This policy covers all three Limecore apps together, because they share one account system and one database. It describes what the apps actually do — if anything here does not match the software, that is a bug, and we want to hear about it.
The data controller is Limecore Studio, a sole trader based in Helsinki, Finland.
Contact for anything in this policy, including data requests: l1m3core@gmail.com. We answer within one calendar month, and usually much sooner.
Every app can be used without an account. In guest mode everything you enter — your finances, training, coursework, tasks and habits — is written to your device's local storage and nowhere else. We never receive it, cannot read it, and cannot recover it for you. Uninstalling the app deletes it.
One honest caveat: Nexus Command Center still fetches public market prices and exchange rates while you are a guest, because a price chart with no prices is not much use. Those requests carry a ticker symbol, never anything you entered. See Who else sees your data.
The Android apps also ask f-droid.org, at most once a day, whether a
newer version exists, so they can tell you about fixes you have not installed.
That request names the app and nothing else, and you can turn it off in
Settings. Error reports and feedback need an account, so a guest never sends
either.
Your data lives in a Supabase database hosted in Stockholm, Sweden (EU). Every table enforces row-level security, so the database itself — not just the app code — prevents anyone from reading rows that are not theirs.
| Email address | How you sign in, and how we reach you if we must. |
|---|---|
| Name and profile picture | Only if you sign in with Google, and only as Google supplies them. |
| Preferences | Things like language and units, so they survive a reinstall. |
| Feedback you send | Only when you use the Feedback form in Settings: your message, the category and rating you picked, and the app, version and platform it came from. We read it to decide what to fix or build next. We may mark it as planned or shipped. Kept until you delete your account. |
|---|---|
| Error reports (only if switched on) | When an app hits an error it cannot recover from: the app, version, platform and Android or browser version, the error message, the location in our code where it happened (a stack trace), which screen was open, and the time. They never include your finances, training, coursework, notes or anything else you entered. We shorten error messages and strip anything that looks like an email address or a long number, but an error message can very occasionally contain a fragment of what was on screen, so we say so rather than promise it cannot. Erased automatically after 90 days. |
Error reports are off after a fresh install. You can switch them on in Settings, or send a single report from the screen an app shows after a crash. They exist so that a bug gets fixed without anyone having to describe it first. They are not analytics: they describe a failure, not what you did, and nothing is sent while the app is working normally.
| Finance | Budget categories and limits, transactions, manual assets and account balances, investment holdings, purchase lots, sales, cash entries, watchlist symbols, savings goals. |
|---|---|
| Tasks & habits | Tasks and due dates, habits and their daily completions. |
| Work | A daily 1–5 self-rating and an optional short note. |
| Sharing | If you share a budget or task with someone, we store who it is shared with and what permission they have. |
Financial figures you enter are stored as you enter them. We do not connect to your bank, and we never see your banking credentials — there is no such feature. Market prices are fetched from public data providers by symbol only; those requests do not identify you.
| Training | Programs and phases, sessions, every set with its weight, reps and effort rating, personal records, and session notes. |
|---|---|
| Body metrics | Bodyweight and any measurements you choose to record, plus vertical-jump entries. |
| Progress photos | Stored only on your device. Photos are never uploaded and never reach our database. |
| Health Connect (only if you grant it) | Read on your device and never stored. If you allow it, LimeLog reads today's step count and active calories from Android Health Connect to show them on the Today screen. The numbers are displayed and discarded — they are not written to our database, not saved on your device, and not included in your export, because we never hold a copy. Revoke the permission in Health Connect and the reading stops immediately. |
| AI debrief (only if switched on) | The note you typed, plus what the model extracted: an effort rating, any body parts you mentioned as sore, a mood, and a one-line summary. |
| Courses | Name, colour, credits, semester, school year. |
|---|---|
| Grades | The grade, its weight, the date, and any note you write. |
| Study sessions | Start time, duration, focus rating, and any note you write. |
| AI debrief (only if used) | The note you typed, plus what the model extracted: topic, a 1–5 comprehension rating, concepts you flagged as confusing, and a one-line summary. |
| Home-screen widgets (only if you add one) | Stays on your device. If you place a StudyDesk widget, the app writes a short list of upcoming assignments and exams — title, course name and due date — to private app storage so the launcher can draw it. Nothing is uploaded, and it is removed when you remove the widget. Worth knowing: whatever a widget shows is visible to anyone who can see your home screen, and depending on your launcher that can include a locked screen. If your coursework titles are sensitive to you, don't add the widget. |
No location, no contacts, no advertising or device identifiers, no browsing history, no usage analytics. The apps request no permissions for any of it. (Error reports, described above, are off unless you switch them on, and are about crashes rather than about you.)
The only sensitive permissions any of the three ever ask for are notifications, the camera (LimeLog progress photos, which stay on your device) and Health Connect (LimeLog steps and calories, which are read and discarded). Each is requested only when you use the feature that needs it, each can be declined, and declining costs you that one feature and nothing else.
We do not sell or share your data, ever, with anyone, for any purpose. The services below are the only ones that receive anything at all.
Hosts the database and handles sign-in. Data is stored in the EU.
Only in two situations, both of which you choose:
To show prices, exchange rates and market indicators, Nexus Command Center
requests public data from CoinGecko, Yahoo Finance, Finnhub,
open.er-api.com, the European Central Bank, the US Federal
Reserve, NYSE and CNN's market-indicator feed.
These requests carry a ticker symbol or a currency pair and nothing else — no account, no name, no email, no holdings, no amounts. They cannot see what you own or how much. They do, like any web request, see the IP address it came from. They happen whether or not you have an account, because prices are the same for everyone. The other two apps make no such requests.
Nexus Command Center and StudyDesk also run in a browser, at
nexus.limecore.dev and studydesk.limecore.dev. Those two
websites are hosted by Vercel. LimeLog has no web edition. Nothing in
this section applies to the Android apps — the analytics code described
here is excluded from them at build time, so it is not merely switched off in the
APK, it is not in the file.
Page counting. The websites use Vercel Web Analytics, which records the page you opened, the site that linked you there, and a coarse country, browser and device type. It sets no cookies, stores nothing on your device, and is never joined to your account — we can see that a page was opened, not who opened it. We use it to know whether anyone is finding the apps at all.
Market data on the web edition takes a detour. A browser cannot call most of the market-data providers listed above directly, so on the Nexus Command Center website those requests are forwarded through Vercel first. Vercel therefore sees them, and may keep them in its request logs for a period it controls. The Android app calls the providers straight from your device and skips this entirely.
One consequence is worth stating plainly rather than leaving you to infer it. If you add your own Finnhub API key in Settings on the website, the key goes along with those forwarded requests. It travels in a hidden request header, not in the web address, so it is not part of the addresses Vercel keeps in its request logs. It does still pass through Vercel's servers on its way to Finnhub. If you would rather it did not, use the Android app, where the request never passes through us.
At most once a day each Android app asks F-Droid's public website which version
it currently offers. The request names the app (for example
com.StudyDesk.app) and carries nothing about you, your account or
your data. Like any web request, F-Droid sees the IP address it came from. You
can turn the check off in Settings; the app then never contacts F-Droid itself.
All three apps have a "support this project" row in Settings. It is an ordinary
link that opens ko-fi.com in your browser — there is no payment
form inside the apps, no payment SDK, and no tracking pixel. Nothing is sent
anywhere unless you tap it, and tapping it sends nothing about you beyond what
any browser sends when it opens a page.
If you choose to donate, Ko-fi and its payment processor handle that entirely. We never see your card details — they do not pass through our apps or our database. What we receive from Ko-fi is what any creator sees: a display name, the amount, and a message if you leave one. That is held by Ko-fi under their own privacy policy, not by us, and it is not linked to your Limecore account — we have no way to tell which account a donor belongs to. Donating is not required and unlocks nothing; every feature is free either way.
Each app has one optional feature that sends something to Google's Gemini model. All three are off until you switch them on in Settings, and they stay off after a fresh install, after a reinstall, and for anyone who signs in on a device where someone else turned them on.
| StudyDesk — study debrief | Sends the note you type after a study session. Gemini returns the topic, a 1–5 comprehension rating, anything you flagged as confusing, and a one-line summary. |
|---|---|
| LimeLog — workout debrief | Sends the note you type after a session. Gemini returns an effort rating, any body parts you mentioned as sore, a mood, and a one-line summary. |
| Nexus Command Center — weekly summary | Sends your domain scores only — five numbers between 0 and 100, plus the pattern headlines already shown on the Life tab. It never sends transactions, amounts, account names, task text or habit names. Gemini returns two or three sentences. |
In practice this means: anything you type into a study or workout debrief could end up as training data at Google. The Nexus Command Center summary sends only five 0–100 scores and the headlines already on your screen, so there is nothing personal in it to train on — but the two debriefs send exactly the words you wrote.
If that is not acceptable to you, leave the switch off. Nothing else in any of the apps changes, and no feature other than these three is affected. If we ever move to Google's paid tier — where this use is contractually excluded — we will update this page and say so in the apps.
You must be at least 16 to create an account, or the minimum age for consenting to online services where you live if that is lower — it is 13 in some EU countries.
StudyDesk in particular is used by people at school. If you are under that age, you can still use any of these apps: use them as a guest, where no account exists and nothing leaves your device. If you believe someone under that age has created an account, contact us and we will delete it.
Under the GDPR you may request access to your data, correct it, delete it, restrict or object to processing, and receive it in a portable format.
Two of those are buttons rather than requests, so you never have to wait for us:
Both are in Settings, in all three apps. Because the three share one account, either button works from whichever app you happen to have open and covers your data in all of them — deleting from LimeLog erases your StudyDesk coursework too, and the confirmation says so before you commit.
Export also works as a guest. A guest's data never left the device, but it is still yours to take a copy of.
For anything else, email l1m3core@gmail.com.
If you think we have handled your data badly you can complain to the Finnish Data Protection Ombudsman (tietosuoja.fi), or to the supervisory authority where you live.
Sign-in is handled by Supabase Auth; we never see or store your password. All traffic is HTTPS. Every table has row-level security enabled, enforced by the database rather than by application code, so a bug in an app cannot expose one user's rows to another.
No system is perfect. If we discover a breach affecting your personal data we will notify the Finnish Data Protection Ombudsman within 72 hours and tell you directly where the law requires it.
All three apps are MIT-licensed and their full source is public. You do not have to take any of this on trust — you can read exactly what the apps send and when: Nexus Command Center, LimeLog, StudyDesk.
If this policy changes materially we will say so in the apps rather than quietly editing this page. The full revision history is public in the repository.