1. Who we are
Targela is operated by Atefeh Salahshoor Goolan ("we", "us"). For questions about this policy or your data, contact us at [email protected].
2. What data we collect
Account data
When you create an account we collect your name, email address, and (if you use email/password sign-up) a hashed password. If you sign in with Google, we receive your Google profile information (name, email, profile picture) as provided by Google. Following data minimization principles, we intentionally collect age ranges (e.g. 25 to 34) rather than exact dates of birth.
Academic email (student price)
If you request the student price band, you may provide a second email address at a recognised academic domain. That address is used only to verify student status. It does not become your login address and does not replace the email you sign in with. Verification tokens are short-lived; yearly re-confirmation may be required. See also student verification in the product and our Terms.
Billing and payments
When you subscribe we process payment through Stripe. Stripe receives the data needed to charge you (for example card details entered on Stripe-hosted pages, customer and subscription identifiers). We store subscription status, price band, period dates, and provider customer/subscription ids in our database. Tax invoices and statutory billing records may be retained after account erasure as required by German commercial and tax law; those retained rows are anonymised so they no longer identify you.
Goals and plans
Targela stores the goals, constraints, and step plans you create. This content is free text and may include personal details you choose to enter. Please avoid entering special-category data (e.g. health, religion) unless necessary for your goal.
Preferences
We store appearance settings (light/dark/system theme) in your account. The web app may also remember your theme choice in browser storage.
Technical data
When you sign in we store session metadata including IP address and browser user agent for security and fraud prevention. On the web, authentication uses an HttpOnly session cookie scoped to our domain. On the native mobile app, we use a bearer token stored in your device's secure storage.
Website visitors (no account)
If you use our marketing site without signing in:
- Contact form: name, email, subject, and message, stored in our database and emailed to us via Resend.
- Waitlist: email address and optional source, stored in our database.
- Bot protection: Cloudflare Turnstile may process interaction data when you submit these forms or sign in on the web (see Cookie Policy).
Push notifications (native app)
If you allow notifications in the native app, we store a device registration token issued by Firebase Cloud Messaging, together with the platform (iOS or Android), your language, and your time zone, so reminders arrive in the right language at the right local time. The token identifies an app install, not you personally, and is deleted when you sign out of that install or delete your account. Delivery runs through Google Firebase Cloud Messaging. Turning notifications off in your device settings or in Settings → Notifications stops this processing.
Google Calendar (optional)
If you connect Google Calendar, we store the connection details needed to keep your plan steps in sync: the Google account email and account id, the id of the calendar you sync to, the granted scope, sync state, and the Google event ids of steps we created. OAuth tokens are stored encrypted and are never included in your data export. Disconnecting the calendar, or deleting your account, revokes our access at Google and removes the connection.
Announcement emails
Separately from account emails, we may send occasional product announcements to registered users. Every such email carries a one-click unsubscribe link, and you can opt out at any time; we record only the fact and time of your opt-out. Opting out never stops transactional account emails (verification, password reset, billing notices), which are part of providing the service.
Analytics (with your consent only)
If you accept analytics cookies on our marketing site or web app, we collect product usage events (e.g. plan created, step completed), page views, and JavaScript errors via PostHog EU. The same events may also be written to Cloudflare Workers Analytics Engine when our API receives your consent cookie (masir_consent). We use an internal user ID, not your email or name, in analytics. See our Cookie Policy for details.
Analytics load on the web app only (PostHog and Cloudflare Web Analytics beacon). The marketing site stores your consent choice but does not load those scripts. The native mobile app does not load PostHog or the web analytics beacon.
Error and performance monitoring
When enabled, Sentry receives error reports, stack traces, and performance traces from our web app, admin dashboard, API, and (optionally) native mobile app. This processing is not covered by analytics cookie consent; it supports reliability and security under our legitimate interest.
On the web and admin apps, session replay is recorded only after a critical error, not during normal browsing. These replays are strictly configured to mask all user text, inputs, and personal data by default, and are used solely to resolve critical application crashes. When you are signed in, we attach your internal user ID to Sentry events, not your email or name.
Installable web app (PWA)
The Targela web app at https://app.targela.com can be installed and caches its interface assets in your browser so pages load faster. Plan data is loaded from our servers when you are online and requires an active connection.
Native mobile app
The iOS and Android app stores your session token in secure storage and loads plans from our API when online. It also keeps a local copy of your recent plan, settings, and draft data on the device so the app works offline; clearing the app's data or uninstalling removes it. It does not share the web app's PWA service worker cache. You can delete your account from Settings → Account in the app (same API as the web app). Data export runs in the web app, where the archive downloads as a file you keep; Settings → Privacy in the native app links you there.
3. Why we use your data (legal bases)
- Contract (Art. 6(1)(b) GDPR): providing your account, storing plans, sending account emails (verification, welcome, password reset, referral notifications), and delivering the service you signed up for.
- Consent (Art. 6(1)(a) GDPR): analytics and optional tracking cookies on our marketing site and web app, push notifications on the native app, and product announcement emails. You can withdraw any of these at any time, via Cookie settings, your device notification settings, or the unsubscribe link in any announcement.
- Legitimate interest (Art. 6(1)(f) GDPR): session security (IP address, user agent), abuse prevention (including Turnstile on forms), and error/performance monitoring (Sentry), balanced against your rights.
4. Processors and subprocessors
We use the following service providers to run Targela:
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare | Hosting, API Workers (Hyperdrive), Workers AI (plan generation), Turnstile, Workers Analytics Engine, optional web analytics beacon | Global / EU edge |
| Supabase | Managed Postgres database (masir-db) | EU (Frankfurt) |
| Stripe | Payment processing, invoices, Customer Portal for paid subscriptions | United States / EU (Stripe) |
| PostHog EU | Product analytics on web app (consent required) | EU (Frankfurt) |
| Sentry | Error monitoring, performance traces, optional session replay on errors | United States |
| Resend | Transactional email (verification, welcome, password reset, referral notifications, billing notices, contact form delivery) | United States |
| OAuth sign-in; optional Google Calendar sync when you connect it | Global / United States | |
| Google Firebase | Cloud Messaging delivery for native app push notifications | Global / United States |
Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses where applicable.
5. AI plan generation
When you create or adjust a plan, text you enter as goals or instructions may be processed on Cloudflare Workers AI using hosted models such as Gemma 4 (@cf/google/gemma-4-26b-a4b-it) or, if the primary model is unavailable, a Meta Llama 3.3 70B fallback (@cf/meta/llama-3.3-70b-instruct-fp8-fast). Inference runs entirely on Cloudflare's infrastructure; Google and Meta do not receive or process your prompts.
We process this data to provide the feature you request (contract basis). Generation metadata may be stored in our database for debugging and quality. Your goals and plans are processed securely to provide the service and are not used to train the underlying AI base models.
Cloudflare acts as the processor for this inference. See Cloudflare's privacy policy.
6. Retention
- Account and plan data: until you delete your account or individual plans.
- Sessions: up to 7 days, with session activity refreshed at least every 24 hours while you remain signed in.
- Verification tokens: until used or expired.
- Push device tokens: until the install is signed out, the token is replaced by the platform, or your account is deleted.
- Google Calendar connection and event links: until you disconnect the calendar or delete your account.
- Announcement opt-out record: kept for as long as your account exists, so we do not email you again by mistake.
- Contact and waitlist submissions: until no longer needed for the purpose you submitted them, or until deleted by us.
- Analytics: per PostHog, Cloudflare Analytics Engine, and Cloudflare Web Analytics retention settings (typically up to 90 days).
- PWA shell cache: until the app is updated or you clear site data in your browser.
- Subscription and billing records: financial facts (periods, provider references, event log) may be kept after erasure for statutory retention. On erasure we anonymise those rows and stop using them to contact or re-identify you. The exact retention periods for German B2C billing will be confirmed and stated here before paid subscriptions go on sale.
7. Your rights
Under GDPR you have the right to:
- Access your data (export from Settings → Privacy in the web app at https://app.targela.com)
- Rectify inaccurate data (edit profile in the app)
- Erasure ("right to be forgotten"): delete your account from Settings → Privacy (web) or Settings → Account (native app)
- Data portability: export your data from Settings → Privacy in the web app
- Restrict or object to processing where applicable
- Withdraw consent for analytics at any time (Cookie settings on our marketing site and web app; Settings → Privacy on the web app), for push notifications (device settings or Settings → Notifications in the native app), and for announcement emails (unsubscribe link in any such email)
- Lodge a complaint with your local supervisory authority
Your export arrives as a zip holding a machine-readable targela-export.json and a readable targela-export.html you can open in any browser, offline. Because it contains everything we hold about you, we ask you to confirm your password first (or, if you signed in with Google, to have signed in recently), and we email you whenever an export is prepared so you would notice one you did not ask for.
You may also email [email protected] for export, deletion, or other requests.
8. Children
Targela is not directed at children under 16. We do not knowingly collect data from children. Contact us if you believe a child has provided personal data.
9. Changes
We may update this policy. Material changes will be posted on this page with an updated date. Continued use after changes constitutes acceptance where permitted by law.
10. Contact
Atefeh Salahshoor GoolanEmail: [email protected]
Website: https://targela.com