Privacy Policy
Last updated: 29 July 2026
This policy explains what personal data Enesy Project Management OS (“Enesy PMOS”, “we”, “us”) collects when you use the app at enesypmos.co.uk, why we collect it, who we share it with, and the rights you have over it. It's written to describe what the product actually does, not generic boilerplate — if something below looks wrong to you, that's worth telling us.
This document is provided for transparency and has not been reviewed by a solicitor. It is not a substitute for professional legal advice, and shouldn't be treated as a complete statement of your legal rights.
1. Who we are
Enesy PMOS is operated by Ernest Adesioye, trading as Enesy PMOS. For any privacy question, request, or concern, contact info@enesypmos.co.uk.
2. What we collect
Account data
When you sign up (by email/password, or via Google or Microsoft sign-in) we store your name, email address, and — if provided by Google or Microsoft — a profile picture URL. If you sign up with email and password, your password is handled entirely by our authentication provider, Supabase; we never see or store it in plain text.
Project data you create
Everything you enter into the app — projects, tasks, milestones, RAID items, comments, reports, and workspace settings — is stored so the app can function. This is your data; we don't use it for anything beyond providing the service and the AI features you actively use (see section 4).
Connected inbox data (Gmail / Outlook — optional)
If you choose to connect a Gmail or Outlook inbox, we request read-only access to your mail (Gmail: gmail.readonly; Outlook: Mail.Read) so the app can surface relevant project signals from your inbox. From matching emails we store the subject line in full, the first part of the message body (up to roughly 8,000 characters), sender name and address, and timestamps — along with an AI-generated summary. We don't store your full mailbox or attachments beyond what you explicitly extract into the app. You can disconnect an inbox at any time from Settings → Integrations, which stops further syncing; previously imported signals remain until you delete them.
Payment data
Subscription billing is handled by Stripe. We never see or store your card details — we only keep a Stripe customer ID and subscription ID so we know what plan you're on.
Usage and error data
We use Sentry to capture crash reports and errors so we can fix bugs. These reports can include technical details about what you were doing when an error occurred (e.g. the page you were on, request data). We don't currently run any product analytics or marketing tracking — there's no Google Analytics, Meta Pixel, or similar on this app.
3. Cookies
We only set the session cookies our authentication provider (Supabase) needs to keep you signed in. We don't use advertising or marketing cookies, and there's currently no analytics tracking that would need a cookie consent banner.
4. AI features
Enesy PMOS uses a third-party AI language model provider to power features like the AI assistant, report generation, and inbox signal extraction. When you use these features, relevant text — for example task and project details for report generation, or extracted email content for inbox signal analysis — is sent to that provider's API to generate a response. This is the one case where inbox content you've connected may leave our infrastructure; it's only sent for the purpose of producing the AI output you asked for, and only for inboxes you've chosen to connect.
5. Who we share data with
We use the following sub-processors to run the app. None of them are permitted to use your data for their own purposes. For the full list with data processing locations, see our Subprocessors page.
- Supabase — authentication and database hosting (all app data lives here).
- Stripe — payment processing for paid plans.
- Resend — sending transactional emails (verification, password reset, invites, notifications).
- Sentry — error monitoring.
- Upstash — rate limiting, to detect abusive request bursts on sign-in and AI features.
- AI language model provider — powers the AI assistant, report generation, and inbox analysis.
- Google / Microsoft — sign-in, and Gmail/Outlook access if you connect an inbox.
We don't sell your data, and we don't share it with anyone else for marketing or advertising purposes.
6. International transfers
Some of the providers above (including Stripe, Google, Microsoft, and our AI language model provider) may process data outside the UK. Where that happens, we rely on the safeguards those providers offer (such as Standard Contractual Clauses) to keep your data protected to a comparable standard.
7. How long we keep data
We keep your data for as long as your account is active. If you delete your account (Settings → Account → Delete Account), your data is deleted immediately, provided you don't belong to any shared workspace with other members — in that case you'll need to leave those workspaces first, since we won't delete data other people rely on without their knowledge. Backups and error logs may persist for a short additional period before they age out.
8. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (most of this you can edit yourself in Settings).
- Delete your data — self-serve via Settings → Account → Delete Account, or by emailing us if you need help.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Complain to the UK Information Commissioner's Office (ICO) if you think we've mishandled your data.
To exercise any of these rights, email info@enesypmos.co.uk.
9. Security
We use industry-standard measures to protect your data, including encrypting connected inbox tokens at rest, authorization checks that verify your workspace and project membership before any data is returned or changed, and encrypted connections (HTTPS) throughout. No system is perfectly secure, but we take reasonable steps to protect what you share with us.
10. Children
Enesy PMOS is intended for business use by adults. It's not directed at, and we don't knowingly collect data from, anyone under 18.
11. Changes to this policy
If we make material changes to this policy, we'll update the “Last updated” date above. Continued use of the app after a change means you accept the updated policy.
12. Contact
Questions about this policy or how we handle your data: info@enesypmos.co.uk.