Privacy Policy
Command Center is a personal dashboard. It signs in to accounts you already have, such as your mail and calendar, and shows them on one screen. This page explains exactly what that involves: what we store, why, where, who can see it, and how to get it deleted. It is written to be read, not skimmed past.
- 1. What we collect
- 2. How we use it
- 3. Google user data
- 4. Who we share it with
- 5. Where it lives and how it is protected
- 6. How long we keep it
- 7. Your rights and choices
- 8. Information about other people
- 9. Children
- 10. Changes to this policy
- 11. Contact
1. What we collect
Your account
When you sign up we store a username, an email address, and a password. The password is stored only as a salted hash; we cannot read it back. If you attach a Google account for sign-in, we also store the Google account identifier, email address and display name that Google returns.
Accounts you connect
Every integration is optional and off until you connect it. When you do, we store what is needed to keep reading from that service on your behalf, and we fetch the data that the relevant tab displays.
| Service | What we store | What we read |
|---|---|---|
| OAuth tokens | Your Gmail messages, labels and drafts; your Google Calendar events and calendar list; your Google Tasks. Sending, editing and deleting only happen when you do them in the app. | |
| Microsoft | OAuth tokens | Your Outlook mail and basic profile, and sending mail when you send it. |
| Other mailboxes | IMAP/SMTP server, username and password | Message headers, unread counts and the messages you open. |
| WHOOP | OAuth tokens | Recovery, strain, sleep and workout records. |
| Spotify | OAuth tokens | What is playing, your playlists and playback control. |
| MyFitnessPal | Session credentials | Your food diary and nutrition totals. |
| Modern States | Username and password | Your CLEP course progress. |
| Canvas / school | The calendar feed URL you paste | Course names, assignments and due dates from that feed. |
| Water tag / coaster | A per-user token, written onto your NFC sticker or given to the coaster | Each drink the tag or your phone's Shortcut logs, and the coaster's weight readings. |
| Obsidian | A per-user sync token | The notes your vault sync sends, so the graph can be drawn. |
Feeds that need no account, such as the news headlines and the Forex Factory economic calendar, are fetched by our server, not from your browser, and carry nothing about you.
Things you enter
Tasks and reminders, money ledger entries and budgets, tracker and water logs, the Realtor tab's clients, deals, checklists and uploaded files, quick links, your settings and layout, and any cover image you upload.
Collected automatically
- Server logs. Like every web server, ours records the IP address, browser type, page requested and time of each request. These logs are kept for 14 days and then deleted automatically.
- A session cookie. One cookie keeps you signed in. It is marked Secure, HttpOnly and SameSite, so it is sent only over HTTPS, only to this site, and cannot be read by scripts.
- Browser storage. Your theme, palette and sidebar preferences are kept in your own browser's local storage so the page paints correctly before it loads. They never leave your browser.
2. How we use it
Everything above is used for one purpose: showing you your own information on your own dashboard. In practice that means we use it to:
- sign you in and keep your data separate from every other account;
- fetch, display and, when you ask, change data in the services you connected;
- send the reminders and notifications you turned on;
- keep the service running, secure and free of abuse (rate limiting sign-in attempts, for example).
We do not sell your data, rent it, use it for advertising, build profiles from it, or use it to train any machine-learning model. The Assistant tab is a set of rules that run on this server; nothing you have is sent to an AI provider.
3. Google user data
Connecting Google asks for access to Gmail, Google Calendar, Google Tasks, and your basic profile. That data is used only to display your mail, calendar and tasks in Command Center and to carry out the actions you take there, such as archiving a thread or creating an event.
Command Center's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is never transferred to anyone else except to provide or improve the app's own features, to comply with law, or as part of a merger or acquisition with prior notice to you; it is never used for advertising; and no human reads it except with your permission, for security purposes, to comply with law, or after it has been aggregated and anonymised.
You can revoke Command Center's access at any time from your Google account permissions. Doing so invalidates the stored tokens immediately.
4. Who we share it with
- The services you connect. When you act inside Command Center, the action goes to that service: sending a mail goes through Gmail, Outlook or your SMTP server; pausing a track goes to Spotify. Each service's own privacy policy governs what it does with that.
- Our hosting provider. The server runs on Oracle Cloud Infrastructure in the United States (Ashburn, Virginia). Oracle provides the machine and the network; it does not access the data on it.
- Font and script hosts on the sign-in pages. The sign-in and sign-up pages load the Inter typeface from Google Fonts and a stylesheet helper from the Tailwind CDN. Loading those files discloses your IP address to Google and to Tailwind's host, as visiting any site that uses them does. The dashboard itself, once you are signed in, and this page load nothing from third parties.
- Legal requirements. We will disclose information if required to by a valid legal process, and we will tell you first unless the law forbids it.
That is the complete list. There are no data brokers, advertisers, analytics vendors or "partners".
5. Where it lives and how it is protected
- All traffic is encrypted in transit with HTTPS. Plain HTTP requests are redirected, and browsers are told to use HTTPS only (HSTS).
- Your data is stored in a folder that belongs to your account alone. Every request is checked against your session before it can read or write anything, and no request can reach another account's folder.
- Passwords for Command Center itself are salted and hashed. Sign-in and sign-up are rate limited, and new accounts require an invite code.
- Access to the server is by SSH key only. One person, the operator named below, has that key.
No system is perfectly secure. If we ever learn of a breach affecting your data we will tell you by email without undue delay, and within any period the law requires.
6. How long we keep it
- Account and entered data: for as long as your account exists.
- Connected-service credentials and cached data: until you disconnect that service, which removes them at once.
- Server logs: 14 days, then deleted automatically.
- Backups: we take occasional manual snapshots of the data folder, kept on the same server under the same access controls. Credentials inside them are encrypted as described above and the key is not part of any snapshot. When you delete your account, your data is removed from those snapshots too, within 30 days.
7. Your rights and choices
Wherever you live, you can ask us to:
- see what we hold about you, and receive a copy in a portable format (your data is stored as plain JSON files, which is what you would get);
- correct anything that is wrong. Most of it you can edit directly in the app;
- delete your account and everything in it. We will confirm when it is done, within 30 days at most;
- disconnect any integration, which you can do yourself from Settings at any time, or by revoking access at the provider (Google, Microsoft, WHOOP, Spotify);
- object to or restrict a use of your data, or withdraw consent where consent is the basis for that use.
To exercise any of these, email the address in section 11 from the address on your account. We will not ask you to jump through hoops, and we will never treat you differently for asking. If you are in the European Economic Area, the United Kingdom or Switzerland, our legal bases are performance of the service you signed up for, your consent for each integration you connect, and our legitimate interest in keeping the service secure; you also have the right to complain to your local data protection authority. If you are a California resident, the rights above cover your rights under the CCPA; we do not sell or share personal information as those terms are defined there.
8. Information about other people
Your mail, calendar and the Realtor tab naturally contain information about other people: senders, attendees, clients. We hold that information only because it is part of your data, use it only to show it to you, and delete it when you delete the account or entry it belongs to. If you use the Realtor tab for client records, you are responsible for having the right to store those records, and for any notice your own clients are owed.
9. Children
Command Center is not directed at children and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has an account, contact us and we will delete it.
10. Changes to this policy
If we change what we collect or how we use it, we will update this page, change the effective date at the top, and, for any change that matters, email the address on your account before it takes effect. The current version always lives at the-command-center.duckdns.org/privacy.
11. Contact
Command Center is operated by an individual in the United States, not a company. For anything about this policy or your data, email avinsolemani@gmail.com.