometimes calendar timing, to an AI provider acting as our processor.
- We send the smallest amount of content the feature needs to work.
- Our AI providers are under contract not to use your content to train their models.
- We do not use your content to train our own models.
- Google Calendar data is never used for model training.
- AI output is a suggestion, not a fact. It can be wrong. Check anything that matters before you act on it.
If you would rather not use AI features, you can turn them off in settings. The rest of the app keeps working.
6. Who we share data with
We use a small number of trusted companies to run the service. They act on our instructions under a data processing agreement. They are not allowed to use your data for their own purposes.
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, authentication and file storage | EU where available |
| Stripe | Payments, subscriptions, invoices | EU, UK and US |
| Calendar integration and Google sign in, if you use them | EU and US | |
| AI provider | Powers optional AI scheduling and summaries | EU and US |
| Analytics provider | Privacy preserving product and site analytics | EU where available |
| Email provider | Service emails and, if you opt in, marketing emails | EU and US |
| Hosting and CDN | Serving the website and the app | Global edge network |
We may also share data where the law requires it, to establish or defend legal claims, or as part of a merger or sale of the business. If the business changed hands we would tell you, and this policy would keep applying until you were given notice of any change.
The list above is our current set of sub-processors. Email us if you need the named provider for any row and we will confirm it.
7. Cookies and consent
We keep cookies to a minimum. There are two kinds.
- Essential cookies. These keep you logged in, remember your consent choice, and protect against fraud and abuse. The service cannot work without them, so they do not need consent.
- Non-essential cookies. Analytics and similar. These are off by default. Our consent banner declines them unless you actively choose to accept. There is no pre-ticked box.
You can change your choice at any time from the cookie link in the site footer, and you can clear cookies in your browser settings. Our analytics are set up to avoid tracking you across other websites.
8. How long we keep data
We keep data only as long as we need it.
- Account and content data: for as long as your account is open. If you delete your account we delete or anonymise your data within 30 days, except where a different period is set out below.
- Backups: deleted data can persist in encrypted backups for up to 90 days, after which it is overwritten.
- Google Calendar data: deleted within 30 days of you disconnecting the integration.
- Billing and tax records: kept for 6 years after the end of the relevant financial year, because UK tax law requires it.
- Support emails: kept for 3 years from the last message in the thread.
- Analytics: kept in aggregated or pseudonymised form for up to 26 months.
- Security and access logs: kept for up to 12 months.
If an account has been inactive for 24 months we will email you first, then delete the account if you do not respond.
9. International transfers
We host account data in the EU where our providers offer it. Some providers, including Stripe, Google and our AI and email providers, may process data in the United States or elsewhere.
Where data leaves the UK or EEA we rely on one of the following: an adequacy decision by the UK government or the European Commission, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses. We add safeguards such as encryption in transit and at rest. Ask us and we will tell you which mechanism covers a specific provider.
10. Security
We take security seriously and do the ordinary things properly. These are the specific mechanisms that protect your data, including data we receive from Google APIs.
- In transit. Everything travels over HTTPS with TLS 1.2 or above. Plain HTTP requests are redirected, never served.
- At rest. Our database, file storage and backups sit on managed infrastructure with AES-256 encryption at rest, applied at the storage layer by our providers.
- Separation between accounts. Every table holding personal data is protected by row-level security enforced by the database itself on every single query, not by application code that could forget to check. A session authenticated as you can only read or write rows that belong to you. Team workspace data is gated the same way, on your role in that workspace.
- Google Calendar data and tokens. Your OAuth tokens and any cached event data live in that same row-secured store, reachable only by your own authenticated session and encrypted at rest at the storage layer. The token is scoped to the three permissions listed in section 4 and nothing wider. When you disconnect, the token is deleted immediately and the cached events within 30 days. You can also revoke access from your Google account at any time, which invalidates the token independently of us.
- Passwords. Stored only as salted hashes by our authentication provider. Nobody at Easier Now can read your password.
- Access to production. Limited to the people who need it to run the service, over authenticated administrative access, and logged.
- Secrets. API keys and service credentials are held in our hosting platform's encrypted environment store rather than in application code.
- Personal versus team. Personal tasks stay private. Team admins can see team workspace content, never your personal lists.
No system is perfectly secure. If a breach affects your rights and freedoms we will tell you, and report it to the ICO within 72 hours where the law requires. If you think you have found a vulnerability, please email hello@easiernow.co and we will respond.
11. Children
Easier Now is not for children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16. If we learn that we have, we will delete it. If you believe a child has created an account, email us and we will act quickly.
12. Your rights
If you are in the UK or the EU, you have the following rights over your personal data.
- Access. Ask for a copy of what we hold about you.
- Rectification. Ask us to correct anything wrong or incomplete.
- Erasure. Ask us to delete your data, subject to records we must keep by law.
- Portability. Get your data in a common, machine readable format, or ask us to send it on.
- Restriction. Ask us to pause processing while a dispute is sorted out.
- Objection. Object to processing we base on legitimate interests, including any profiling.
- Withdraw consent. Where we rely on consent, you can withdraw it at any time. That does not undo processing we already did lawfully.
- Automated decisions. We do not make decisions with legal or similarly significant effects using automated processing alone.
How to exercise them
Two of these you can do yourself right now. Export your data from account settings, and delete your account from account settings. For anything else, email hello@easiernow.co and tell us what you want.
We will reply within one month. If your request is complex we may extend that by two months, and we will tell you why. These rights are free to use. We would only charge, or refuse, if a request were clearly unfounded or excessive, and we would explain if that ever happened. We may ask you to confirm your identity first.
13. Complaints
If something is wrong, tell us first on hello@easiernow.co. We would rather fix it than have you go elsewhere.
You also have the right to complain to a regulator. In the UK that is the Information Commissioner's Office at ico.org.uk/make-a-complaint, or on 0303 123 1113. If you are in the EEA you can complain to your national data protection authority.
14. Changes to this policy
We will update this policy when the product changes or the law does. The date at the top always shows the current version. If a change materially affects you, we will email you or show a notice in the app before it takes effect. Where a change needs your consent, we will ask for it.
15. Contact us
Email hello@easiernow.co for anything to do with privacy, your data, or this policy. A postal address for formal notices is available on request.
See also our terms and conditions.