CadenceBack to Cadence

Privacy policy

Draft for review before launch

This draft describes the current prototype. Replace every bracketed field and have qualified counsel review it for your business, users, and jurisdiction before publishing it as an operative policy. It does not eliminate liability or override legal rights.

Effective date: [ADD EFFECTIVE DATE]
Responsible operator: [ADD LEGAL ENTITY OR OPERATOR NAME]
Privacy contact: [ADD PRIVACY EMAIL]
Business address: [ADD BUSINESS MAILING ADDRESS]

1. Scope

This draft explains the data flows in the current Cadence prototype. It must be updated if hosting, authentication, analytics, payment processing, or storage changes. It is not a claim that every legal or security requirement has already been implemented.

2. Information you provide

Cadence processes Google account names, email addresses, profile images, and session identifiers, assignment documents, project settings, deadlines, task selections, generated plans, ownership, comments, and files submitted for review. Uploaded material can contain personal information. Only provide information needed for your project and that you have permission to share.

3. Why information is processed

Information is used to interpret your assignment brief, generate or adjust a work plan, show project membership and task ownership, support project discussions, and respond to submission-review requests. Where applicable, the operator must identify valid legal grounds and obtain meaningful consent, including any required parental or guardian consent. [CONFIRM LAWFUL BASES, CONSENT FLOW, AND TARGET REGIONS].

4. AI processing

Assignment text, plan-management requests, and submitted work are processed by a model running on the Cadence host computer through Ollama. The application does not send these requests to an external AI provider or use an external AI API key. Model and OCR language files may be downloaded during setup; project content is processed locally. The operator must document the actual deployment location and model configuration before launch: [CONFIRM HOST, MODEL, AND RETENTION].

5. Browser and server storage

Projects, membership, comments, private messages, notifications, source files, submissions, activity dates, and session records are saved on the host computer. They survive a server restart. Browser storage saves tour acknowledgments and claim-confirmation preferences. A secure HTTP-only session cookie keeps you signed in for up to seven days. An OAuth cookie lasts up to ten minutes during sign-in. Clearing browser data does not erase server records. Archiving a project keeps its history. [ADD VERIFIED RETENTION, BACKUP, AND DELETION PROCESS].

6. Sharing and project visibility

Invited people must sign in with Google before joining a shared project. Project members can access its plan, files, discussions, and submissions. Private messages are returned only to the sender and recipient; server operators with database access can still access stored data. Leaders can remove members and replace invitation links. Keep links within your group. Google processes sign-in under its own terms. [ADD HOSTING PROVIDERS, REGIONS, AND OPERATOR ACCESS POLICY].

7. Cookies, analytics, and local media

The current source does not include marketing analytics, advertising trackers, or payment processing. Cadence’s landing-page videos and images are served locally by the app; the preview does not embed YouTube. The app uses local storage as described above. Hosting or future integrations may introduce additional cookies or logs, which must be documented and, where required, subject to consent before use.

8. Security

The app uses Google identity verification, HTTP-only sessions, same-origin checks for changes, and server-enforced project membership and leader permissions. No system guarantees absolute security. This local deployment is designed for one Node server with local disk storage; a public deployment needs reviewed infrastructure, HTTPS, backups, operational monitoring, and incident procedures. [ADD VERIFIED DEPLOYMENT SAFEGUARDS].

9. Your choices and rights

Depending on your location and applicable law, you may have rights to access, correct, delete, or receive your personal information, withdraw consent, object to or restrict certain processing, or complain to a privacy regulator. Contact [ADD WORKING PRIVACY EMAIL]. The operator must implement a way to verify and respond to requests before launch: [ADD REQUEST PROCESS AND APPLICABLE RESPONSE TIMES].

You can archive projects using the app’s available controls and clear local site data through your browser. Those actions are not a promise that every server or provider copy is erased. Request assistance for shared data, subject to legal retention obligations and the technical limits described above.

10. Children and younger users

Age eligibility, parental consent where required, and appropriate youth privacy practices must be established before offering the service to children: [ADD AGE POLICY AND GUARDIAN CONTACT PROCESS]. If you believe information was provided without required consent, contact the privacy contact above.

11. International processing

Depending on the chosen hosting and AI services, information may be processed outside your province or country, where laws may differ. [CONFIRM PROCESSING COUNTRIES, TRANSFER BASIS, AND APPLICABLE SAFEGUARDS].

12. Changes and contact

Update this policy when practices change, and provide notice and renewed consent where required. Notice method: [ADD NOTICE METHOD]. For privacy questions, contact [ADD PRIVACY EMAIL].

© 2026 Cadence. All rights reserved.Terms of usePrivacy policyHome