Privacy Policy

Last updated: July 17, 2026

$ cat controller.txt

Data controller: Aldo Website LLC (operating aldowebsitellc.xyz and the Aldo's Toolkit app), Park City, Utah, USA.

Contact: hello@aldowebsitellc.xyz

Covered products: this website (aldowebsitellc.xyz) and the Aldo's Toolkitapp (package xyz.aldowebsitellc.toolkit) on Google Play and the Apple App Store. The two share a single Supabase backend, so the data-processing rules below apply to both unless a section specifically scopes itself.

Aldo Website LLC is a small US-registered company running a personal portfolio, blog, service offering, and the Aldo's Toolkit app. It does not have a formal EU representative, but all requests from EU/EEA residents are honoured under GDPR.

$ cat data-processing.txt

Contact form submissions

Data: name, email address, message text.

Purpose: to respond to your inquiry.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), responding to an unsolicited message you initiated.

Retention: up to 12 months, then deleted.

Account registration & authentication

Data: email address, hashed password, or a Google/Apple sign-in identifier (with Sign in with Apple we may receive only Apple's private email relay address), optional display name.

Purpose: to provide account-based features (comments, ratings).

Legal basis: performance of a contract (Article 6(1)(b) GDPR), you requested an account.

Retention: until you delete your account, or after 24 months of inactivity.

Comments & ratings

Data: your comment text, star rating, and user ID. This content is publicly visible.

Purpose: to display user-generated discussion on blog posts.

Legal basis: consent (Article 6(1)(a) GDPR), you actively submitted the content.

Retention: until deleted by you or by an administrator.

Payments

Data: purchase amount and Stripe session ID. No card numbers are stored on this site.

Purpose: to fulfil a purchased service.

Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Retention: 7 years (legal obligation for financial records).

Server & access logs

Data: IP address, browser type, pages visited, timestamp.

Purpose: security monitoring and operational diagnostics.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), keeping the site secure and operational.

Retention: server and platform logs are kept for our hosting provider's (Vercel) standard log-retention period for our plan, then automatically deleted; we do not keep a separate copy. Crash and error data sent to Sentry is retained under Sentry's default retention.

$ cat aldo-toolkit-app.txt

The mobile app (Android and iOS) uses the same backend as the website, plus a few extra integrations specific to mobile features. Everything below is in addition to the data-processing rules above.

On-device storage (never leaves your device)

Data stored only on your device (AsyncStorage) and deleted when you uninstall: your saved dev-tool results and history (hash, base64, UUID, JSON outputs and their history), tip-out calculator shift records (including coworker first names you enter and any attached POS-slip photo), app settings and preferences (stay-signed-in, quick actions, onboarding, daily-reminder time, Dexter visibility), and the on-device credential vault (see below).

These never leave your device. NOTE: notes, code snippets, flashcard progress, daily-question streak, pomodoro sessions, game scores, and favorites are stored locally first but also sync to our Supabase backend when you are signed in (see Cross-device sync below); uninstalling does not delete the synced cloud copy.

Legal basis: performance of a contract (Article 6(1)(b) GDPR), required for the app to function.

Cross-device sync (signed-in users only)

When you are signed in, the following sync to your private, row-level-security-protected Supabase rows keyed by your account user ID: notes, code snippets, flashcard progress, daily-question streak, pomodoro sessions, game scores, favorites, and app-open counts. Deletions are recorded as tombstones (so a delete on one device propagates to your other devices).

Your username/display name (and, if you sign in with Google, your provider avatar URL) are stored in your Supabase account profile. Your account user ID and session token are also used to authenticate every request the app makes to aldowebsitellc.xyz (AI features, account actions).

Purpose: roam your notes, snippets, streaks, sessions, scores, and favorites across devices.

Legal basis: consent (Article 6(1)(a) GDPR), sync only happens once you sign in. Sign out and the cloud copy stays unchanged; the local copy persists. Everything synced is removed when you delete your Toolkit account.

Retention: until you delete your account, or after 24 months of inactivity.

On-device credential vault (password manager)

The app includes an optional credential vault (label, username, password, URL, notes). Entries are stored encrypted at rest in the OS keystore (Android Keystore / iOS Keychain via expo-secure-store), gated behind your device biometric or PIN unlock, and any generated passwords come from a secure random generator.

Where: on your device only. Vault data never syncs to the cloud and never leaves your device; we cannot see, recover, or reset it. Uninstalling the app or clearing its data deletes the vault permanently.

Legal basis: performance of a contract (Article 6(1)(b) GDPR), the feature you chose to use.

Account session tokens on device

Data: your Supabase session (access token, refresh token) and account user ID, cached in on-device storage (AsyncStorage) so your session persists across app restarts.

Where: stored on your device; the token is sent to aldowebsitellc.xyz as the bearer identity for server calls (AI, account, admin actions). Signing out clears it.

Legal basis: performance of a contract (Article 6(1)(b) GDPR), required to keep you signed in.

AI features (AI Tutor, Dexter assistant, Image AI)

The app ships three AI surfaces: the AI Tutor (study Q&A), the in-app Dexter assistant (free-text chat), and Image AI (analyse a photo). They send your typed text, recent chat history (last ~16 messages), and any image you pick from your library or camera (as base64, up to ~4.5MB) first to our own server at aldowebsitellc.xyz, which holds the model keys and relays it to a third-party model provider (Groq running Meta Llama, or Google Gemini, whichever is configured) for inference.

We do not store the prompts, chat content, or images in our database; we store only a per-user daily usage count. The providers may log requests for abuse prevention under their own policies.

Don't paste real secrets, credentials, IDs, or other sensitive PII, anything you wouldn't put on a public pastebin.

The AI Tutor free tier is limited to 10 questions per UTC day, counted against your signed-in account (a per-user daily counter stored in our database). The in-app Dexter assistant has a separate 100/day per-user limit.

Legal basis: consent (Article 6(1)(a) GDPR), you initiate every send.

Weather on the home dashboard

Data: your device's approximate (coarse) latitude and longitude. We request only approximate location; precise/fine location is blocked in the app manifest.

Where: requested when the weather card loads and sent to Open-Meteo for the forecast and to your device's reverse-geocoding service for a city label. We do not store the coordinates (they exist only in memory for the request), but Open-Meteo and the geocoder receive them and may log the request under their own policies.

This is the only feature that uses location. Denying the permission simply hides the weather card; the rest of the app works normally.

Legal basis: consent (Article 6(1)(a) GDPR), you grant location permission at the OS prompt.

Local notifications

Data: pomodoro session timestamps and daily reminders, scheduled locally on your device.

Where: handled by the OS notification permission (Android POST_NOTIFICATIONS; iOS prompts at first use). Notifications are local only: there is no push server and no FCM/APNs push token is generated or sent. Nothing leaves your device for this feature.

Crash & error reporting

Data: device model, OS version, app version/release, a breadcrumb of recent screen names, stack traces, and an auto-generated installation/device identifier.

Where: sent to Sentry for crash and error reporting, and for a 20% sample of performance traces. We configure Sentry with sendDefaultPii disabled, which prevents your email and IP address from being attached (Sentry would otherwise collect IP by default). We make a best effort not to capture user input.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), fixing crashes and errors you experience.

Bot protection on sign-in (Cloudflare Turnstile)

Data: browser/device signals collected by Cloudflare Turnstile to issue a single-use captcha token.

Where: the sign-in, sign-up, and password-reset screens (both the website and the app's WebView) load Cloudflare Turnstile, which produces a one-time bot-protection token sent with the auth request. Supabase enforces this captcha project-wide.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), preventing automated abuse of the auth endpoints.

App delivery & over-the-air updates (Expo/EAS)

Data: app version and update-channel pings; no user content.

Where: the app checks Expo / Expo Application Services for over-the-air updates. These pings carry only the app version and update channel so the right update is delivered.

Legal basis: legitimate interest (Article 6(1)(f) GDPR), shipping fixes and updates.

Community / forum features

Community and forum features (and their tables) exist in the code but are turned off for this release (feature-flagged). No user-generated forum content is collected or transmitted in the shipped app.

Shared sign-in across Aldo Website LLC products

Your login (email identity) is shared across Aldo Website LLC products (for example Aldo's Toolkit and other apps we operate): one sign-in works in all of them. Each product keeps its own data, separated per app; a membership registry records which products you use. No product can read another product's data about you.

Account & data deletion (in-app)

You can delete your account and all associated Toolkit data from inside the app (Account tab). Deletion is confirmed with a 6-digit code emailed to you (request a code, then confirm; the deletion is processed server-side). You can also delete individual items.

Because the sign-in is shared, deleting your Toolkit account removes ALL Toolkit data and the Toolkit membership; the login identity itself is removed as soon as no other Aldo Website LLC product is using it. If you also use another of our products, the login survives for that product only - email us to remove it everywhere at once.

Self-service data export is available: a JSON archive of your profile, comments, ratings, contact submissions, orders, and toolkit usage. You can also request deletion on the web at aldowebsitellc.xyz/account or by emailing hello@aldowebsitellc.xyz.

On deletion, Stripe order records are retained for tax and financial-records obligations with the customer email scrubbed to “[deleted account]”.

Payments

The app does not process card data. Tapping a Buy button opens an in-app browser tab to Stripe-hosted Checkout (the same flow the website uses). After payment, an order record is created on the website and you receive a Stripe receipt by email; for digital products, the download link is sent in a follow-up email via Resend.

$ cat cookies.txt

Strictly necessary: authentication/session cookies (set by our auth provider, Supabase) keep you signed in. These are required for the account feature.

Advertising measurement: the website (not the app) uses the Meta Pixel, which sets the _fbp cookie and sends Meta Platforms page-view and form-submission events so we can measure whether our ads work. We honor Global Privacy Control: if your browser sends the GPC signal, the pixel never loads and no advertising cookie is set. You can also opt out via Meta ad preferences or any content blocker; the site works identically without it.

Vercel Analytics and Speed Insights are cookieless. We use no other analytics or tracking cookies.

$ cat third-parties.txt

Data is shared with the following processors / sub-processors under Data Processing Agreements (DPAs) where applicable. They cover international transfers via Standard Contractual Clauses (SCCs) where applicable. User-supplied photos (Image AI) and chat text (AI Tutor and Dexter) are transmitted to Groq and Google as model providers via our own relay.

Supabase Inc., authentication, Postgres database, storage, cross-device sync, AI usage counters. Privacy policy

Stripe Inc., payment processing for services and digital products. Privacy policy

Vercel Inc., website hosting, CDN, serverless functions, cron, Analytics + Speed Insights. Privacy policy

Resend, Inc., transactional and marketing email delivery (receipts, ebook delivery, contact replies). Privacy policy

Groq, Inc., LLM inference (Meta Llama 3.3 70B text and Llama-4 Scout vision) for the app's AI features; receives prompt text and any image you submit. Privacy policy

Google LLC, Gemini 2.5 Flash LLM inference for text and vision (receives prompt text and any image you submit) and optional Google OAuth sign-in. Privacy policy

Apple Inc., Sign in with Apple (identity provider on iOS) and App Store distribution; we receive your Apple user identifier and, if you choose to share it, your name and email or an Apple private-relay email. Privacy policy

Cloudflare, Inc., Turnstile bot/captcha protection on sign-in, sign-up, and password-reset screens; collects browser/device signals to issue a one-time token. Privacy policy

Functional Software, Inc. d/b/a Sentry, crash, error, and performance reporting in the mobile app. Privacy policy

Open-Meteo, weather forecast API; receives approximate latitude/longitude for the dashboard weather card. Terms

Expo / Expo Application Services, Inc., mobile app delivery and over-the-air updates (receives app version and update channel; no user content). Privacy policy

Zapier, Inc., admin-only outbound social-post scheduling; no end-user PII. Privacy policy

Meta Platforms, Inc., advertising measurement on the website via the Meta Pixel (page views, audit-form submission events, browser/device signals, the _fbp cookie); not used in the app; skipped entirely for browsers sending Global Privacy Control. Privacy policy

Social sign-in: Google OAuth and Sign in with Apple are offered. With Sign in with Apple you may hide your email behind Apple's private relay, in which case we receive only the relay address. Facebook and GitHub sign-in are not available.

We do not sell your data. The one advertising-related disclosure: the website's Meta Pixel (above) shares page-view and form-event data with Meta for ad measurement, which some laws classify as “sharing.” Sending the Global Privacy Control signal opts you out of it completely. Nothing else goes to advertisers.

$ cat your-rights.txt

Under GDPR (and applicable national laws), you have the right to:

Access, request a copy of data held about you (Article 15)

Rectification, correct inaccurate data (Article 16)

Erasure, request deletion of your data (Article 17)

Restriction, limit processing in certain circumstances (Article 18)

Portability, receive your data in a machine-readable format (Article 20)

Object, object to processing based on legitimate interest (Article 21)

Withdraw consent, where processing is based on consent, you may withdraw at any time

To exercise any right, email hello@aldowebsitellc.xyz. Requests are handled within 30 days (extendable to 90 days for complex requests, with notice).

$ cat supervisory-authority.txt

If you are located in the EU/EEA and believe your data has been processed unlawfully, you have the right to lodge a complaint with your local data protection authority (DPA). A directory of EU DPAs is available at edpb.europa.eu.

$ cat changes.txt

This policy may be updated to reflect changes in our practices or applicable law. The “Last updated” date at the top reflects the most recent revision. For material changes, registered users will be notified by email where feasible.

See also: Terms of Service