Command Center Sign in

Privacy Policy

Effective September 9, 2026

Command Center is a personal dashboard. It signs in to accounts you already have, such as your mail and calendar, and shows them on one screen. This page explains exactly what that involves: what we store, why, where, who can see it, and how to get it deleted. It is written to be read, not skimmed past.

1. What we collect

Your account

When you sign up we store a username, an email address, and a password. The password is stored only as a salted hash; we cannot read it back. If you attach a Google account for sign-in, we also store the Google account identifier, email address and display name that Google returns.

Accounts you connect

Every integration is optional and off until you connect it. When you do, we store what is needed to keep reading from that service on your behalf, and we fetch the data that the relevant tab displays.

ServiceWhat we storeWhat we read
GoogleOAuth tokensYour Gmail messages, labels and drafts; your Google Calendar events and calendar list; your Google Tasks. Sending, editing and deleting only happen when you do them in the app.
MicrosoftOAuth tokensYour Outlook mail and basic profile, and sending mail when you send it.
Other mailboxesIMAP/SMTP server, username and passwordMessage headers, unread counts and the messages you open.
WHOOPOAuth tokensRecovery, strain, sleep and workout records.
SpotifyOAuth tokensWhat is playing, your playlists and playback control.
MyFitnessPalSession credentialsYour food diary and nutrition totals.
Modern StatesUsername and passwordYour CLEP course progress.
Canvas / schoolThe calendar feed URL you pasteCourse names, assignments and due dates from that feed.
Water tag / coasterA per-user token, written onto your NFC sticker or given to the coasterEach drink the tag or your phone's Shortcut logs, and the coaster's weight readings.
ObsidianA per-user sync tokenThe notes your vault sync sends, so the graph can be drawn.

Feeds that need no account, such as the news headlines and the Forex Factory economic calendar, are fetched by our server, not from your browser, and carry nothing about you.

Things you enter

Tasks and reminders, money ledger entries and budgets, tracker and water logs, the Realtor tab's clients, deals, checklists and uploaded files, quick links, your settings and layout, and any cover image you upload.

Collected automatically

There is no analytics script, no advertising pixel, no fingerprinting, and no third-party tracker anywhere in Command Center. We do not know how you use the app beyond what the server logs above record.

2. How we use it

Everything above is used for one purpose: showing you your own information on your own dashboard. In practice that means we use it to:

We do not sell your data, rent it, use it for advertising, build profiles from it, or use it to train any machine-learning model. The Assistant tab is a set of rules that run on this server; nothing you have is sent to an AI provider.

3. Google user data

Connecting Google asks for access to Gmail, Google Calendar, Google Tasks, and your basic profile. That data is used only to display your mail, calendar and tasks in Command Center and to carry out the actions you take there, such as archiving a thread or creating an event.

Command Center's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is never transferred to anyone else except to provide or improve the app's own features, to comply with law, or as part of a merger or acquisition with prior notice to you; it is never used for advertising; and no human reads it except with your permission, for security purposes, to comply with law, or after it has been aggregated and anonymised.

You can revoke Command Center's access at any time from your Google account permissions. Doing so invalidates the stored tokens immediately.

4. Who we share it with

That is the complete list. There are no data brokers, advertisers, analytics vendors or "partners".

5. Where it lives and how it is protected

Credentials are encrypted at rest. Some services offer no OAuth, so the only way to read them on your behalf is to keep the username and password you give us: other mailboxes over IMAP, Modern States and MyFitnessPal. Those, and the OAuth tokens for Google, Microsoft, WHOOP and Spotify, are stored encrypted (AES-128-CBC with an HMAC-SHA256 integrity check, the Fernet scheme) with a key that is kept outside the data folder and outside every backup. A copy of the data folder without that key cannot be read. If a service offers an app-specific password, use one anyway, and connect only what you want the dashboard to show. Disconnecting a service deletes its credentials immediately.

No system is perfectly secure. If we ever learn of a breach affecting your data we will tell you by email without undue delay, and within any period the law requires.

6. How long we keep it

7. Your rights and choices

Wherever you live, you can ask us to:

To exercise any of these, email the address in section 11 from the address on your account. We will not ask you to jump through hoops, and we will never treat you differently for asking. If you are in the European Economic Area, the United Kingdom or Switzerland, our legal bases are performance of the service you signed up for, your consent for each integration you connect, and our legitimate interest in keeping the service secure; you also have the right to complain to your local data protection authority. If you are a California resident, the rights above cover your rights under the CCPA; we do not sell or share personal information as those terms are defined there.

8. Information about other people

Your mail, calendar and the Realtor tab naturally contain information about other people: senders, attendees, clients. We hold that information only because it is part of your data, use it only to show it to you, and delete it when you delete the account or entry it belongs to. If you use the Realtor tab for client records, you are responsible for having the right to store those records, and for any notice your own clients are owed.

9. Children

Command Center is not directed at children and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has an account, contact us and we will delete it.

10. Changes to this policy

If we change what we collect or how we use it, we will update this page, change the effective date at the top, and, for any change that matters, email the address on your account before it takes effect. The current version always lives at the-command-center.duckdns.org/privacy.

11. Contact

Command Center is operated by an individual in the United States, not a company. For anything about this policy or your data, email avinsolemani@gmail.com.