Axis - AI-Powered Time Architecture Effective Date: August 21, 2026
RMR Products LLC ("Company," "we," "our," or "us") operates Axis, an AI-powered time architecture and productivity platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Axis is built to help you design your whole week, not only your working hours. That means the Service can hold information about your work, your health and training, your rest, and your state of mind. We have tried to describe every category of data the Service collects rather than summarizing them loosely, so you can judge for yourself what you are comfortable connecting. Several of the categories below are optional and inactive until you turn them on: connected calendars, connected fitness accounts, the desktop application-usage bridge, and voice capture. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
When you create an account, we collect: • Email address • First and last name • Password (stored in hashed form by our authentication provider) • Multi-factor authentication settings, including authenticator app enrollment and one-time codes sent to your email address • Trusted device records, so that you are not challenged on every sign-in from a device you have already approved • If you joined through our gated beta: the information you submitted on the access request form and any invite code you redeemed
To personalize the Service, you may voluntarily provide: • Occupation and industry/role • Work context (solo or team) • Chronotype and peak productivity window preferences • Preferred work hours and work days • Date of birth, marital status, number of children, and family commitment level • Meeting load preferences • Timezone This profile information is used to configure the AI system's recommendations and generate personalized weekly architectures. Providing this information is optional, but the Service functions best with a complete profile.
During onboarding, you may complete a work profile quiz that categorizes your work style into one of our defined profiles (such as Maker, Analyst, Operator, Strategist, Connector, or Generalist). This classification and your responses are stored to initialize your planning defaults and attention mix targets. Over time we also derive and store a personality profile from your usage, which the AI uses to tailor its tone and suggestions.
As you use the Service, we collect: • Weekly Plans: Your weekly schedules, time block configurations, cognitive mode assignments, planning session data, and day templates • Goals, Projects, and Tasks: Goals and projects you create (including priority, time horizon, estimated effort, and status), milestones, tasks, and their assignments to time blocks • Session Feedback: Your ratings of session outcomes (productive, as planned, interrupted, unproductive) and energy states (energized, normal, stressed, drained), along with optional notes about what you worked on • Daily Check-Ins: Your daily top priority, the energy state you record entering the day, your anchor intent for the day, and any free-text notes you write during your startup or shutdown routine, including notes about what is on your mind • Habits and Rituals: Habits you define, your completion history, and the rituals and ritual steps you configure • Captures and Scratchpad: Quick captures, notes, and scratchpad entries you record for later triage • Attention Mix: Your target percentage allocations across cognitive modes • Block Constraints and Weekly Rules: Your preferred scheduling rules, including day and time preferences for different work modes • Accomplishments and Reviews: Daily accomplishment entries, weekly reviews, and the wins feed generated from them Some of these fields are free text. Anything you type into a note, capture, check-in, or review is stored as you wrote it.
Axis includes optional training and wellbeing features. If you use them, we collect: • Workouts: Workout templates and schedules you build, and logs of completed workouts including date, duration, the exercises performed with their actual sets, personal records, and any notes you add • Mindfulness: Mindfulness and meditation sessions you log, including the practice, duration, date, and any notes • Energy and Wellbeing Signals: The energy states and session feedback described in Section 2.4, which the Service analyzes to surface fatigue and burnout patterns We treat this as sensitive information. See Section 6 for how it is handled and Section 10.4 for how to remove it.
When you use the AI assistant features, we collect: • Messages you send to the AI assistant and the AI's responses • Tool use actions (block creation, task assignments, schedule modifications) initiated through the AI • Token usage metrics per exchange, used to meter AI credits and manage cost Planning and weekly review conversations are stored on your account, attached to the week they relate to, and are retained for the life of your account unless you delete them. We store them so that you can revisit how a plan was arrived at and so the Service can reference earlier reasoning. Other AI chat exchanges are processed in real time and are additionally held in your browser's session storage for continuity within a session. Authorized staff can access stored planning and review conversations. See Section 4.2.
Some parts of the Service let you dictate instead of type. If you use voice capture, the audio you record is uploaded to our servers and forwarded to OpenAI's Whisper transcription API to be converted to text. Uploads are limited to 25MB per recording and are rate limited per account. We do not retain the audio after transcription; we keep only the resulting text, which is then stored with whatever feature you dictated into (for example a capture, a note, or an AI message). OpenAI's handling of the audio is governed by its API terms, which exclude API data from training its models.
Connecting an external calendar (Google Calendar or Microsoft Outlook) is optional. If you connect one, we request read-only access through that provider's OAuth consent screen and store: • The email address of the connected account, used to label the connection • The list of calendars in that account, so you can choose which ones to sync • For events in the calendars you select: event title, start and end time, day of week, attendee count, and the email domains of attendees • OAuth access and refresh tokens, encrypted at rest (AES-256-GCM) We use this data to show your existing commitments alongside your Axis plan, to schedule Axis blocks around fixed events rather than on top of them, and to suggest a cognitive mode for each event. Axis requests read-only calendar permission and does not create, modify, or delete events in your connected calendar. We do not store full attendee email addresses — including the organizer's — nor event descriptions, locations, or attachments. You can disconnect at any time from Settings → Integrations. Disconnecting deletes the stored OAuth tokens and your calendar selections, and stops all further syncing. Events already brought into Axis are kept rather than removed: events you had confirmed have become blocks on your own schedule, and events still awaiting your review are dismissed from your inbox. You remain able to delete any of them individually at any time, and deleting your account removes all of them.
Connecting a fitness account (currently Strava) is optional. If you connect one, we request read access to your activities and store: • Your provider account identifier and display name • OAuth access and refresh tokens, encrypted at rest (AES-256-GCM) • Activity records imported into your workout log, including the activity identifier, date, and duration When you connect, you choose how much history to import (none, 30, 60, or 90 days). We also subscribe to activity webhooks so that newly recorded activities can appear in Axis without a manual sync. This data is used to reflect training load in your week and to relate physical activity to your energy patterns. You can disconnect at any time from Settings → Integrations, which deletes the stored tokens and ends the webhook subscription for your account.
Axis offers an optional desktop bridge that reads from ActivityWatch, a separate open-source time-tracking tool that runs on your own computer. This bridge is not installed by default and does nothing unless you set it up yourself. If you enable it, it sends us, per hour: the application name and key, and the number of active seconds recorded for that application. We use this to compare where your attention actually went against the week you planned. We do not receive window titles, document names, URLs, keystrokes, screen contents, or screenshots through this bridge. You can stop the bridge at any time by disabling it on your own machine, which immediately stops any further data reaching us.
If you submit a bug report or feature request through the Service, we collect the subject and description you write, the page you were on, your browser and device details, and — where you choose to include them — a screenshot and a serialized snapshot of the application state at the time. That snapshot can include the planning data visible on screen when the report was filed. Please avoid including information in a report that you would not want our staff to read.
We automatically collect certain technical information: • Browser type and version • Device information • IP address • Pages visited and features used within the Service • Timestamps of account activity (login times, last activity) • Error logs, client-side error reports, content security policy violation reports, and performance metrics • If you enable push notifications, the device push token needed to deliver them
We use the information we collect to: • Provide the Service: Generate personalized weekly plans, process AI interactions, track goals and tasks, deliver session feedback analytics, and detect patterns in your productivity data • Personalize Your Experience: Use your archetype, profile, feedback history, and attention mix to tailor AI recommendations and planning suggestions to your individual work style and capacity • Reflect Your Real Commitments: Use connected calendar events, connected fitness activity, and — if you enabled it — application usage data to show what your week actually contains and to plan around it • Detect Patterns and Burnout Signals: Analyze your session feedback, energy states, training load, and mode usage patterns to identify trends and provide early warnings about unsustainable work patterns • Process Payments: Manage your subscription through our payment processor, and meter AI credit usage • Communicate with You: Send account-related notifications, lifecycle and digest emails, push notifications you have opted into, respond to support requests, and provide updates about the Service • Improve the Service: Analyze aggregate usage patterns (in anonymized or de-identified form) to improve features, fix bugs, and develop new capabilities • Ensure Security: Monitor for unauthorized access, operate multi-factor authentication, enforce rate limits, and maintain the integrity of the Service
We do not sell your personal information. We may share your information with the following categories of third parties solely to operate and provide the Service:
• Supabase: Provides authentication services and database hosting. Your email, hashed password, and account data are stored on Supabase's infrastructure • Anthropic and OpenAI: Our large language model providers, accessed directly over their APIs rather than through any aggregator, gateway, or model hub. When you use the AI assistant, relevant context from your profile, current week, goals, session history, and synced calendar events is sent to the active provider's API to generate responses. We may change or add AI providers at any time, subject to the restrictions in Section 5 • OpenAI (Whisper): Receives voice recordings you submit for transcription, as described in Section 2.7 • Stripe: Processes subscription payments. Stripe receives your payment information directly; we store only your Stripe customer ID, subscription ID, and subscription status • Vercel: Hosts the application. Standard server logs may be collected as part of hosting operations • Resend: Delivers transactional and lifecycle email on our behalf, and therefore receives your email address and the contents of those messages • Upstash: Provides the Redis service used for rate limiting and for short-lived caching of the context assembled for AI requests • Google and Microsoft: Only if you connect a calendar. We call their calendar APIs with the read-only access you granted, as described in Section 2.8 • Strava: Only if you connect a fitness account. We call the Strava API with the read access you granted, as described in Section 2.9
Axis is operated by a small team. Authorized administrators can, for support, debugging, abuse investigation, and safety purposes: • View account and subscription records • View stored planning and weekly review conversations associated with an account • Temporarily access the Service as your account (impersonation) in order to reproduce a problem Administrative actions of this kind are recorded in an audit log. We access your content only where there is an operational reason to do so, and we do not read it for any purpose unrelated to running the Service. Data received from Google APIs is subject to the additional restrictions in Section 5.1.
We may disclose your information if required to do so by law or in response to valid legal processes, such as a subpoena, court order, or government request.
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.
We take your privacy seriously with respect to AI processing. The following principles govern how your data is handled by third-party AI providers: • Your data sent to AI providers is used solely to generate responses within the Service and is not provided to any AI provider for the purpose of training their language models • We select AI providers whose API terms do not permit the use of API inputs for model training, and we will make commercially reasonable efforts to maintain this standard • We may use multiple AI providers simultaneously or change providers over time to optimize the quality, cost, and reliability of the Service. Each provider is subject to their own data handling policies, and we evaluate these policies when selecting providers • Context sent to AI providers includes relevant portions of your profile, schedule, goals, session history, and connected calendar events necessary to generate useful responses. We minimize the data sent to what is reasonably necessary for each interaction • We do not use your personal data, User Content, or AI interaction data to train our own AI or machine learning models without your explicit opt-in consent
Axis's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. In particular: • We do not use, transfer, or sell Google user data — whether raw, aggregated, anonymized, or derived — to create, train, fine-tune, or improve any foundational or generalized artificial intelligence or machine learning model • When you use the AI assistant, calendar event titles, times, attendee counts, and attendee email domains synced from Google Calendar may be included in the context sent to our AI providers (Anthropic and OpenAI) solely to generate a response for you in that session. Both providers' API terms state that data submitted through their APIs is not used to train their models. We do not use aggregators, gateways, or model hubs, and we do not operate self-hosted models • We do not transfer Google user data to third parties for advertising, credit assessment, lending, or any purpose unrelated to providing or improving the user-facing features of Axis • Google user data is not read by humans except with your explicit consent, to resolve a support issue you have raised, for security purposes such as investigating abuse, or where required by law • Axis requests only the narrowest Google Calendar permissions its features require: permission to see the list of calendars you are subscribed to, and permission to view events on your calendars. Axis does not create, modify, or delete Google Calendar events You can revoke Axis's access at any time from Settings → Integrations within the app, or from your Google Account permissions page at myaccount.google.com/permissions. Revoking access deletes the stored OAuth tokens and stops all further syncing. Events already synced are kept rather than removed — ones you confirmed have become blocks on your schedule, and ones still awaiting review are dismissed from your inbox — and every one of them remains deletable, individually from within the Service or all at once by deleting your account.
Some of what Axis stores — training logs, mindfulness sessions, energy states, and the fatigue patterns we derive from them — concerns your health and wellbeing. We apply the following commitments to it: • We do not sell it, and we do not use it for advertising or profiling outside the Service • We do not share it with employers, insurers, or any third party beyond the service providers listed in Section 4.1 that are necessary to operate the Service • Fitness and mindfulness features are optional. You can use Axis for planning without connecting a fitness account or logging a single workout • You can delete individual workout logs, mindfulness logs, and check-ins from within the Service at any time, and deleting your account removes all of them Axis is a planning tool, not a medical device. It does not diagnose any condition, and nothing it surfaces about your energy or training is medical advice. See the Health and Wellness Disclaimer in our Terms and Conditions.
We retain your personal information for as long as your account is active or as needed to provide the Service. Specific retention details: • Account Data: Retained until you delete your account • Planning, Productivity, Health and Fitness Data (blocks, goals, tasks, feedback, check-ins, habits, workouts, mindfulness logs): Retained for the life of your account to enable pattern detection, trend analysis, and historical insights • Planning and Weekly Review Conversations: Stored on the relevant week and retained for the life of your account • Other AI Chat Data: Processed in real time and not retained on our servers as a separate transcript. Browser session storage is cleared when you close the session • Voice Recordings: Not retained after transcription. The resulting text is retained with whatever feature you dictated into • Connected Account Tokens: Retained, encrypted, until you disconnect that integration or delete your account • Application Usage Data: Retained for the life of your account, or until you delete your account • Payment Records: Retained as required by tax and financial regulations • Admin Audit Logs: Retained as immutable records for security and compliance purposes Upon account deletion, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes.
We implement appropriate technical and organizational measures to protect your information, including: • All API routes are protected by authentication, requiring a valid session for access • All data queries are scoped to the authenticated user, preventing cross-account data access • Optional multi-factor authentication, with trusted device records so you are not challenged unnecessarily • OAuth tokens for connected calendar and fitness accounts are encrypted at rest using AES-256-GCM • Input validation and field whitelisting on all data submissions to prevent injection attacks • Database-level uniqueness constraints and referential integrity • Rate limiting on AI interactions, transcription, and other sensitive endpoints to prevent abuse • Batch operations wrapped in database transactions for data consistency • Administrative actions recorded in an audit log While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee its absolute security.
In the event of a data breach that affects your personal information, we will: • Notify affected users via email within 72 hours of confirming the breach • Provide a description of the nature of the breach, including the categories of data affected • Describe the measures taken or proposed to address the breach and mitigate potential harm • Provide recommendations for steps you can take to protect yourself • Notify relevant regulatory authorities as required by applicable law We maintain incident response procedures to detect, investigate, and respond to potential data breaches promptly.
Depending on your location, you may have the following rights regarding your personal information:
You can access most of your personal information directly through the Service (via your profile, settings, and data views). Axis also includes an export feature that produces a copy of your planning data. You may request a full export by contacting us at support@axisplanner.ai, and we will provide your data in a commonly used, machine-readable format within 30 days of receiving a valid request.
You can update your profile information, preferences, and settings at any time through the Service.
You can delete your account from within the Service. Deleting your account removes your associated records, including planning data, check-ins, workouts, mindfulness logs, stored conversations, connected account tokens, and application usage data. You may also request deletion by contacting our support team. Deletion is subject to the retention exceptions described in Section 7.
Participation in each optional feature is under your control: • You may choose not to provide optional profile information (such as date of birth, marital status, or family details). The core Service will still function, though AI personalization may be less accurate • You can disconnect a calendar or fitness account at any time from Settings → Integrations. This deletes the stored tokens and stops further syncing, and for Strava we also ask Strava to revoke our access. Data already synced into Axis is kept and remains yours to remove — individually from within the Service, or all at once by deleting your account • You can stop the desktop application-usage bridge at any time on your own machine • You can unsubscribe from lifecycle and digest emails using the link in those messages, or disable push notifications from your device. We will still send essential account and security messages
The Service uses cookies for authentication session management (JWT-based session cookies) and to remember devices you have marked as trusted for multi-factor authentication. These are essential cookies required for the Service to function and cannot be disabled while using the Service. We do not use advertising cookies or third-party tracking cookies. The Service uses browser session storage to temporarily persist AI chat messages for continuity within a browsing session. This data is automatically cleared when you close the browser tab.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
The Service is operated from the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Service, you consent to the transfer of your information to the United States.
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. As stated above, we do not sell personal information. To exercise your rights, please contact us using the information provided below.
We may update this Privacy Policy from time to time. When we make changes, we will update the "Effective Date" at the top of this document and notify you via email or through the Service. Where the changes are material, we will ask you to review and accept the updated documents before continuing to use the Service. We encourage you to review this Privacy Policy periodically.
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: RMR Products LLC Email: support@axisplanner.ai