isimo
PricingEnterprise

Privacy Policy

What you write here stays yours.

Isimo asks you to write down the things that matter most to you. That only works if you know exactly where it goes. This policy explains what we collect, why, who else can see it, and how to take it back.

Effective
22 August 2026
Last updated
22 August 2026

Contents

01The short version02Who we are and what this covers03What we collect04Why we use it05Your consent, and taking it back06Mismo and AI processing07Email we send you08Who else can see it09Cookies and local storage10How long we keep it11How we protect it12Your rights and choices13Children14Changes to this policy15Contacting us
01

The short version

This policy is written to be read, not survived. The full detail follows, but the substance of it is short:

  • What you write in Isimo is yours. Your goals, reviews, reflections, clarity sessions, habits, documents, vision boards, and Brainstorm boards are stored privately against your account and are not readable by other members.
  • We do not sell your personal information, and we do not trade it, rent it, or hand it to advertisers.
  • There are no advertising or analytics trackers on Isimo. No third-party pixels, no behavioural profiling, no cross-site tracking.
  • Mismo is the one place your writing leaves our systems. When you use it, your message and a bounded slice of your saved context are sent to our AI provider to generate a reply. Section 06 explains exactly what is sent.
  • You can ask for your data or ask us to delete it, and we will answer within 30 days.
02

Who we are and what this covers

Isimo is a goal-setting and personal-progress system operated by Isimo(“Isimo”, “we”, “us”). This policy covers the Isimo website at isimo.co, the signed-in product, and the emails we send you.

We are accountable for the personal information under our control under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and, where it applies, provincial privacy legislation. Our privacy contact is privacy@isimo.app.

Where you are protected by privacy law outside Canada — the GDPR in the EU and UK, or state privacy laws in the United States — we extend the access, correction, deletion, and portability rights in section 12 to you regardless of where you live.

03

What we collect

Account information

Accounts are handled by Firebase Authentication. Depending on how you sign up we receive:

  • Email and password. We never see your password in readable form — Firebase stores it as a salted hash and we cannot recover it.
  • Google Sign-In. If you use the Google option, Google gives us the name, email address, profile picture, and Google account identifier on that account. We do not receive your Google password and we request no access to any other Google service.
  • Sign-in records kept by Firebase Authentication, including account creation time, last sign-in time, and the IP address of sign-in attempts, which Google uses to detect abuse.

What you write in Isimo

Everything you create in the product is stored in Cloud Firestore under your own account and is readable only by you. That is enforced in our database rules, not merely in the interface. It includes:

  • Goals and progress steps — titles, descriptions, links, categories, and which goal you have named as your definite goal.
  • Documents — the rich-text pages you write and autosave.
  • Reflections — the lessons you distil and reuse as planning context.
  • Setbacks — the pattern, its trigger, your planned response, your proof, and whether you have overcome it.
  • Clarity Field and clarity sessions — your destination, your greatest constraint, the first move you committed to, and the writing you produce in the Clarity Hour, 20 Solutions, Constraint Finder, and End-of-Day Reset practices.
  • Reviews and review templates — the period, your evidence, wins, lessons, corrections, next commitment, time invested, your 1–10 score, and any custom questions you add to your own template.
  • Habits — the habit, its description and cadence, your start date, your per-period notes, and completion times used to calculate streaks.
  • Vision boards — the images, text blocks, and video links you place on the canvas, and the canvas position, colour, and pattern.
  • Brainstorm boards— each board’s name, the notes, text, images, video links and frames on it, the connections you draw between them, and the canvas position, surface, and pattern.
  • Life areas — the 1–10 ratings you give health, relationships, career, finances, purpose, and growth for the Analytics page.
  • Your settings and page notes — preferred name, chosen quote and tone, first day of the week, which cards you show, and the private per-page notes you write behind the question-mark button.

Much of this is, by its nature, personal. People write about their health, their relationships, their finances, and their setbacks in Isimo. We treat all of it as sensitive and apply the protections in section 11 to it uniformly.

Images you upload

Images you place on a vision board, a Brainstorm board, or a journal thread are held in Cloud Storage under a path belonging to your account, and they share one quota. Uploads pass through our authenticated server so that quota can be reserved correctly; only image files are accepted, each file must be under 10 MB, and each account has 250 MB of space. Each image gets an unguessable download link, so anyone you deliberately give that link to can view the file.

Conversations with Mismo

Your messages to Mismo, its replies, and the status of any Isimo action you confirm or dismiss are saved privately to your account so you can reopen the conversation across devices. You can delete a conversation from Mismo history at any time. What is sent to our AI provider to produce each reply is set out in section 06.

Technical records

Our hosting produces ordinary server logs: IP address, browser and device type, the pages and API routes requested, timestamps, and error traces. We use them to keep the service running, diagnose faults, and detect abuse.

What we do not collect

We do not run advertising networks, third-party analytics, session recording, heatmaps, or tracking pixels. We do not buy personal information about you, we do not build advertising profiles, and we do not track you across other websites.

04

Why we use it

We use personal information only for the purposes we identify here:

  • To give you the product. Storing and displaying your goals, reviews, habits, documents, boards, and settings, and syncing them across your devices.
  • To make the product intelligent for you. Surfacing your next step, calculating streaks and progress, and giving Mismo the context to answer usefully.
  • To keep accounts secure. Authenticating you, enforcing per-account isolation, applying storage quotas, and detecting abuse.
  • To communicate with you. Account, security, and billing messages, and product news where you have asked for it. See section 07.
  • To support you. Answering the notes you send us and investigating problems you report.
  • To meet legal obligations, including tax and accounting records for paid plans.

We do not use what you write in Isimo to train AI models, our own or anyone else’s. We do not read your content to build marketing profiles. Staff access to member content is limited to what is necessary to investigate a fault or a support request you have raised, and is not routine.

05

Your consent, and taking it back

You consent to the handling described here when you create an account and use Isimo. For anything beyond running the product — promotional email in particular — we ask separately and you are free to decline without losing any part of the service.

You can withdraw your consent at any time, subject to legal and contractual limits and to reasonable notice. Withdrawing consent for core processing means closing your account, because we cannot operate Isimo without storing what you write in it. Withdrawing consent for optional processing — promotional email, or use of Mismo — simply means turning that part off, and everything else keeps working.

06

Mismo and AI processing

Mismo is the one feature that sends your writing outside our own systems, so it deserves plain description rather than a general clause about “third-party technology”.

Who processes it. Mismo’s replies are generated by OpenAI, L.L.C.in the United States, using its API models. OpenAI is our processor: it receives the data to generate and return Mismo’s response.

What is sent. When you send a message, our server assembles a bounded context from your own saved data and sends it with your message. That context is capped and consists of:

  • up to 8 recent messages from the current conversation, with no message longer than 4,000 characters;
  • up to 25 of your goals, with their descriptions, and which is your definite goal;
  • your Clarity Field focus — destination, constraint, and committed first move;
  • your six most recent clarity sessions;
  • your eight most recent progress reviews;
  • your twelve most recent reflections;
  • the private notes you wrote for Mismo on the Clarity page.

What is not sent. Your documents, your vision and Brainstorm boards and their images, your habits and habit notes, your setbacks, your life-area ratings, your email address, and your name are not sent to OpenAI. We send a one-way hash of your Isimo account ID as a safety identifier; it does not contain your name, email address, or account ID.

What happens to it. Isimo stores the conversation in your private account history until you delete it or close your account. Our request still tells OpenAI not to retain it as reusable Responses API conversation state. OpenAI does not use API content to train its models unless we explicitly opt in. Its default abuse monitoring logs may retain submitted content for up to 30 days, and prompt caching may keep encrypted computational state for up to 24 hours. Replies are returned to your browser with browser and intermediary caching disabled.

How to avoid it entirely. Nothing is sent to OpenAI unless you open Mismo and send a message. If you never use Mismo, your writing never leaves our systems for this purpose.

Mismo is a thinking companion, not an authority. It can be wrong, and it is not a substitute for medical, psychological, financial, or legal advice. The judgment stays yours — see section 03 of our Terms of Service.

07

Email we send you

Isimo sends email through Resend, Inc., which receives your email address and the content of the message in order to deliver it. There are two kinds, and they are governed differently.

Service email — account confirmation, password reset, security alerts, billing receipts, and notices about changes to these documents. These are part of holding an account and are sent for as long as your account exists. They carry no marketing, and they are not something you can unsubscribe from without closing your account.

Product news and promotional email— new features, guides, and offers. Under Canada’s Anti-Spam Legislation (CASL) these are commercial electronic messages, so we send them only where you have given us express consent, we identify ourselves in every message, and every message carries a working unsubscribe link that we action within 10 business days. You can also withdraw consent at any time by writing to privacy@isimo.app. Unsubscribing from product news never affects your service email or your access to Isimo.

Our email provider records ordinary delivery information — whether a message was delivered, bounced, or was marked as spam. We use it to keep our sending healthy and to stop emailing addresses that no longer work.

If you send us a note through the contact form or by email, we keep that correspondence so we can answer you and handle any follow-up.

08

Who else can see it

We use a small number of service providers to run Isimo. Each is bound by contract to protect the information, to use it only to provide the service to us, and to give it a level of protection comparable to our own.

ProviderWhat it doesWhat it can seeWhere
Google LLC / Google CloudFirebase Authentication, Cloud Firestore, Cloud Storage, and Firebase App Hosting — the accounts, the database, the uploaded images, and the servers that run Isimo.Account identifiers, everything you write and upload in Isimo, and server request logs.United States
OpenAI, L.L.C.AI inference for Mismo. OpenAI's API models generate Mismo's replies.Your messages to Mismo and the personal context assembled for that request. Nothing else, and nothing at all if you never open Mismo.United States
Resend, Inc.Delivery of account and service emails, and of product news where you have asked for it.Your email address, your name where you have given one, and the content of the message sent to you.United States

Information held outside Canada. These providers store and process information in the United States. While it is there it is subject to the laws of that country, and foreign courts, law enforcement, and national security authorities may be able to compel access to it under their own legal processes. We tell you this plainly because PIPEDA requires that you know it before you decide to use Isimo.

We also disclose personal information where we are legally required to — a valid court order, subpoena, or lawful demand — and where it is necessary to protect the rights, safety, or property of Isimo, our members, or the public. If Isimo is ever involved in a merger, acquisition, or sale of assets, member information may transfer as part of that transaction; we will give notice before it becomes subject to a different privacy policy.

We do not sell, rent, or trade personal information, and we do not share it for cross-context behavioural advertising.

09

Cookies and local storage

Isimo sets no advertising or analytics cookies.There is no consent banner on this site because there is nothing to consent to. What the product does use is your browser’s own storage, and only for these things:

  • Keeping you signed in.Firebase Authentication stores your session token in your browser’s local storage. Without it you would sign in on every page load. Clearing your browser storage signs you out.
  • Remembering how you like the app. A handful of per-device preferences: the order of your Workspace sidebar, which charts you show on habit statistics, whether you asked for reduced motion, and a local draft of Clarity Hour writing so a refresh cannot cost you an hour of work. These stay on your device and are never sent to us.
  • A short-lived session record used by the dashboard greeting to tell a new visit from a page refresh.

If you sign in with Google, Google sets its own cookies on its own domains under its privacy policy. That is Google’s processing, not ours. A vision board or Brainstorm board that embeds a video loads that player from whoever hosts it — YouTube, Vimeo, Loom, Dailymotion, Streamable, Wistia, or Twitch — when the board is viewed, which lets that service see the request and set its own cookies under its own policy. Nothing is loaded from them until a board holding such a video is opened.

10

How long we keep it

We keep what you write for as long as your account is open, because that is the point of it — a review from two years ago is evidence, not clutter. You control most of it directly: goals, documents, reflections, setbacks, reviews, habits, clarity sessions, Mismo conversations, and Brainstorm boards can each be deleted from within Isimo whenever you like. Deleting a Brainstorm board also releases the images only it was using, so the space comes back to your quota.

A few records are designed to be revised rather than individually deleted — your Clarity Board focus, your weekly reviews, your vision board, and your settings are overwritten as you change them, and keep no history of earlier versions. Closing your account removes all of them.

When you close your account, we delete your account record and the content stored against it, including uploaded images, within 30 days. Backups are purged on their own rotation, no later than 90 days. We retain what the law requires us to keep — billing and tax records for paid plans, typically six years — and anything needed to resolve a dispute or enforce our agreements.

Server logs are retained for a rolling period of up to 90 days.

11

How we protect it

Safeguards appropriate to the sensitivity of the information, which for a product people write their private ambitions into means a high bar:

  • Per-account isolation enforced at the database.Our Firestore security rules permit reads and writes only where the signed-in account matches the account that owns the record. A flaw in the interface cannot expose one member’s data to another, because the interface is not what is enforcing it.
  • Validated writes. The database also checks the shape and size of what is written, so a compromised client cannot store arbitrary data against your account.
  • Locked-down file storage. Uploads are written only by our authenticated server; direct client writes to storage are denied outright.
  • Encryption in transit over TLS and at rest by Google Cloud.
  • Secret management. Server credentials are held in Google Cloud Secret Manager and are never shipped to your browser.

No system is perfectly secure, and we will not pretend otherwise. If a breach creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we keep records of breaches as required.

12

Your rights and choices

You may, at any time:

  • Access the personal information we hold about you and be told how it has been used and who it has been disclosed to.
  • Correct anything inaccurate or incomplete. Most of it you can edit directly in the product.
  • Delete your content or your whole account.
  • Take it with you — ask for a copy of your content in a portable format.
  • Withdraw consent as described in section 05, and opt out of promotional email as described in section 07.
  • Complain to us, and get a substantive answer.

Write to privacy@isimo.app. We will respond within 30 days, at no cost, and will tell you in advance if a request is genuinely complex enough to need an extension. We may need to verify your identity before acting, and we may have to withhold information whose release would reveal another person’s personal information or is otherwise protected by law — if we refuse a request, we will tell you why and how to challenge it.

If our answer does not satisfy you, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the privacy regulator in your own province or country.

13

Children

Isimo is not intended for children. You must be at least 16 to create an account. We do not knowingly collect personal information from anyone under 16, and if we learn we have, we will delete it. If you believe a child has given us information, write to privacy@isimo.app.

14

Changes to this policy

As Isimo grows, this policy will change. When it does, we update the date at the top of this page. If a change materially affects how we handle your personal information — a new category of data, a new purpose, or a new provider that can see your content — we will tell you by email or in the product before it takes effect, and where the law requires it, we will ask for your consent rather than assume it.

15

Contacting us

Privacy questions, requests, and complaints go to our privacy contact at privacy@isimo.app. Everything else reaches us at hello@isimo.app.

Your use of Isimo is also governed by our Terms of Service.

Questions

If anything here is unclear, ask us.

We would rather explain a clause than have you agree to something you do not understand. Write to privacy@isimo.app for anything about your data, or hello@isimo.app for everything else. A person answers.

IIsimo

A calmer operating system for meaningful goals, focused work, and measurable progress.

Product

  • Overview
  • Individuals
  • Teams
  • Philosophy
  • Pricing

Company

  • Our mission
  • The Isimo method
  • The practice
  • Customer cases
  • Enterprise
  • Isimo Labs
  • Contact

Resources

  • Overview
  • Guides
  • Journal
  • Help center

© 2026 Isimo. All rights reserved.

PrivacyTermsAccessibilityCookies