Skip to content

Draft — not yet in force

This is a draft, published so you can read it rather than being told it exists. It has not been reviewed by a lawyer, and parts of it describe how Control is designed to work rather than what has shipped — Control is in private beta and no payment has been taken. Details still to be settled are shown like this: to be confirmed.

Privacy Policy

What Control stores, what leaves the server, who processes it and how to get it all deleted.

Effective date: effective date Last updated: effective date Applies to: take-control.ai and the Control web app


In short

A plain-language summary. It is not a substitute for the full policy below, but nothing below contradicts it.

  • Control is not end-to-end encrypted, and it is not zero-knowledge. Our servers can read what you write. They have to — an AI model has to read your words to understand them. Anyone telling you they do both is telling you something that isn't true.
  • Your words are sent to a third-party AI company, ai provider, to be understood. We have a written agreement that they do not store your data and do not train models on it. We tell you exactly what was sent, every single time, in Settings → Privacy.
  • We send the smallest amount we can. Never your whole history — at most about 20 facts and a handful of relevant items per request.
  • Control builds a profile of you — your employer, your manager's name, your working hours, your routines — partly from things you tell it directly and partly by inferring them from what you write. Every single one of those facts is visible, editable, and deletable on the You page, and it shows you where it came from.
  • We encrypt things properly: TLS 1.3 in transit, AES-256 at rest, and an extra layer of per-user encryption over the most sensitive fields (your notes, your original words, your personal facts).
  • The founder cannot read your content. The admin console shows numbers, not words. Support access to your content requires you to switch it on, and it expires after 24 hours.
  • You can take everything with you (one-click JSON export) and you can have it destroyed (hard delete, gone within 30 days, out of backups within 35).
  • We don't sell your data. We don't share it for advertising. There is no ad tech in the app.
  • We do not accept users under 16.

1. Who we are

Control is operated by company legal name, a company established in the United Arab Emirates, with its registered address at registered address.

For the purposes of the UK and EU General Data Protection Regulation (GDPR), company legal name is the controller of the personal data described in this policy.

Contact Details
General and privacy enquiries contact email
Postal address registered address
EU representative (GDPR Art. 27) eu representative
UK representative (UK GDPR Art. 27) uk representative
Data Protection Officer dpo status

2. What this policy covers

This policy covers:

  • the public Control website at take-control.ai (the "marketing site"), and
  • the Control application (the "app"), including the installable progressive web app version.

It does not cover third-party websites we link to, or the sign-in providers you choose to use (Google, Microsoft, GitHub, Discord, Slack), who handle your data under their own policies.

3. The part people care about most: how AI processing works

We are putting this near the top on purpose, because it is the single most important thing to understand about Control.

3.1 Control's servers can read your content

Control is not end-to-end encrypted. Control is not zero-knowledge. We do not claim otherwise anywhere on our site, in our marketing, or in this policy.

The reason is simple and unavoidable: Control's entire value is that it understands what you write. "Call Joseph about the contract before Friday" only becomes a scheduled, prioritised item if software actually reads that sentence. Encryption that made the content unreadable to our servers would also make it unreadable to the model, and Control would be a plain notepad.

So: our servers can decrypt and read your task content in order to process it. We limit who and what can do so (see §11), but we will not pretend the capability does not exist.

3.2 Your content is sent to a third-party AI provider

When Control needs to understand something you wrote, it sends a request to ai provider, an external AI company. We also keep a second provider, ai provider fallback, registered as a failover so that an outage at one provider doesn't break the product; your content may be sent to the failover provider instead when the primary is unavailable.

What is sent in a typical request:

Sent Not sent
The sentence you just wrote or spoke Your name or email address
Up to about 20 relevant personal facts from your You store (e.g. your timezone, your employer, your workday hours) Your whole fact store
The titles and IDs of a small number of your existing items, where they are needed to resolve what you meant ("move that to the 19th") Your full item history, your archive, or your completion statistics
The current date and time, and your timezone Your payment details

Our agreement with ai provider is a zero-retention agreement: they do not store the content of our requests after processing them, and they do not use it to train or improve their models. This is a contractual commitment, backed by a data processing agreement. It is not a technical guarantee we can verify from the outside, and we say so plainly.

3.3 We show you exactly what was sent — the Data Receipt

Every model request writes a receipt. In Settings → Privacy you can see a live log of every request Control has made on your behalf, showing:

  • what you said,
  • which facts were used — by name only, never their values (e.g. it will say employer was used, not what your employer is),
  • which items were referenced,
  • which provider and model handled it, and
  • the retention policy that applied.

You can delete individual receipts.

3.4 Some of your input never reaches an AI model at all

Roughly half of what people capture is handled entirely by a deterministic parser that runs in your browser — no model, no network request, no third party. "Gym 6am tomorrow" does not need an AI to be understood. When Control can do it locally, it does.

3.5 We do not use your content to train anything

We do not train models on your content. We do not fine-tune on it. Our AI providers are contractually barred from training on it. We use a small hand-labelled set of the founder's own captures to benchmark model quality; no other user's content is used for that purpose without separate, specific, opt-in consent.

4. What we collect

4.1 Data you give us

Category Examples Notes
Account Email address, display name, the sign-in method you used and the identifier your provider returns We never store a password. Sign-in is by one-time code or by an external provider.
Task content Item titles, notes, dates and times, durations, locations, tags, recurrence rules, and the original sentence you typed or spoke, kept verbatim The original input is retained so that Control can re-derive things when you correct it, and so parsing can be improved over time. Notes and original input are encrypted at the application layer.
People you mention Names, nicknames and aliases, the relationship ("manager", "client", "friend"), and their organisation This is personal data about other people, provided by you. See §6.
Voice The transcript of anything you dictate See §5.
Settings Home timezone, current timezone, locale, week start day, notification preferences, voice preferences
Support correspondence Anything you email us

4.2 Data Control generates about you — the "You" store

This is the feature that most warrants your attention, so we describe it in full.

Control maintains a store of personal facts about you. Each fact has a key and a value — for example employer, manager.name, workday_end, commute_minutes, relationship.joseph, wake_time. Facts fall into these kinds: identity, relationship, preference, routine, constraint, context.

Facts arrive in two ways:

  1. You state them. "I work at Autonos." Recorded with full confidence, marked as coming from you.
  2. Control infers them. If you mention Joseph five times in a work context, Control may infer that Joseph is a colleague or your manager. Inferred facts are recorded with a confidence score and a record of which of your captures led to the inference.

Controls we give you over this:

  • Everything is visible. The You page lists every active fact, grouped by kind.
  • Everything shows its provenance. Each fact tells you where it came from ("Control inferred this from something you said on 3 August") and links to the original input.
  • Everything is editable and deletable. Edit · Correct · Delete · See where this came from.
  • Low-confidence inferences are put to you for confirmation in the app rather than being used silently as fact.
  • If you reject an inference, Control does not infer it again.
  • Nothing is destroyed by correction. When a fact changes ("I left Company A and joined Company B"), the old fact is marked superseded and kept in history rather than deleted, so Control can reason about when things were true. You can delete superseded facts too.

4.3 Data we collect automatically

Category Examples Where it goes
Usage and metering Number of AI interactions, which processing tier was used, tokens in/out, cost, latency, whether a cache was hit, your quota state Our own database. This is what enforces plan limits and what our unit economics are calculated from.
AI receipts Fact keys (never values), item IDs, provider, model, retention policy, timestamp Our own database; shown back to you in Settings → Privacy.
Product analytics Which features are used, session counts, capture counts, activation and retention measures PostHog. On the marketing site this is cookie-based and requires your consent in the EU/UK. Inside the authenticated app we run no third-party scripts at all; product analytics there is collected server-side and is not used to track you across other websites.
Error diagnostics Error messages, stack traces, browser and device type, the page you were on Sentry. Diagnostics may incidentally contain fragments of content; we configure scrubbing to reduce this.
Technical/security IP address, approximate location derived from it, request timestamps, rate-limit counters, session and device records Used for security, abuse prevention and to work out which region to serve you from.
Audit log Administrative actions taken on your account by us, with who did it and what changed Retained as an accountability record.

4.4 Payment data

We do not process your payment card. Purchases are made through merchant of record, which acts as the merchant of record — legally, they are the seller, and they collect and remit the relevant sales taxes.

merchant of record collects your payment details and billing information directly, as an independent controller under their own privacy policy: mor privacy policy url.

What we receive back from them: your subscription status, plan, billing period dates, and their customer and subscription identifiers. We may also receive the country and the last four digits of your card for support and fraud purposes. We never see your full card number.

5. Voice

Control offers two ways to turn speech into text.

Browser transcription (all plans, default) Server transcription (paid plans)
How it works Uses your browser's or device's own speech recognition Your audio is uploaded and transcribed by stt provider
Does audio reach Control's servers? No. Control receives only the finished text. Yes.
Where the audio goes Handled by your browser/operating system. Depending on which browser you use, your browser vendor may send the audio to their own servers to transcribe it. That is a function of your browser, not of Control, and it is governed by your browser vendor's privacy policy. To stt provider under a data processing agreement.
Is the audio kept? Not by us — we never receive it. No. The audio is used to produce the transcript and is not retained by us afterwards.

To improve accuracy on names and jargon, server transcription is given a short biasing vocabulary drawn from your own data — the names of people you've mentioned, your tags, and organisations you've referenced. This means a small number of proper nouns from your You store are sent to stt provider along with the audio. Values of other personal facts are not.

Transcripts are always placed in the capture box for you to check before you submit them. Nothing is submitted automatically from voice.

6. Personal data about other people

When you write "call Joseph about the contract", you are giving us personal data about Joseph. Control stores a record for Joseph — name, aliases, relationship, organisation, and an internal importance score used to prioritise your list.

  • We process this data solely to provide the service to you, and for no other purpose.
  • We do not contact these people, market to them, or build profiles of them for our own purposes.
  • We do not sell or share this data.
  • Deleting a person from your account deletes their record.
  • You are responsible for what you enter about other people. Please only record what you reasonably need to manage your own tasks.

7. Why we process your data, and our lawful basis (GDPR Art. 6)

What we do Why Lawful basis
Create and run your account, authenticate you, keep sessions You asked us to provide Control Contract — Art. 6(1)(b)
Store your items, notes, tags, dates and original input; sync them across your devices Core product Contract — Art. 6(1)(b)
Send your input to an AI provider to interpret it Core product; without it there is no Control Contract — Art. 6(1)(b)
Order your home screen by relevance and heat Core product Contract — Art. 6(1)(b)
Server voice transcription (paid plans) A feature you enable and pay for Contract — Art. 6(1)(b)
Infer personal facts about you (the "You" store) To make Control's judgements accurate to your actual life Legitimate interests — Art. 6(1)(f). Our interest is delivering a product that is right often enough to be trusted; the inferences are limited to what you have voluntarily written, are shown to you, and can be corrected, rejected or deleted at any time. You can object — see §10.
Meter usage and enforce plan limits To run the business fairly and stay solvent Contract — Art. 6(1)(b)
Take payment and keep the resulting records To sell you a subscription; to keep tax and accounting records Contract — Art. 6(1)(b) and legal obligation — Art. 6(1)(c)
Send transactional email (sign-in codes, billing notices, deletion confirmations) You cannot use the service without them Contract — Art. 6(1)(b)
Send push notifications you have configured (morning brief, reminders) A feature you switch on Contract — Art. 6(1)(b), plus your device permission
Send product-update or marketing email To tell you about Control Consent — Art. 6(1)(a). Opt-in, and every message has an unsubscribe link.
Analytics on the marketing site To understand what brings people to Control Consent — Art. 6(1)(a), collected via our cookie banner
Product analytics and error diagnostics inside the app To keep the product working and decide what to build Legitimate interests — Art. 6(1)(f)
Rate limiting, abuse detection, fraud prevention, security logging To protect the service and other users Legitimate interests — Art. 6(1)(f)
Respond to your support requests To help you Contract — Art. 6(1)(b) / legitimate interests — Art. 6(1)(f)
Comply with legal requests and obligations Because we must Legal obligation — Art. 6(1)(c)

You can ask us for our legitimate interests assessments at contact email.

7.1 Special category data (GDPR Art. 9)

Control is a general-purpose task manager. We do not ask for, and we do not want, data about your health, race, religion, politics, sex life, sexual orientation, trade union membership, genetics or biometrics.

But you type freely, and a task like "physio Tuesday 4pm" or "mosque before the meeting" may reveal something in that list. Where that happens, the data is there because you chose to put it there, and we rely on Art. 9(2)(e) where you have manifestly made it public, or otherwise on your explicit consent under Art. 9(2)(a), which you give by choosing to enter it.

Practical advice: if you would not want an AI provider's systems to process something, do not put it in Control.

8. Who we share data with

We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not run advertising in Control.

We use a small number of service providers ("subprocessors") who process data on our instructions and under a data processing agreement. The current list, with what each one does and where, is at take-control.ai/legal/subprocessors and in subprocessors.md.

In summary, they are: our host and CDN, our database and authentication provider, our AI providers, our speech-to-text provider, our transactional email provider, our analytics and error-monitoring providers, our key management provider, and our merchant of record.

We will also disclose data:

  • when you tell us to (for example, when you grant time-limited support access to your content);
  • to professional advisers under confidentiality;
  • if we are legally required to, or where we believe in good faith that disclosure is necessary to prevent serious harm, investigate fraud or protect our legal rights. Where we are legally permitted to tell you about such a request, we will;
  • to a buyer or successor if the business is sold or reorganised — in which case this policy continues to apply to your data until you are told otherwise.

9. International transfers

We are established in the United Arab Emirates and our service providers are spread across several countries. This means personal data is transferred internationally, including out of the European Economic Area (EEA) and the United Kingdom.

Where data goes Examples
European Union Our primary database region is eu-central-1 (Frankfurt, Germany)
United States Vercel (hosting/edge), ai provider, PostHog and Sentry (unless their EU regions are used), Resend
United Arab Emirates Our own administrative access
Other regions Our CDN serves cached, non-content assets from edge locations worldwide, including the GCC

The UAE is not the subject of an EU or UK adequacy decision. For transfers from the EEA and the UK we rely on:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with each recipient, plus the UK International Data Transfer Addendum (or the IDTA) for UK transfers;
  • a transfer impact assessment for each recipient; and
  • supplementary technical measures — in particular TLS 1.3 in transit, AES-256 at rest, and application-level encryption of the most sensitive fields with per-tenant keys (see §11).

Where a provider is certified under the EU–US Data Privacy Framework, we may rely on that instead for transfers to that provider.

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), we transfer personal data outside the UAE on the basis of uae pdpl transfer basis.

You can request a copy of the transfer safeguards we have in place by emailing contact email.

10. How long we keep things

Data How long
Items (tasks, events, reminders) — including completed, dropped, dormant and archived ones For as long as your account is open. Control deliberately never auto-deletes your items; archiving is not deletion. You can delete any item yourself at any time.
Notes and original captured input Same as the item it belongs to
Personal facts, including superseded versions For as long as your account is open, or until you delete them
People records For as long as your account is open, or until you delete them
Capture and metering records (what tier, tokens, cost — the billing spine) For as long as your account is open. After account deletion, we retain a content-free record (no text, no fact values) for as long as required for tax and accounting purposes: 7 years
AI receipts (fact keys, item IDs, provider, model) receipt retention period, then automatically purged. You can delete individual receipts sooner.
Clarification prompts ("which day did you mean?") Auto-expire 14 days after they are raised
Voice audio Browser transcription: never reaches us. Server transcription: not retained after the transcript is produced.
Sessions Rolling 30-day expiry; revocable per device from Settings at any time
Product analytics (PostHog) posthog retention period
Error diagnostics (Sentry) sentry retention period
Security and rate-limit logs security log retention period
Administrative audit log audit log retention period
Support email support retention period after the matter is closed
Backups Rolling; fully rotated within 35 days

10.1 Deleting your account

You can delete your account from Settings → Privacy. When you do:

  1. Your account is closed immediately and you lose access.
  2. All your rows are purged within 30 days.
  3. Backups containing them are rolled off within 35 days.
  4. We email you to confirm when it is done.

What survives, and why: a content-free financial record of the transactions you made (required for tax), a record that an account with your email address was deleted on a given date (so we can prove we honoured your request), and anything we are separately required by law to keep. None of it contains your task content, your notes, your original input, or your personal fact values.

11. How we protect your data

Layer What we do
In transit TLS 1.3, HSTS preload, a strict Content Security Policy, and no third-party scripts on authenticated pages
At rest — database AES-256 full-disk encryption
At rest — sensitive fields An additional layer of application-level envelope encryption on your task notes, your original captured input, your personal fact values, and your raw captures. Each tenant has its own data key, wrapped by a master key held in a managed key service and rotated annually. A stolen database dump is not readable without separate access to the key service.
Tenant isolation Enforced by the database itself using PostgreSQL row-level security on every table — not by application code that could contain a bug
Authentication No passwords are ever stored. Sign-in is by 6-digit one-time code (10-minute expiry, 5 attempts, rate-limited by email and by IP) or by an external provider you choose. Sessions are revocable per device.
Administrative access The admin console cannot display your task content, notes, fact values or original input. Content fields are excluded at the query layer, not merely hidden in the interface. Support access to your specific content requires your explicit in-app consent, is time-boxed to 24 hours, and is itself recorded in an audit log. Every administrative action is logged with who did it and what changed.
Secrets Held in a platform secret store. Never in our source code, never in the browser bundle.
AI providers Zero-retention agreements; data processing agreements; at least two providers so no single vendor is a hard dependency

No system is perfectly secure, and we do not claim ours is. What we claim is listed above; what we explicitly do not claim is in §3.1.

12. If there is a data breach

If we suffer a personal data breach:

  • we will notify the relevant supervisory authority within 72 hours of becoming aware of it, where the breach is likely to result in a risk to people's rights and freedoms (GDPR Art. 33);
  • we will notify you directly, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms (GDPR Art. 34);
  • we will notify the UAE Data Office and affected individuals as required under the UAE PDPL, and any US state authorities and individuals as required under applicable state breach laws;
  • our notice will describe what happened, what data was involved, what we are doing about it, and what you should do.

13. Your rights

13.1 If you are in the EEA, the UK or Switzerland

You have the right to:

Right What it means Reference
Access Get a copy of the personal data we hold about you, and information about how we use it Art. 15
Rectification Have inaccurate data corrected. Note that you can already do most of this yourself — every item and every personal fact is directly editable in the app Art. 16
Erasure Have your data deleted ("right to be forgotten"). Account deletion is self-service in Settings → Privacy Art. 17
Restriction Ask us to stop processing your data while a dispute about it is resolved Art. 18
Portability Get your data in a structured, machine-readable format. This is one click in Settings — a complete JSON export of every item, fact and capture. No dark patterns, no waiting period, no fee. Art. 20
Objection Object to processing we carry out on the basis of legitimate interests — including, specifically, our inference of personal facts about you Art. 21
Withdraw consent Withdraw consent at any time where we rely on it (marketing email, marketing-site analytics). This does not affect processing carried out before you withdrew Art. 7(3)
Not be subject to solely automated decisions See §14 Art. 22
Complain Lodge a complaint with your local supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to fix it first. Art. 77

13.2 If you are in California

Under the CCPA/CPRA you have the right to know what personal information we collect and why, to request deletion, to request correction, to opt out of the "sale" or "sharing" of personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.

  • We do not sell your personal information, and we have not in the preceding 12 months.
  • We do not share it for cross-context behavioural advertising.
  • We collect the categories listed in §4. The business purposes are listed in §7.
  • You may use an authorised agent, with proof of authorisation.
  • We will verify your request by reference to the email address on your account.

13.3 If you are in the UAE

Under the UAE PDPL you have rights of access, correction, erasure, restriction of processing, data portability, objection to automated processing, and the right to complain to the UAE Data Office.

13.4 How to exercise your rights

You want to Do this
Export everything Settings → Privacy → Export. Immediate, one click, complete JSON.
Delete your account and all data Settings → Privacy → Delete account.
Correct a fact Control got wrong You page → tap the fact → Correct.
See what was sent to an AI provider Settings → Privacy → Data receipts.
Anything else, or if the in-app route doesn't work for you Email contact email

We will respond within one month. If your request is complex we may extend that by up to two further months and will tell you why within the first month. There is no fee unless a request is manifestly unfounded or excessive.

We may need to verify your identity. Normally that means responding from, or confirming control of, the email address on the account.

14. Automated processing and profiling

Control makes automated decisions about what to show you and in what order. Specifically:

  • a relevance score determines what appears on your home screen, calculated from how soon something is due, its "heat", how well it fits your usual routine, and how often you've skipped it;
  • heat is a priority score inferred from time proximity, urgency words you used, how important the people involved seem to be, an AI estimate of the consequence of missing it, and how many times you've ignored it;
  • personal facts are inferred from your writing, as described in §4.2.

Things worth knowing:

  • The relevance and heat calculations are deterministic formulas, not AI. They are explainable, and we can tell you exactly why something was ranked where it was.
  • You can always override. Long-press the heat indicator on any item to set priority yourself; your override wins, then fades back over two weeks so that a one-off "this is urgent" doesn't distort your list forever.
  • Nothing here produces a legal effect or a similarly significant effect on you — it is the order of a to-do list. We therefore do not consider this to be automated decision-making within GDPR Art. 22. If you disagree, contact us and we will look at it.

15. Children

Control is for people aged 16 and over.

  • You may not create an account if you are under 16.
  • We do not knowingly accept any user under the age of 13 in any jurisdiction, under any circumstances, with or without parental consent.
  • We ask for age confirmation at sign-up. We do not currently operate document-based or third-party age verification.
  • If we learn that an account belongs to someone under 16, we will close it and delete the data.
  • If you believe a child has an account, email contact email and we will act promptly.

16. Cookies

The authenticated app uses strictly necessary and functional cookies only — the ones that keep you signed in and remember your preferences. These are exempt from consent requirements.

The public marketing site uses analytics cookies, which require your consent in the EU and UK and are only set after you give it.

Full details, including a table of every cookie we set, are in our Cookie Notice at take-control.ai/legal/cookies.

17. Changes to this policy

We will update this policy from time to time.

  • The "last updated" date at the top always reflects the current version.
  • For material changes — a new category of data, a new purpose, a new class of recipient — we will notify you by email and in the app at least 30 days before the change takes effect.
  • We will notify you before adding a new subprocessor, as described in subprocessors.md.
  • If a change requires your consent, we will ask for it rather than assume it.
  • Previous versions are available on request.

18. Contact us

Email contact email
Post company legal name, registered address
EU representative (Art. 27) eu representative
UK representative (Art. 27) uk representative

If you are in the EEA or the UK and you are not satisfied with our response, you can complain to your national data protection authority. In the UAE, you can complain to the UAE Data Office.


This is a draft prepared for legal review. It is not legal advice and has not been reviewed by a qualified lawyer.