Last updated: July 10, 2026 · Effective: July 10, 2026
This Privacy Policy explains what personal information Minute Left (the “App”) and the website at minuteleft.app collect, how we use it, who we share it with, and the rights you have. Please read it together with our Terms of Service and Refund Policy.
The data controller and seller is Roman Melnychuk (Roman Vasylovych Melnychuk), an individual entrepreneur (sole proprietor) registered in Ukraine (“we”, “us”, “our”). We decide why and how your personal information is processed.
| Contact for privacy matters | hello@minuteleft.app |
|---|---|
| Website | minuteleft.app |
| Licensing API | api.minuteleft.app |
Minute Left needs read access to your macOS Calendar (Apple’s EventKit framework, “Full Calendar Access”) so it can remind you before meetings. From each event it reads the title, start/end time, all-day flag, notes, location, URL, and the calendar account’s name (which is often an email address), and it scans the notes, location, and URL fields to find a video-meeting link.
This calendar information is processed entirely on your Mac. It is never
transmitted to our servers or to any third party. It is held in memory and shown
on screen. The only thing stored is a short list of local app preferences in macOS
UserDefaults — identifiers of reminders already shown (an opaque event ID plus
a timestamp) and snooze times — so the App doesn’t repeat a reminder. These local records
are automatically deleted after 48 hours.
authuser= value to the meeting link before opening it in your own
browser, so the browser opens the right Google account. This stays on your device and
is not sent to us.To run the trial, provide the paid license, and understand how the product is used, the App collects and transmits a small amount of data to our backend. We do not use a password — your email address is your identity, and it is not independently verified by us.
| Data | Source | Purpose |
|---|---|---|
| Email address | Entered by you when you buy a license (at checkout) or restore a purchase | Identify you, attach and restore the license, and contact you about your purchase |
| Install identifier | Random ID generated on your device on first run | Anchor the trial to an installation and link a purchase to it |
| Anonymous usage events | Generated in the App and on the website as you use them | Understand how the product is used — which setup steps are reached, whether a meeting reminder was shown and how you responded, which screens are viewed — so we can improve it (see §4) |
| Trial start time | Set on our server on first contact | Compute your 7-day trial window |
| License / entitlement status | Derived on our server (trial / active / expired / revoked) | Decide whether the App is unlocked |
| Purchase & transaction records | Received from our payment provider (Paddle) by webhook | Grant or revoke your license; keep an audit record for refunds and chargebacks |
| Website visitor hash | Derived on our server from your IP address, User-Agent and a secret key when you trigger a website event; never stored on your device | Count unique visitors rather than raw requests, so one person clicking twice is not counted as two (see §4) |
| Technical log data | Generated automatically when the App contacts our API | IP address and standard request metadata, logged by our hosting provider for security and reliability |
We do not store your payment-card details. Card and billing data are handled by Paddle (see §7).
The App and the website contain no third-party analytics or advertising SDKs, set no advertising or analytics cookies, and use no cross-site tracking. We do, however, collect anonymous product analytics to understand and improve how the App is used:
The remaining third-party resources on the website are:
These are limited to operating the site and the purchase; we do not use them to build advertising profiles. If you do not want to load Paddle’s checkout, do not visit the checkout page.
We use the limited information we collect only for these purposes:
Legal bases. Depending on the activity, we rely on: performance of the agreement under which we provide the App (running your trial, license, updates, and support); our legitimate interests (securing the service, preventing fraud and abuse, and understanding usage through anonymous analytics to improve the product); compliance with our legal obligations (keeping tax and transaction records); and, where applicable, your consent, which you may withdraw at any time.
The App uses the open-source Sparkle framework to keep itself up to date.
About once a day it checks an update feed hosted on GitHub Pages
(chamooo.github.io). Each check sends your IP address and standard
HTTP request metadata to GitHub; no account or identifier is sent. Updates are
cryptographically signed (EdDSA) and verified before installation. You can disable
automatic update checks in the App’s settings.
We share personal information only with the providers we need to run the service. Each acts under a contract that limits their use of the data.
| Provider | Role | Data they process |
|---|---|---|
| Paddle (Paddle.com Market Ltd) | Merchant of Record & payment processor — Paddle is the seller of record for your purchase | Your name, email, billing and payment details, and transaction data; Paddle handles invoicing, VAT/sales tax, receipts and refunds under its own terms and privacy policy |
| Cloudflare, Inc. | Hosting of our backend (Workers) and database (D1), plus request logging | Email, install ID, trial/entitlement data, transaction IDs, and request logs including IP address |
| GitHub, Inc. (GitHub Pages) | Hosts the website and the App’s update feed | Your IP address and request metadata when you visit the site or the App checks for updates |
| PostHog (PostHog, Inc. — EU Cloud) | Product-analytics processor for the anonymous usage events described in §4 | The random install identifier and non-identifying event metadata only — no email, name, IP address, or calendar data. Processed in the European Union under its privacy policy |
| Apple Inc. | Provides the macOS calendar APIs and code-signing/notarization | Calendar access is mediated by macOS on your device; we receive no data from Apple about you |
We do not sell your personal information and we do not give it to data brokers or advertisers.
We are based in Ukraine. Our providers Paddle, Cloudflare and GitHub are based in or process data in the United States and other countries; our analytics provider PostHog processes data in the European Union. By using the App you understand that your information is processed in those locations. Each provider operates under a data-processing agreement that limits its use of the data; you can ask us for details by email.
Minute Left is not offered to, or directed at, individuals located in the European Economic Area or the United Kingdom, and we use country-level access controls to block access from those regions. We do not intentionally collect personal information from people in the EEA or the UK. If you are located there, please do not use the App. If you believe we hold your data despite these measures, email us and we will delete it.
If you are a resident of California or another U.S. state with a comprehensive privacy law (e.g. Virginia, Colorado, Connecticut, Texas, Utah), you have the right to:
For the 12 months before this policy’s date, we collected these CCPA/CPRA categories: identifiers (email address, install identifier, IP address, website visitor hash), commercial information (purchase and license records), and internet or other electronic network activity information (the anonymous App and website usage events described in §4, keyed to the random install identifier). We collect them from you and from our payment provider, use them for the purposes described in §5, and disclose them only to the service providers listed in §7. We did not sell or share personal information.
To make a request, email hello@minuteleft.app. We will verify your request using the email address associated with your account and respond within 45 days (extendable once where permitted). You may use an authorized agent to submit a request on your behalf. California residents may also request information under California’s “Shine the Light” law (Civil Code §1798.83); as stated, we do not share personal information with third parties for their own direct-marketing purposes.
Because we are established in Ukraine, we process personal data in accordance with the Law of Ukraine “On Protection of Personal Data” (No. 2297-VI). If you are a data subject, Article 8 of that law gives you the right to:
Our grounds for processing under Article 11 of the law are your consent; the conclusion and performance of the agreement under which we license the App to you; our legal obligations (such as tax and accounting records); and our legitimate interests in operating, securing, and improving the service, where these do not override your rights.
To exercise any of these rights, email hello@minuteleft.app. You also have the right to lodge a complaint with Ukraine’s data-protection supervisory authority, the Ukrainian Parliament Commissioner for Human Rights (Ombudsman) — ombudsman.gov.ua.
We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. We do not knowingly collect sensitive personal information for the purpose of inferring characteristics about you. Because we never sell or share, there is no opt-out to configure — but you may still email us with any related request.
Minute Left is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
We use HTTPS for all data in transit, store your credentials in the macOS Keychain on your device, verify payment webhooks with a signed secret, and limit access to the backend. No method of transmission or storage is completely secure, but we work to protect your information and will notify you and the relevant authorities of a data breach where the law requires.
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, take reasonable steps to notify you. Your continued use of the App after a change means you accept the updated policy.
For any privacy request or question, email hello@minuteleft.app.