✓ No trackers. ZoneIn contains no analytics SDKs, no advertising SDKs, no ads, and does no cross-app tracking. We don't sell data — there's nothing to sell.
✓ No account needed. Every core feature works without signing in. Your tasks live on your own device.
✓ AI that doesn't train on you. Sorting runs on Google Cloud Vertex AI through our own private server. Under Google Cloud's terms, your content is not used to train AI models.
✓ Erase anytime — yourself. Settings → Data gives you one-tap buttons to export everything (JSON), delete your cloud data, and erase this device. No emails, no waiting, no account-closure hoops.
What data exists, and where
- Your tasks are stored on your device. If — and only if — you sign in for sync, an encrypted copy is kept in your private cloud record that only your login can read. We (the developers) cannot browse your tasks.
- Photos of paper lists are sent once to the AI to be read, then discarded — we don't keep a photo library.
- Your email address is stored only if you enable sync, purely as your sign-in identity.
- That's the whole list. No name, no phone number, no location, no contacts, no advertising ID, no usage analytics.
How the AI handles your words
When you tap Organize My Week, your task text (or list photo) is sent through our own backend server to Google Cloud Vertex AI, which does the sorting and sends the result straight back. Three things make this unusual for a consumer app:
- Google Cloud's terms prohibit using your content to train their AI models.
- No AI credentials exist inside the app — every request goes through our authenticated, rate-limited server.
- Processing is transient: the AI reads, sorts, responds. Your tasks aren't accumulated into an AI profile of you.
A sensible habit for work tasks: the AI needs to read your words to sort them — that's what AI processing is. If a task is genuinely confidential, phrase it the way you'd write it in a notebook: "Review the acquisition contract — Friday" works perfectly without naming names or numbers.
Sync security
- Everything is encrypted in transit (TLS) and at rest on Google's infrastructure.
- Access rules are enforced server-side: your record is readable and writable by your login only. There is no way to list or browse other users' data.
- Subscription status and any credentials are deliberately never part of the synced data.
Honest limitations
ZoneIn is an independent product in alpha. We don't yet hold formal certifications (SOC 2 / ISO 27001) — on the roadmap alongside an optional end-to-end encrypted vault for people who want storage only they can decrypt. We'd rather tell you this plainly than imply enterprise guarantees we don't yet have. One note for alpha testers: deleting your cloud data does not revoke your lifetime-access grant — that record is kept so your entitlement survives.
Your controls (all self-serve, in Settings → Data)
- Export my data (JSON) — download every task, archive, and week record in a readable format. Your data is portable, not captive.
- Delete my cloud data — one tap removes your synced record from the cloud and turns sync off. Your device copy stays until you say otherwise.
- Erase this device — wipes all local data instantly.
- Sign out — stops all syncing; the app keeps working locally.
- Anything else — including full rights requests (access, correction, objection), honored for every user worldwide: chadquesnel@gmail.com.
Delete your ZoneIn AI account & data
You can delete everything yourself, in the app, right now — no email, no waiting:
- Open Settings → Data in ZoneIn AI.
- Tap Delete my cloud data — this permanently removes your synced record (tasks, plans, notes, tags, archive, week history) from our servers and signs you out.
- Optionally tap Erase this device to wipe the local copy too.
To delete your sign-in account itself (the Google or email identity used for sync), email chadquesnel@gmail.com from that address with the subject "Delete my account" — completed within 72 hours, confirmation sent.
What is deleted: all synced content (tasks, steps, notes, target dates, tags, archive, week history) and, on account deletion, the sign-in identity. What may be retained: alpha testers' lifetime-access grant records (kept so the entitlement survives data deletion — removed too if you ask), and nothing else; we keep no backups of deleted content beyond a ≤30-day infrastructure backup cycle.