Treasynx ← Back to Treasynx

Privacy policy

Last updated 6 August 2026 · bmvp.ai Ltd

The short version

Your tasks, plans and notes are stored on your phone. Treasynx has no user accounts and no server that holds your day. A few things do leave your device, all of them because you asked: an AI prompt goes to the provider you chose with your key; the microphone sends audio to your phone's speech service if you use it; and three entirely optional features send us something if you switch them on — anonymous usage statistics, crash and error reports, and twelve anonymous numbers describing the shape of a plan. All three are off by default and independent of each other. Everything else stays where it is.

Who we are

Treasynx is published by bmvp.ai Ltd, a company registered in England & Wales (company no. 17126191), registered with the Information Commissioner's Office under reference C1898705. For the purposes of UK GDPR we are the data controller for the limited processing described below.

Privacy questions: support@bmvp.ai
Formal or legal notices: legal@bmvp.ai

What stays on your device

The following never leaves your phone unless you explicitly export or sync it:

This is held in your app's private storage, which other apps cannot read. Uninstalling Treasynx deletes it. We cannot recover it for you, because we never had it.

What leaves your device, and when

Treasynx contacts other services only for specific features. Each one is listed here with what it receives.

ServiceWhenWhat it receives
OpenWeatherMap Only when you use weather-aware trip planning Approximate coordinates or a place name, and the time you're planning for.
OpenStreetMap
& Overpass
Only when you ask for nearby places or a route Approximate coordinates and a search radius.
OpenRouteService Only when you request directions Start and end coordinates.
Your chosen
AI provider
Only when you generate or adjust a plan with AI The planning prompt, which may include task titles you've written. Sent from your phone directly to the provider you configured, using your key. It does not pass through us and we never see it.
Your chosen
AI provider
(wellness)
Only when you ask for wellness suggestions with AI switched on for that feature Selected fitness, food or health entries — shown to you before sending. Requires a separate consent beyond the general AI setup. Never sent as part of the general planning prompt.
Your WebDAV
server
Only when you sync a backup Your encrypted backup file, sent to a server address you supplied — your Nextcloud, Koofr or similar. Not ours.
PostHog
(EU hosted)
Only if you switch analytics on, which is off by default Which screen was opened and which features were used. A random device id not linked to you. No task content, no keystrokes, no screen recording, no automatic tap capture.
PostHog
(EU hosted)
Only if you switch analytics on — crash/error reports travel the same channel Stack traces and error messages when the app crashes or encounters an error. These contain code-level information (class names, method names, line numbers) but never task titles, notes, prompts, AI responses, or any content you entered.
Your phone's
speech service
Only while you hold the microphone in the schedule interview The audio you speak. Android hands this to whatever speech service is installed — on most phones Google's, which transcribes it on their servers. We never receive it and never store it. Typing gets the same result if you'd rather not.
Supabase
(EU, Ireland)
Only if you switch on "Help train the model", which is off by default Twelve numbers describing the shape of a plan, and whether you kept it. Never task titles, notes, dates, times or anything you typed. See Donating plan shapes below.
Open-Meteo Only when you ask for a hobby recommendation Your coordinates, rounded to about a kilometre. Returns daylight, air quality, wave height, UV, frost, soil temperature and snow depth. No key and no account, so nothing identifies you. Only the endpoints your own active hobbies need are called — if your only hobby is gaming, no request is made at all.
Your chosen
AI provider
(your notes)
Only when you generate a plan, and only if the "notes" context source is on Up to four Basalt notes relevant to that day's tasks, found by word matching on your device. No note is sent anywhere to be indexed. Titles are included so the model can cite which note it used.
Your phone's
calendar
Only after you grant permission and tap import Read-only, one day at a time. Events are shown to you and discarded; only the ones you tick become Treasynx blocks. Goes nowhere — not to us, not to an AI. The write permission is absent from the app, so it cannot change your calendar.
Google Play Only when you buy a subscription or consumable Handled entirely by Google Play Billing. We receive confirmation that a purchase occurred; we never see your card details.

Bring your own AI key

Treasynx does not operate an AI service. If you use the AI features you supply your own key, and your request goes straight from your phone to that provider, governed by their privacy policy rather than this one. It is worth reading the one that applies to you.

Sixteen are supported: Anthropic, OpenAI, Google Gemini, Grok (xAI), Groq, DeepSeek, Mistral, OpenRouter, Together, Fireworks, Cerebras, Perplexity, DeepInfra, and any other OpenAI-compatible endpoint — plus two that involve no third party at all: Ollama or LM Studio on your own machine, where nothing leaves your network, and the on-device model, where nothing leaves your phone.

Two are worth flagging rather than burying in a list. DeepSeek is operated from China, so your prompts would be processed there. Perplexity searches the web to answer, which means your prompt shapes outbound searches. Neither is a reason to avoid them; both are a reason to choose knowingly.

Running the AI on your phone instead

You can install a small language model on the device and use the AI features with no key, no account and no network at all — aeroplane mode is a valid way to run it. In that configuration nothing about your schedule leaves the phone, which is a property of the wiring rather than a promise you have to trust.

We do not supply or host the model. You download it from its publisher and accept their licence — for the Gemma models, Google's Gemma Terms of Use. bmvp.ai Ltd is not a party to that licence and does not check it; complying with it is between you and the publisher. The file lives in the app's private storage and no new phone permission is required.

If you switch on local training, a small scorer is trained on your phone from which plans you keep, and used to choose between drafts. That training never leaves the device. It is not the language model changing — no phone can retrain a language model, and we do not claim otherwise.

Fitness, food & health data

Treasynx includes optional diaries for movement, meals and daily health (sleep, energy, mood, soreness, water, weight). All entries are stored locally on your device and are never uploaded to us. Health data is special category data under Article 9 of the UK GDPR, and each diary is off until you switch it on individually.

The one path by which health data can leave your device is the optional AI suggestions feature inside the wellness screen. This requires its own separate consent — beyond the general AI setup — and you are shown exactly what will be sent before each request. Health entries are never added to the general AI context used by the planner, the agent, the chatbot or the chief of staff. The wellness screen builds its own prompt, on its own consent.

Weight logging is behind a further switch and an age confirmation (self-declared, 18+). There are no calorie figures, no targets, no BMI, no body-fat estimates, and no gamification of food or body metrics. A safeguard watches for patterns that may indicate disordered eating and suppresses AI suggestions when one is detected, showing support information instead.

Voice input

The microphone in the schedule interview is optional and does nothing until you tap it. When you do, Android passes the audio to your phone's speech recognition service, which on most phones is Google's and works by uploading the recording for transcription. We never receive the audio, never store it, and cannot see it — but it does leave your device, and it goes to a company you did not pick as an AI provider. The first time you tap the microphone the app explains this and asks. Typing produces exactly the same result.

Donating plan shapes

This is the only feature in Treasynx that sends anything to us, and it is off unless you switch it on in AI settings. There is no prompt, no reminder, and nothing in the app works worse if you decline.

What is sent

Twelve numbers describing the shape of a plan — what fraction of the day was focus work, how long the average block ran, how many blocks there were, and so on — plus whether you kept, edited or rejected it. Alongside those: a random identifier generated on your phone, which model produced the plan, and the app version.

Never sent: task titles or notes, dates, the time of any block, prompts, anything an AI wrote for you, your location, your device model, any advertising identifier, or any account detail. The payload cannot be turned back into a schedule because the schedule was never in it. You can see the exact data in the app before agreeing.

Why we ask

The scorer that learns which plans you keep needs roughly twelve examples before it says anything and a few hundred before it is any good, so every new install is useless for weeks. Pooled shapes let a sensible starting scorer ship inside the app, so one person's first week benefits from other people's second month. That is the whole purpose. It is not sold, not shared with anyone, and not used for advertising — there is no advertising in Treasynx.

Basis, processor and retention

Withdrawing, and one catch worth knowing

Use Withdraw and delete everything on the donation screen. Collection stops at once, the queue on your phone is erased, and the server is told to delete every row your install has sent. If the server can't be reached you are told so and given an email address, rather than left to assume it worked.

The catch, stated plainly because it is a real limitation of the privacy-preserving design: donated rows carry only that random identifier, stored nowhere but your phone. That is what stops the data being traceable to you — and it is also the only thing that lets us find your rows in order to delete them. If you clear the app's data or uninstall without withdrawing first, that identifier is gone and we can no longer locate your rows on request. So withdraw first, then clear. We would rather tell you that now than discover it together later.

Analytics

Off unless you switch it on. Treasynx collects no usage statistics at all until you agree to it, on a card in Settings → Privacy & compliance. Declining changes nothing about how the app works, and you are asked once rather than repeatedly.

What is collected if you agree: which screen was opened, and which features were used. The complete list of possible events is printed inside the app next to the switch, so you can read it rather than take our word for it. As of this version it is: screen opened, plan generated, plan accepted, plan rejected, on-device model installed, alarm set, tier upgraded, bug reported.

What is never collected: task titles, notes, prompts, AI responses, block times, dates, your location, your device model, or any advertising identifier. Automatic tap capture and session replay are switched off in the code rather than left to the library's defaults, because autocapture can lift the text of a task title out of a view label.

One piece of history worth recording, because we would rather you heard it from us. This page previously described PostHog in detail, including a setting to switch it off, at a time when the library had been added to the project and never actually started. No event was ever sent and no setting existed — the page was written for the version of the app that was planned rather than the one that shipped. The implementation is real now. The rule that follows from the mistake is that this page and the code change together or neither changes.

Crash and error reporting

Crash and error reports are collected through the same PostHog integration as analytics, and are governed by the same consent switch. If analytics is off, crash reporting is off too. There is no separate toggle and no silent fallback.

What is collected: stack traces, error messages, and the class and method names where a crash or error occurred. These are code-level diagnostics — they tell us which line of our code broke, not what you were doing when it broke.

What is never collected: task titles, notes, prompts, AI responses, screen content, health entries, finance data, or any text you entered. Autocapture is off, so no view hierarchy or screen state is included in the report.

Separately from all of this, Android itself reports crashes to Google Play if you have Google's "usage and diagnostics" setting switched on. That is controlled entirely by your Android settings, not by us, and we see those reports only in anonymised, aggregated form in the Play Console.

One piece of history, on the same rule as the analytics section. This page previously said we used Firebase Crashlytics; we did not, and never have — the text described something planned and not built. It was corrected rather than quietly deleted. PostHog crash reporting is real now and is what this section describes.

Checking for new AI models

The model optimiser is optional and off by default. Switched on, it asks each provider you already hold a key for which models it currently offers, so it can warn you when the one you use is retired — which would otherwise break your AI features with no explanation. The request carries your key and nothing else: no schedule, no prompt, no personal data. It runs only while the app is open, never in the background, and at the interval you choose.

Reporting AI output

Every AI-generated response carries a control to report it. Choosing a category and sending opens your own email app with a message addressed to us, which you can read before it goes. Whether the AI's response is attached is your choice and is off by default, because a response is built from your schedule and can repeat your own notes back. A report without it is still useful — the category and the model are the two things that matter most.

Location

Location is optional and used only for weather and nearby places. Treasynx requests coarse or fine location only at the point you use one of those features, never in the background, and does not store a location history. The coordinates are used for a single API call to OpenWeatherMap or OpenStreetMap and then discarded — they are held only in memory and never written to storage. Deny the permission and the rest of the app is unaffected — you can type a place name instead.

Backups and encryption

Exports can be encrypted with AES-256-GCM, with the key derived from your passphrase using PBKDF2. The passphrase is never stored and never transmitted. If you lose it, the backup cannot be opened — not by us either. Where you put the file is your choice; if you sync it to a third-party service, that service's policy applies to the file at rest.

Autosave, and what survives what

Four different questions with four different answers, set out plainly because "will I lose my schedule?" is the thing people most need a straight answer to.

What happensWhat survives
Closing and reopening the app Everything. Nothing to do.
Updating Treasynx Everything. An app update never touches your data.
Uninstalling and reinstalling Android 10 and later offer to keep your app data at uninstall — tick it and everything is still there. Google's own backup restores it automatically if you have that switched on. And autosave has already written a copy to Documents/Treasynx, restorable in one tap.
Factory reset, lost phone The Documents copy goes with the device. For this you want the optional autosave folder pointed at a drive you sync, or an encrypted export kept elsewhere.

Google's Android backup

This is an Android feature, not one of ours. If you have backup switched on in Android Settings → Google → Backup, Android sends an encrypted copy of Treasynx's settings to your own Google account and restores it automatically when you reinstall. The copy is encrypted with a key derived from your device screen lock; we never see it, never receive it, and cannot switch it on or off for you.

Three things are deliberately excluded from it: your analytics consent and identifier, your plan-shape donation consent, and the register of alarms. Restoring a consent is not the same as being asked for one, and restored alarms would list things that will never ring.

Autosave

Autosave has three tiers, and which are on by default differs. The differences are worth reading once.

One limitation of the Documents tier, stated here rather than left to be discovered. Android shows an app only the files it wrote itself, and a reinstalled app counts as a new app for that purpose. So your autosaves survive the uninstall but the fresh install cannot see them, and the screen will look empty. Recovery is one step: tap "Restore from a file" and pick the newest one out of Documents/Treasynx in the system picker. Automatic would be better, and getting it would mean asking for a permission that lets the app read your whole device — a worse trade than one tap.

Autosave files are not encrypted. Encrypting them would mean asking for your passphrase every time you left the app, and a passphrase stored to avoid asking is not encryption. So those files contain your task titles, notes, health diary entries, Finance holdings and AI API keys in readable form, in a folder other apps holding storage access can read. If that is not a trade you want, switch it off on the Your data screen — nothing else in the app changes, and the encrypted export is still there for anything you want to put somewhere less private.

Seeing everything we hold

Under UK GDPR you have a right of access and a right to portability. Because your data is on your device and we hold no copy, both are answered in the app rather than by writing to us and waiting a month.

Settings → Storage & cache → Your data lists every store the app writes, with a plain-English description of what is in it, its size, and whether it travels in a backup. "Export everything" writes the lot to one file you choose the location of.

Values are deliberately not printed on screen — showing every key's contents would put your API keys and health entries in front of whoever is next to you. The export is the proper route to the actual contents, and it is one tap away.

Your phone's calendar

Optional, off until you ask, and read-only. Treasynx can pull an appointment out of your phone's own calendar rather than making you retype it.

A calendar holds who you are meeting and where, which is more revealing than the schedule this app keeps. So the reason for the permission is explained on screen before Android asks you anything, and declining costs you nothing else.

Your notes, and what the AI can now see

This widens what an AI provider receives, so it is worth reading rather than skimming.

Basalt notes used to be invisible to the AI. They are not any more. When you generate a plan, the app searches your notes for ones relevant to that day's tasks and includes up to four in the prompt — so a note saying "no deep work for an hour after the gym" can actually change tomorrow.

The search runs entirely on your device: word matching over each note's title, tags and body, plus one hop through the links you drew between notes. No embedding model is used and no note is sent anywhere to be indexed — doing that would have quietly turned "your notes stay on your phone" into a false statement.

Note titles are included deliberately, so the model can cite which note it used and you can check it. Retrieval is sometimes wrong, and an uncited wrong note becomes a confident false premise. To stop it entirely, switch off the "notes" context source in AI settings.

Measured durations

Off until you switch it on. With it on, starting and finishing a block records two timestamps on your device, and the app works out how long things actually take you per category against what you planned.

It reports the median ratio, and only where there are at least eight measurements for a category — below that it reports nothing rather than a figure with a caveat. The median rather than the average, because a block cannot take less than no time but can take five times the estimate, so one bad afternoon would drag an average permanently.

What goes to an AI provider is the per-category bias figures, not the individual blocks or their titles. Running over is information about an estimate, not about you.

Hobby conditions

When you ask what to do with your free time, the app fetches real conditions and scores your hobbies against them. What it fetches depends entirely on which hobbies you switched on.

The source is Open-Meteo, which needs no API key and no account. Moon phase is not fetched at all — it is arithmetic the phone does without a network.

Coordinates are rounded to two decimal places, roughly a kilometre: precise enough for weather, imprecise enough not to identify a house. Nothing else is sent — no hobby names, no schedule, no identifier.

The recommendation is computed on your device from rules shown on screen, each with its reason. Your AI provider, if you have one, is then asked to phrase the result and is given the reasons rather than the raw data, so it cannot invent a justification the numbers do not support.

No AI is set up until you set it up

On a fresh install no AI provider is configured, none is enabled, and no AI feature will attempt a network call.

An earlier version got this wrong, and it is worth saying so. The app shipped with a default pointing at a local Ollama address, and because Ollama needs no API key the app believed AI was already configured. Features appeared available then failed, the prompts that would have told you to set AI up never appeared, and the multi-model features thought they had a provider. It is fixed.

Deleting your data

All your data is stored locally on your device. Uninstalling the app or clearing app data from Android Settings removes everything. The app also provides an "Erase everything" option on the Storage & cache screen.

For plan-shape donation data stored on our servers (Supabase), use the "Withdraw and delete everything" button on the donation screen, or email support@bmvp.ai to request deletion.

Lawful basis for processing

PurposeBasis
Running the app on your deviceContract — you asked for a planner
Weather, places, routesConsent, by choosing to use the feature
AI planningConsent, by configuring a provider and key
Wellness AI suggestionsExplicit consent under Article 9(2)(a), given per request
Anonymous analyticsConsent, switchable off in the app at any time
Crash and error reportingConsent (same switch as analytics)
Voice inputConsent, by choosing to use the microphone
Donating plan shapesConsent, withdrawable in the app at any time
Purchases and refundsContract, and legal obligation for records
Learning how you workLegitimate interests, with controls to pause or erase
Reading your calendarConsent, granted per device and revocable in Android settings
Hobby condition dataConsent, by asking for a recommendation
Measured durationsConsent, switchable off; stays on the device

International transfers

Analytics events and crash reports, if you enable them, are held by PostHog on EU infrastructure. Open-Meteo is operated from Germany, inside the EEA. Donated plan shapes are held by Supabase in Ireland, which is inside the EEA and covered by the UK's adequacy decision, so no additional transfer safeguard is required. If you choose a non-UK AI provider or WebDAV host, your request travels to wherever they operate — a transfer you initiate and control by choosing that provider. Voice audio goes wherever your phone's speech service processes it, which for Google's is subject to Google's own policy.

Retention

On-device data lives until you delete it or uninstall. Analytics events and crash reports are retained by PostHog on a rolling basis and are not tied to you. Donated plan shapes are deleted 18 months after collection, or sooner if you withdraw. Purchase records are kept as long as UK tax and accounting law requires.

Your rights

Under UK GDPR you can request access, correction, erasure, restriction, portability, and object to processing. In practice, for most of it you don't need us: your data is on your device, exportable to a file you hold, and deletable by you at any time. For anything concerning analytics, crash reports, or purchases, write to support@bmvp.ai and we'll respond within one month.

If you're unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.

Children

Treasynx is not directed at children under 13 and we do not knowingly collect data from them. There is no social feature, no user-to-user messaging and no public profile. The optional plan-shape donation is restricted to users aged 18 or over. Weight logging and AI-powered food suggestions are restricted to users who have confirmed they are 18 or over.

Changes to this policy

If we change how data is handled we'll update this page and the date at the top, and note material changes in the app's release notes. The current version always lives at treasynx.com/privacy.