← Back to User Guide

Privacy Policy

Last updated: 7 July 2026

This Privacy Policy explains how Slycora OÜ (“Slycora”, “we”, “us”) processes personal data when you use the Slycora mobile application, website and related services.

Slycora is a planning and productivity application for adults. It helps users capture tasks, organise priorities and receive realistic daily planning recommendations. Slycora may be marketed as a productivity and planning tool for users with ADHD/ATH or similar executive-function challenges, but Slycora is not a medical device and does not provide medical, psychological, therapeutic, legal, financial or safety-related advice.

Slycora does not diagnose, treat, monitor or prevent ADHD/ATH or any other health condition. Any recommendations generated by Slycora are advisory and may be changed, ignored or deleted by the user.

1. Who we are

Slycora OÜ, Männiku tn 2, Kehtna alevik, Kehtna vald, Rapla maakond, 79001, Estonia, registry code 17428297, is the controller of your personal data.

You can contact us about privacy matters at support@slycora.com.

We have assessed the need to appoint a Data Protection Officer under Article 37 GDPR. Based on the current scope of our service, we have not appointed a Data Protection Officer. We will reassess this if the nature, scale or risk level of our processing changes.

2. Privacy principles

Slycora is designed to minimise the identification of users. We do not require your name, identity documents, diagnosis, medical records, treatment information or medication data. We do not verify who is behind the email address used for registration, and we do not combine data for the purpose of identifying the user as a named individual.

Registration requires an email address. An email address is personal data under GDPR, even if we do not know the user’s real name.

Optional personalisation data is provided voluntarily by the user. You can use the core service without providing detailed personal characteristics or health-related information, although some recommendations may be less personalised.

3. Eligibility

Slycora is intended only for users aged 18 and over. We do not knowingly provide the service to children or knowingly collect personal data from anyone under 18. If we become aware that a person under 18 has created an account, we will delete the account and related personal data without undue delay.

4. Data we process

We process account data, such as your email address, authentication identifiers, sign-in provider identifiers, account settings and subscription status.

We process task and planning data that you enter into the app, such as tasks, notes, deadlines, goals, priorities, user-created plans, reminders and completed or postponed tasks.

You may choose to provide optional personalisation data to improve the quality of recommendations. This may include information about your working style, planning preferences, energy level, cognitive load, emotional state, physical state, friction tolerance, self-described behaviour patterns, task avoidance patterns, motivation-related context and other similar information.

Slycora may generate recommendation data, including task clarification suggestions, priority scores, effort estimates, daily plans, explanations, behavioural suggestions and summaries of user-provided planning context. These outputs are generated to support planning and are not medical, psychological or therapeutic assessments.

We may also process technical data, such as app usage events, device type, operating system, app version, crash reports, technical logs, security logs and other technical identifiers necessary to operate and secure the service.

If you purchase a subscription, payments are processed through the relevant app store or payment provider. We may receive subscription status, transaction identifiers, product information, renewal or cancellation status and limited payment metadata. We do not receive your full payment card number.

5. Health-related and special category data

Slycora does not require users to provide health data, diagnosis information, medical records, treatment information, medication data or other special category data.

Some users may choose to include health-related, wellbeing-related or ADHD/ATH-related information in their own notes, tasks or personalisation context. Slycora does not require such information for account creation or for the basic use of the service.

If a user chooses to provide such information and wants Slycora to use it for optional personalised recommendations, Slycora will request the user’s explicit consent before such data is used for that purpose.

Where such information qualifies as special category data under Article 9 GDPR, we process it only on the basis of the user’s explicit consent under Article 9(2)(a) GDPR and only for the purpose of providing personalised planning recommendations.

If the user does not give explicit consent, Slycora will not intentionally use health-related or special category data for optional personalised recommendations. The user may still use the core planning features of the service.

We do not use health-related or special category data to diagnose you, treat you, assess your medical condition, verify your identity or make legal or similarly significant decisions about you.

6. Personalisation and profiling

Slycora provides account-based personalisation. This means that Slycora may analyse information connected to your user account, such as task patterns, planning history, preferences, self-reported capacity, friction tolerance, emotional or cognitive context and interaction patterns, in order to generate personalised planning and behavioural recommendations.

This is profiling within the meaning of GDPR, because it involves analysing or predicting certain aspects of how a user plans, prioritises or interacts with tasks. However, Slycora does not require your real name, does not verify the person behind the email address and does not combine data for the purpose of identifying you as a named individual.

Recommendations are advisory. You can change, ignore or delete them. You can also withdraw consent for optional personalisation and delete your account and related data.

Slycora does not make decisions that produce legal effects or similarly significant effects concerning you within the meaning of Article 22 GDPR.

7. Purposes and legal bases

We process your email address and account data to create and manage your account on the basis of performance of a contract under Article 6(1)(b) GDPR.

We process task and planning data to provide the core service on the basis of performance of a contract under Article 6(1)(b) GDPR.

We process optional personalisation data on the basis of your consent under Article 6(1)(a) GDPR. Where optional personalisation data includes health-related or other special category data, we process it on the basis of your explicit consent under Article 9(2)(a) GDPR.

We process task and planning data through AI tools to provide planning recommendations on the basis of performance of a contract under Article 6(1)(b) GDPR. Where AI-based personalisation uses optional health-related or special category data, we rely on your explicit consent under Article 9(2)(a) GDPR.

We process payment and subscription data to manage subscriptions and payments on the basis of performance of a contract under Article 6(1)(b) GDPR and, where accounting or tax rules require retention, on the basis of legal obligation under Article 6(1)(c) GDPR.

We process technical, diagnostic and security data to maintain, secure and improve the service and prevent abuse on the basis of our legitimate interest under Article 6(1)(f) GDPR.

We process data where necessary to respond to user requests, comply with legal obligations or establish, exercise or defend legal claims.

Marketing communications, if any, are sent only where legally permitted and, where required, based on your consent.

8. Consent and withdrawal

Where processing is based on consent, you may withdraw your consent at any time.

Where processing involves health-related or special category data, we request explicit consent before using such data for optional personalised recommendations. Consent is voluntary. You may continue using the core service without giving such consent.

You may withdraw consent by changing your privacy or personalisation settings in the app, deleting optional personalisation data, deleting your account or contacting us at support@slycora.com.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. If you withdraw consent for optional personalisation, you may continue using the core service, but some recommendations may become less personalised.

9. Artificial intelligence

Slycora uses AI-based tools to generate clarifications, task suggestions, priority scores, effort estimates, explanations, daily plans and personalised planning recommendations.

Slycora uses Gemini through the Gemini API. When AI is used, the text you enter into the app may be sent to Gemini for processing. This may include the full task or note text where this is necessary to generate the requested planning recommendation.

Gemini acts as our AI service provider. According to Gemini’s business and API data controls, API inputs and outputs are not used to train Gemini models by default unless the customer explicitly opts in. Slycora does not opt in to model training with user data.

Slycora has configured Gemini API processing with European data residency, where available for the relevant API project and endpoint. Model requests and responses are processed in accordance with that configuration.

AI prompts and outputs are retained by Slycora for up to 30 days, unless the user deletes the relevant data earlier or longer retention is necessary for security, legal or dispute-resolution reasons.

AI is used only to support planning and productivity. AI outputs are advisory. You remain free to accept, modify, ignore or delete them. We do not use AI outputs to make legal, medical, employment, credit, insurance or similarly significant decisions about you.

We do not intentionally send diagnosis documents, medical records or unnecessary health information to AI providers. However, if you choose to include health-related information in your tasks, notes or personalisation context and give explicit consent for health-related personalisation, such information may be processed through AI tools to generate personalised planning recommendations.

10. EU AI Act transparency

Slycora uses AI systems that interact with users and generate planning recommendations. We inform users that they are interacting with AI-supported functionality and that AI-generated outputs may be incomplete, inaccurate or unsuitable for a particular situation.

Slycora does not use AI for emotion recognition, biometric categorisation, social scoring, medical diagnosis, law enforcement, employment decisions, credit decisions, insurance decisions or other legal or similarly significant decisions.

Slycora is intended to function as a productivity and planning tool. If the nature of the service changes in a way that may bring it within a higher-risk category under the EU AI Act, we will reassess our obligations before deploying such functionality.

11. Cookies, analytics and diagnostics

Slycora may use necessary technologies to operate the app and website, keep users signed in, secure the service and remember user preferences.

We may also use analytics and crash reporting tools to understand app performance, fix errors and improve the service. Non-essential analytics, tracking or marketing technologies will be used only where legally permitted and, where required, based on your consent.

We do not sell personal data and we do not use personal data for cross-context behavioural advertising.

12. Recipients and processors

We do not sell your personal data.

We may share personal data with service providers who process data on our behalf and under our instructions. These may include Google for EU hosting, Gemini for AI processing, authentication providers, app store or payment providers, analytics providers, crash reporting providers, email or support service providers, security and infrastructure providers and professional advisers where necessary.

We require processors to protect personal data, process it only for agreed purposes and comply with Article 28 GDPR or other applicable data processing requirements.

13. International transfers

We aim to store and process user data in the European Economic Area where possible. Slycora hosts its service infrastructure with Google Cloud in the EU region and uses Gemini API processing with European data residency where configured and available.

If personal data is transferred outside the European Economic Area, we will use a valid transfer mechanism under Chapter V GDPR, such as an adequacy decision of the European Commission, Standard Contractual Clauses approved by the European Commission, the EU–U.S. Data Privacy Framework where applicable, or another lawful transfer safeguard.

Where required, we will assess whether the recipient country provides an adequate level of protection and whether supplementary safeguards are necessary.

You may request more information about international transfers by contacting support@slycora.com.

14. Data retention

We keep personal data only for as long as necessary for the purposes described in this policy.

Account data is kept until the account is deleted, unless longer retention is required by law. Task and planning data is kept until deleted by the user or until the account is deleted. Optional personalisation data is kept until deleted by the user, consent is withdrawn or the account is deleted. AI prompts and outputs are kept for up to 30 days. Usage, analytics and diagnostic logs are kept for up to 15 days. Security logs are kept for up to 30 days. Backup copies are kept for up to 30 days. Payment and accounting data is kept as required by applicable accounting and tax laws, generally up to 7 years.

When you delete your account, we delete or anonymise account data, task data and optional personalisation data from active systems without undue delay and no later than 14 days, unless we are legally required to retain limited information.

Backup copies are deleted or overwritten according to the normal backup cycle and are not used for active processing unless restoration is necessary for security or continuity reasons.

15. Your rights under GDPR

If you are in the European Economic Area, the United Kingdom or another jurisdiction where similar rights apply, you have the right to access your data, rectify inaccurate data, request erasure, restrict processing, receive your data in a portable format, object to processing based on legitimate interests, withdraw consent and not be subject to solely automated decisions producing legal or similarly significant effects.

You can exercise your rights through the app, where available, or by contacting support@slycora.com.

We usually respond within one month. If the request is complex or we receive many requests, we may extend the response period as permitted by GDPR.

16. Deleting your data

You can delete your account and related data through the app or by contacting us.

Account deletion includes deletion of account data, task and planning data, optional personalisation data, recommendation history, user-generated notes and consent settings connected to the account, unless we are legally required to retain limited information.

If you only want to delete optional personalisation data but keep using the account, you may do so through the app where this feature is available or by contacting us.

17. Security

We apply technical and organisational measures appropriate to the nature and sensitivity of the data processed. These may include encryption in transit, encryption at rest where appropriate, access controls, least-privilege access, authentication controls, logging and monitoring, backup procedures, processor due diligence, internal access restrictions and incident response procedures.

No digital service can be guaranteed to be completely secure. If we become aware of a personal data breach, we will assess it and, where required, notify the competent supervisory authority and affected users in accordance with GDPR.

18. U.S. and California privacy notice

This section applies to users in the United States, including California residents, to the extent applicable law grants them additional privacy rights.

Slycora collects the categories of personal information described in this Privacy Policy, including identifiers such as email address, internet or electronic network activity information, commercial information relating to subscriptions, inferences generated for planning and productivity recommendations, and any optional information the user chooses to provide.

Slycora may process sensitive personal information if the user voluntarily provides health-related, wellbeing-related or ADHD/ATH-related information and gives explicit consent for such information to be used for optional personalised recommendations.

Slycora uses personal information to provide the service, generate planning recommendations, manage accounts and subscriptions, secure and improve the service, respond to requests, comply with legal obligations and exercise legal rights.

Slycora does not sell personal information. Slycora does not share personal information for cross-context behavioural advertising. Slycora does not use or disclose sensitive personal information for purposes other than providing the service requested by the user, securing the service, complying with law or other legally permitted purposes.

To the extent California privacy laws apply, California residents may have the right to know what personal information we collect, use and disclose, the right to request deletion, the right to correct inaccurate personal information, the right to access personal information, the right to opt out of sale or sharing, the right to limit certain uses of sensitive personal information and the right not to be discriminated against for exercising privacy rights.

You may exercise these rights by contacting support@slycora.com. We may need to verify your request before responding. You may also use an authorised agent where permitted by California law.

19. U.S. health data and breach notice

Slycora is a productivity and planning application and is not a medical provider, health plan or healthcare clearinghouse. Slycora is not intended to be subject to HIPAA as a covered entity.

However, because users may voluntarily provide health-related or wellbeing-related information, certain U.S. health privacy or breach notification rules may apply depending on the facts and applicable law.

If a breach of unsecured health-related personal information occurs and a U.S. health breach notification law applies, Slycora will assess the incident and provide notices to affected users, regulators or other parties as required by applicable law.

20. Marketing communications

We will send marketing communications only where legally permitted and, where required, based on your consent. You may unsubscribe from marketing communications at any time.

Service-related messages, such as security notices, account notices or important changes to this policy, are not marketing communications.

21. Supervisory authority

You have the right to lodge a complaint with a supervisory authority.

Our lead supervisory authority is the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon, website: https://www.aki.ee.

You may also contact the supervisory authority in your EU Member State of residence, place of work or place of alleged infringement.

22. Changes to this policy

We may update this Privacy Policy from time to time.

If we make material changes, we will notify users in the app or by email before the changes take effect, where required by law.