Privacy Policy
Last updated: 29 September 2026
This policy explains what personal data Enesy Project Management OS (“Enesy PMOS”, “we”, “us”) collects when you use the app at enesypmos.co.uk, why we collect it, who we share it with, and the rights you have over it. It's written to describe what the product actually does, not generic boilerplate — if something below looks wrong to you, that's worth telling us.
This document is provided for transparency and has not been reviewed by a solicitor. It is not a substitute for professional legal advice, and shouldn't be treated as a complete statement of your legal rights.
1. Who we are
Enesy PMOS is operated by Ernest Adesioye, trading as Enesy PMOS. For any privacy question, request, or concern, contact info@enesypmos.co.uk.
2. What we collect
Account data
When you sign up (by email/password, or via Google or Microsoft sign-in) we store your name, email address, and — if provided by Google or Microsoft — a profile picture URL. If you sign up with email and password, your password is handled entirely by our authentication provider, Supabase; we never see or store it in plain text.
Project data you create
Everything you enter into the app — projects, tasks, milestones, RAID items, comments, reports, and workspace settings — is stored so the app can function. This is your data; we don't use it for anything beyond providing the service and the AI features you actively use (see section 4).
Connected inbox data (Gmail / Outlook — optional)
If you choose to connect a Gmail or Outlook inbox, we request read-only access to your mail (Gmail: gmail.readonly; Outlook: Mail.Read) so the app can surface relevant project signals from your inbox. From matching emails we store the subject line in full, the first part of the message body (up to roughly 8,000 characters), sender name and address, and timestamps — along with an AI-generated summary. We don't store your full mailbox or attachments beyond what you explicitly extract into the app. You can disconnect an inbox at any time from Settings → Integrations, which stops further syncing; previously imported signals remain until you delete them.
Google Drive files you choose to link (optional)
If you connect Google Drive, we ask for the drive.file permission (files you select in Google's file picker) and the read-only drive.readonly permission, which lets Enesy PMOS list and read the files in Drive folders you choose to link so it can keep them up to date. We only read; we never edit, delete or share your files. For each file you link we store its name, type, link and the text we extract from it, so it can be shown against your project and used by the AI assistant. You can unlink a file or disconnect Drive at any time from Settings → Integrations, and you can also revoke access from your Google Account permissions page.
Google user data
We access Google user data only to provide the features you have asked for: signing you in and, if you connect Drive or Gmail, the files, folders and mail you choose to link. We do not sell Google user data, use it for advertising, or use it to train or improve AI models. Our staff do not read Google user data except where you ask us for support or where the law requires it. When you use the AI assistant, text from files you have linked is sent to our AI provider only to write the answer you asked for.
Enesy PMOS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Payment data
Subscription billing is handled by Stripe. We never see or store your card details — we only keep a Stripe customer ID and subscription ID so we know what plan you're on.
Usage and error data
We use Sentry to capture crash reports and errors so we can fix bugs. These reports can include technical details about what you were doing when an error occurred (e.g. the page you were on, request data). We don't currently run any product analytics or marketing tracking — there's no Google Analytics, Meta Pixel, or similar on this app.
3. Cookies
We only set the session cookies our authentication provider (Supabase) needs to keep you signed in. We don't use advertising or marketing cookies, and there's currently no analytics tracking that would need a cookie consent banner.
4. AI features
Enesy PMOS uses a third-party AI language model provider to power features like the AI assistant, report generation, and inbox signal extraction. When you use these features, relevant text — for example task and project details for report generation, or extracted email content for inbox signal analysis — is sent to that provider's API to generate a response. This is the one case where inbox content you've connected may leave our infrastructure; it's only sent for the purpose of producing the AI output you asked for, and only for inboxes you've chosen to connect.
5. Who we share data with
We use the following sub-processors to run the app. None of them are permitted to use your data for their own purposes. For the full list with data processing locations, see our Subprocessors page.
- Supabase — authentication and database hosting (all app data lives here).
- Stripe — payment processing for paid plans.
- Resend — sending transactional emails (verification, password reset, invites, notifications).
- Sentry — error monitoring.
- Upstash — rate limiting, to detect abusive request bursts on sign-in and AI features.
- AI language model provider — powers the AI assistant, report generation, and inbox analysis.
- Google / Microsoft — sign-in; Google Drive if you link files or folders; Gmail/Outlook if you connect an inbox.
We don't sell your data, and we don't share it with anyone else for marketing or advertising purposes.
6. International transfers
Some of the providers above (including Stripe, Google, Microsoft, and our AI language model provider) may process data outside the UK. Where that happens, we rely on the safeguards those providers offer (such as Standard Contractual Clauses) to keep your data protected to a comparable standard. Our AI language model provider stores the data it receives on servers in Singapore.
7. How long we keep data
We keep your data for as long as your account is active. If you delete your account (Settings → Account → Delete Account), your data is deleted immediately, provided you don't belong to any shared workspace with other members — in that case you'll need to leave those workspaces first, since we won't delete data other people rely on without their knowledge. Backups and error logs may persist for a short additional period before they age out.
8. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (most of this you can edit yourself in Settings).
- Delete your data — self-serve via Settings → Account → Delete Account, or by emailing us if you need help.
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Complain to the UK Information Commissioner's Office (ICO) if you think we've mishandled your data.
To exercise any of these rights, email info@enesypmos.co.uk.
9. Security
We use industry-standard measures to protect your data, including encrypting connected inbox tokens at rest, authorization checks that verify your workspace and project membership before any data is returned or changed, and encrypted connections (HTTPS) throughout. No system is perfectly secure, but we take reasonable steps to protect what you share with us.
10. Children
Enesy PMOS is intended for business use by adults. It's not directed at, and we don't knowingly collect data from, anyone under 18.
11. Changes to this policy
If we make material changes to this policy, we'll update the “Last updated” date above. Continued use of the app after a change means you accept the updated policy.
12. Contact
Questions about this policy or how we handle your data: info@enesypmos.co.uk.