← This & That

Privacy Policy

Last updated: 23 July 2026

This policy explains what information This & That collects, why, where it is stored, who can access it, and the choices and rights you have. It reflects how the product works today.

Who we are

This & That ("the Service") is operated by RKM Industries, 201, 2nd Floor, Building Number 4, Vasant Lawns, Majiwada, Thane West – 400601, Maharashtra, India ("we", "us"). For any privacy question or request, contact info@rkm.support.

What we collect

Account data: the email address you sign in with. We use passwordless sign-in (a one-time code), so we never store a password.

Workspace content you create: tasks, people you add, groups, notes, records, calendar entries and follow-up settings. This is the data the Service exists to hold for you.

Contacts you choose to import: if you import contacts, the names, numbers, emails and photos you select are stored in your workspace. Importing is always initiated by you.

Technical data: minimal request metadata (e.g. IP address for rate-limiting and abuse prevention) and, if you consent, basic product analytics.

We do not sell your personal data, and we do not use it to serve ads.

Where your data is stored and who processes it

Your workspace is stored in a per-user, access-controlled database row (Supabase, Postgres with Row-Level Security) so that only your authenticated account can read or write it.

The application is hosted on Vercel. Data in transit is encrypted with HTTPS/TLS.

Sub-processors we rely on: Supabase (authentication and database) and Vercel (hosting). If and when you enable optional integrations, additional processors apply only to the data routed through them — for example a payment provider (Razorpay, for payments handled by our merchant of record), an AI provider you select (Google Gemini, Anthropic Claude or OpenAI), or a messaging provider (e.g. WhatsApp/Meta). These are off until explicitly configured.

AI processing

When AI features are enabled, the specific text needed to answer your request (for example a question you ask, plus the relevant snippet of your workspace) is sent to the AI provider selected for that request. We send the minimum needed and instruct the provider not to invent facts about your data.

If you use your own AI key (bring-your-own-key), your key is stored only in your browser and calls go directly from your device to the provider — your key never reaches our servers. See the AI & Data page for details.

Legal bases

Where GDPR/UK-GDPR applies, we process your data to perform our contract with you (providing the Service), on the basis of your consent (optional analytics and optional integrations), and for our legitimate interests in keeping the Service secure and functional.

Your rights

You can access and edit your workspace at any time inside the app.

You can export your data and you can delete your account and its data. Deleted items are held briefly in Recently Deleted and then permanently removed.

After account deletion, residual copies are purged within 30 days after deletion, except where we must retain records to meet a legal obligation.

Depending on where you live, you may also have rights to restrict or object to processing, or to lodge a complaint with your data-protection authority. To exercise any right, contact info@rkm.support.

Security

We enforce per-user isolation at the database layer (Row-Level Security), encrypt data in transit, apply a strict Content-Security-Policy and other security headers, and rate-limit our API. No system is perfectly secure, but we design to limit blast radius and never expose one user's data to another.

Children

The Service is not directed to children under 16, and we do not knowingly collect their data.

Changes & contact

We will update this policy as the Service evolves and revise the date above. Questions or requests: info@rkm.support. Governing law: India.