Privacy Policy (NEDIO)

Last updated: September 2, 2026

This Privacy Policy explains how NEDIO ("NEDIO", "we", "us", or "our") collects, uses, shares, and protects information when you use our website, web app, and compatible editor extension at https://nedio.xyz (the "Service").

If you have questions, contact us at support@nedio.xyz.

The data controller is HAYZI LTD, a company registered in England and Wales (company number 15955089), trading under the brand NEDIO.

Registered office and controller address: 69 Highgate West Hill, London N6 6BU, United Kingdom.

1) What NEDIO is

NEDIO is a web-based focus radio and session timer. You can use the Service without creating an account, or you can create an account to save your progress (for example, focus streaks and stats) and manage a subscription (NEDIO Pro).

Where the Service is offered

The Service is directed to users in the United Kingdom. We do not target, market, or offer the Service to individuals in the European Economic Area, and we do not monitor the behaviour of individuals in the European Economic Area. This policy is written around UK data protection law.

The Service may be technically accessible from other countries. If you use it from outside the United Kingdom, you do so on your own initiative.

2) Information we collect

We collect information in three ways: (a) information you provide, (b) information collected automatically when you use the Service, and (c) information from third parties you choose to use (like Google/GitHub sign-in).

A. Information you provide

  • Account information: email address and authentication details when you create an account or sign in. If you use OAuth (Google or GitHub), we receive a token/identifier from that provider to sign you in.
  • Profile and preferences: information you choose to share to personalize the experience (for example, profession and preferred genres).
  • Support messages: if you contact support through the in-app contact form, we collect the subject, message, your email (if provided), and any attachments you upload (up to 3 files).
  • Subscription-related information: when you subscribe, we associate your account with billing identifiers (such as Stripe customer/subscription IDs) and your subscription status (for example, free, trialing, active, canceled).

B. Information collected automatically

  • Usage and session information: listening sessions and usage measurements such as session start/end time, session duration, station/mode, and minutes listened (used for usage limits and stats).
  • Sprint journal (text you write in the app): if you use the focus timer's sprint features, we store what you enter about that sprint. This can include:
  • the sprint goal — the one thing you said you wanted to finish;
  • "done when" — what has to be true for that goal to count as finished;
  • the goal outcome you record afterwards (completed, partial, or not completed);
  • a reflection note — free text you write on the review screen;
  • a mood rating and a focus rating, each 1–5;
  • a parking line — the concrete next step you write down at the end of a sprint;
  • the planned length you chose and the focused time actually counted;
  • your time zone, so scheduled features know when your week begins.

This is content you write, not measurement we take. Please do not put information in these fields that you would not want stored — they are notes about your work, not a secure vault.

  • Insights derived from your sprints: where the feature is enabled for your account, we generate observations and weekly-review text from counts of your own sprints (for example, how often a work mode appears, or that the same next step has been written down several times). See Section 3A.
  • Editor extension analytics (if enabled): whether you use VS Code, VS Code Insiders, Cursor, or another compatible editor; NEDIO and editor versions; an ephemeral editor-session identifier; and allowlisted product events such as panel engagement, account connection, sprint lifecycle, statistics views, web-app opens, and coarse error codes. We do not collect source code, filenames, repository names, sprint goals, review text, extension lists, or the editor's machine identifier for this analytics stream.
  • Anonymous identifiers (for guests): if you use the Service without an account, we may generate a random identifier stored on your device to recognize a returning guest session and help measure usage (for example, daily minutes used).
  • Device and log information: IP address, browser type, user agent, approximate location (derived from IP), referring/exit pages, timestamps, and similar diagnostic information.
  • Cookies and local storage: we use cookies and local storage for essential functionality (such as authentication) and, if enabled, for analytics/marketing measurement (see Section 6).

C. Information from third parties

If you sign in via Google or GitHub, those providers may share basic account information (like an email address) with us based on your provider settings. We use it only to authenticate you and associate your account.

3) How we use information

We use information to:

  • Provide the Service (stream audio, run focus sessions, enforce daily usage limits for free users, and enable Pro features).
  • Create and manage accounts (authentication, account settings, and security).
  • Personalize your experience (for example, content preferences).
  • Operate subscriptions and billing (create checkout sessions, manage subscriptions, and provide a billing portal).
  • Support and communicate with you (respond to support requests and send operational messages).
  • Measure and improve the Service (understand feature usage, fix bugs, and improve performance).
  • Prevent fraud and protect the Service (security monitoring, abuse prevention, and compliance).

We do not sell your personal information.

3A) AI features, insights, and profiling

Where these features are enabled for your account, NEDIO produces a short weekly review of your own sprints.

What is analysed. Counts and labels drawn from your sprints — how many you finished, how long they ran, which work mode you chose, whether the same next step keeps reappearing. This is arithmetic over your own records. It is not compared against other users, and it does not make any decision about you: nothing here affects your price, your access, or your account.

What leaves our systems. Most of these sentences are written from counters alone, and those counters contain none of your writing. There is one exception: an observation about a next step you keep writing down has to quote that line to be worth reading, so for that one kind of sentence the parking line itself (up to 120 characters) is sent to our language model provider, Anthropic, to be phrased.

Your choice. You can turn this off in Settings → Email and privacy. Turning it off does not remove the feature or the finding — the same sentence about the same line is written by NEDIO's own templates instead, and your text stays with us.

What is never sent. We do not send your sprint goals, "done when" text, reflection notes, support messages, email address, or account identifiers to the language model provider. Model output is not used to train the provider's models.

This processing is profiling in the sense that we infer patterns about your working habits, but it is not automated decision-making producing legal or similarly significant effects.

4) Legal bases (United Kingdom)

We process personal data under the UK GDPR and the Data Protection Act 2018. Depending on the processing, we rely on one or more of the following legal bases:

  • Contract: to provide the Service you request — your account, playback, the sprint journal and stats you use the product for, and subscription management.
  • Legitimate interests: to keep the Service secure and working, to prevent abuse and fraud, and to send existing customers information about our own similar products by email. Our interest is in running and improving a product people are already paying for; we have weighed that against your interests, which is why every such email carries a one-click way to stop it and why analytics is not covered by this basis.
  • Consent: for analytics and marketing cookies and similar technologies (including Google Analytics, Vercel Analytics, Meta Pixel and the Conversions API, and the attribution snapshot described in the Cookie Policy), and for sending the text you write to a language model provider (Section 3A). You can withdraw consent at any time.
  • Legal obligation: to comply with applicable law, in particular UK accounting and tax rules that require us to keep billing records.

Direct marketing. Product emails during and after a trial are sent under the "soft opt-in" in regulation 22 of PECR: you gave us your address in the course of buying or negotiating to buy a subscription, the emails are about our own similar products, and you were given a way to refuse both when we collected the address and in every message since.

5) How we share information

We share information only as needed to run the Service, including with the following categories of providers:

  • Hosting and infrastructure: Vercel (hosting, content delivery, and server-side execution of the Service).
  • Bot and abuse detection: Vercel BotID, which runs on our pages to distinguish automated traffic from people. It is used to protect the Service and runs regardless of your cookie choices.
  • Database and authentication: Supabase (accounts, sessions, and app data, including the sprint journal described in Section 2).
  • Payments: Stripe (subscription billing). Payment card details are processed by Stripe; we do not store full card numbers.
  • Email delivery: Resend, which sends every email the Service produces — sign-in and password emails, trial and onboarding emails, the weekly recap, and support correspondence, including any attachments you send us.
  • Sign-in providers: Google and GitHub, if you choose to sign in with them. They receive the fact that you are authenticating with us; we receive an identifier and, depending on your settings, an email address.
  • Language model provider: Anthropic, where the AI features described in Section 3A are enabled for your account.
  • Analytics and measurement (only with your consent): Google Analytics, Vercel Analytics, and Meta (Pixel and Conversions API).
  • Media storage/delivery: Cloudflare (for storing and serving audio assets).

We may also share information:

  • For legal reasons: to comply with law, regulation, legal process, or government request.
  • To protect rights and safety: to enforce our terms, prevent fraud, and protect users and the Service.
  • Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets (you will be notified as required by law).

6) Cookies, tracking, and choices

We use cookies and similar technologies to operate the Service and, depending on configuration, to measure marketing/analytics performance.

Essential cookies

These help the Service work (for example, authentication/session cookies used by our authentication provider). Disabling them may prevent sign-in or other features from working.

Analytics cookies and measurement

If enabled, we may use:

  • Google Analytics to understand aggregated usage and improve the Service.
  • Vercel Analytics to measure traffic and performance.

Advertising/marketing measurement (Meta)

If enabled, we may use Meta Pixel and Meta Conversions API to measure the performance of ads and understand conversions (for example, sign-ups, checkout events, or session starts). Depending on how the Service is configured, these events may be sent only after you grant consent.

When Meta measurement is enabled, we may process:

  • cookie identifiers (for example _fbp and _fbc, when present),
  • IP address and user agent (for event matching),
  • event identifiers (for deduplication), and
  • hashed email (SHA-256) when you provide an email in a relevant flow.

Your choices

  • You can often control cookies through your browser settings and clear local storage via your browser controls.
  • Where we use consent-based tracking, you can deny or withdraw consent at any time through the Service (if available) or by clearing the relevant consent cookie/local storage.
  • In the editor extension, analytics runs only when both the editor-wide telemetry setting and nedio.telemetryEnabled are enabled. Turning either setting off stops new extension analytics events.
  • If you do not want marketing/ads measurement, do not grant consent when prompted (where applicable).
  • If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to disable marketing measurement where applicable.

6A) California privacy notice (CCPA/CPRA)

NEDIO does not “sell” personal information. We may “share” certain information for cross-context behavioral advertising when marketing measurement is enabled (for example, Meta Pixel/Conversions API). You can opt out of such “sharing” by turning off Marketing in the in-app cookie settings or by visiting /do-not-sell. We also honor Global Privacy Control (GPC) signals as an opt-out of marketing measurement.

6B) California privacy notice (CPRA/CCPA) - categories, sources, and retention

Categories of personal information we collect:

  • Identifiers (for example, email address, account IDs, device identifiers).
  • Commercial information (subscription status and billing identifiers).
  • Internet or network activity (usage, session data, and cookie identifiers).
  • Approximate geolocation (derived from IP address).
  • Inferences (preferences such as profession and genres).
  • Customer service content (support messages and attachments).

Sources of personal information:

  • Directly from you (account creation, personalization, support).
  • Automatically from your device (usage and log data).
  • From service providers you choose to use (OAuth providers and payment processors).

Retention by category (criteria):

  • Identifiers and account data: retained while your account is active and as needed to comply with legal obligations.
  • Commercial information: retained as required for billing, tax, and dispute resolution.
  • Internet/network activity: retained as needed for security, analytics, and service improvement.
  • Approximate geolocation: retained with log data as needed for security and diagnostics.
  • Support content: retained as needed to resolve requests and maintain support history.
  • Preferences/inferences: retained until you update them or delete your account.

We do not discriminate against you for exercising CPRA/CCPA rights.

7) Data retention

We keep information only as long as needed for the purposes described in this policy.

WhatHow long
Account and profile dataWhile your account exists. Deleted within 30 days of you asking us to close it, except where we must keep something to meet a legal obligation.
Sprint journal (goals, "done when", reflections, moods, parking lines, ratings)While your account exists, because it is the history the stats and streaks are built from. Deleted with your account.
AI-generated insights and observationsRegenerated from your sprints and deleted with them.
Listening and usage measurementsWhile your account exists. Aggregate figures that identify nobody may be kept afterwards.
Guest identifiers and hashed IP addresses (no account)Up to 12 months, which is also the lifetime of the identifier stored on your device.
Product analytics events (only with your consent)Up to 14 months, in line with our analytics provider's settings.
Email delivery logs (which message was sent to which account, and when)Up to 24 months, so we can show that consent and opt-outs were honoured.
Support messages and attachmentsUp to 24 months after the request is resolved.
Billing and tax records7 years, as UK accounting and tax law requires. This is a legal obligation and is not removed by deleting your account.
BackupsBackups roll over on their own schedule, so deleted data can persist in a backup for up to 90 days before it ages out.

You can request deletion (see Section 9).

8) Security

We use reasonable administrative, technical, and organizational measures to protect information. However, no method of transmission or storage is completely secure.

9) Your rights and requests

If you are in the United Kingdom, the UK GDPR gives you the following rights over your personal data:

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion of your data, where we have no overriding obligation to keep it (billing and tax records are the usual exception).
  • Restriction — to have us pause processing while a dispute about accuracy or legitimate interests is resolved.
  • Portability — a machine-readable copy of the data you gave us, to take elsewhere.
  • Objection to legitimate interests — to object to processing we base on our legitimate interests, including product analytics.
  • Objection to direct marketing — an absolute right. If you object, we stop, with no balancing exercise. You can exercise this yourself at any time using the unsubscribe link in any product email or in Settings → Email and privacy; you do not need to be signed in to use the link in an email.
  • Withdrawal of consent — where we rely on consent (analytics and marketing cookies, and the AI text setting), you can withdraw it at any time using the in-app "Cookies" button or Settings → Email and privacy. Withdrawing consent does not affect processing that already happened.

How to make a request. Email support@nedio.xyz. We answer within one month. If a request is complex we may extend that by up to two further months and will tell you why within the first month. There is no charge unless a request is manifestly unfounded or excessive.

To protect your data against someone else asking for it, we may need to verify your identity before acting — normally by asking you to write from the address on the account.

Complaints. If you are unhappy with how we handled your data or your request, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at https://ico.org.uk/make-a-complaint/ or on 0303 123 1113.

10) International transfers

Several of the providers listed in Section 5 are based in, or store data in, the United States and other countries outside the United Kingdom.

Where personal data leaves the UK, we rely on one of the following:

  • UK adequacy regulations, where the destination country has been found to provide adequate protection; or
  • the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, entered into with the provider; or
  • for providers certified under the UK Extension to the EU–US Data Privacy Framework, that certification.

You can ask us which mechanism applies to a particular provider by writing to support@nedio.xyz.

11) Children’s privacy

The Service is not intended for children under 13 (or the minimum age required in your jurisdiction). If you believe a child has provided us personal information, contact support@nedio.xyz.

12) Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date and, where required, provide additional notice.

NEDIOTermsPrivacyCookie PolicyDo Not Sell/Share

Cookies & privacy. Essential cookies keep sign-in and the core features working. Optional ones help us measure usage and improve NEDIO. Privacy Policy · Cookie Policy · Do Not Sell/Share