Enerio Logo

Privacy Policy

Last updated: 5 April 2026

1. Introduction

Enerio ("Enerio", "we", "us", or "our") provides a web-based service at www.enerio.app that helps users track activities that charge or drain their energy, review patterns, and receive AI-assisted reflections and summaries.

This Privacy Policy explains what personal data we collect, how we use it, when we share it, and what rights you may have in relation to that data.

2. Data We Collect

Account and authentication data

When you create an account, we collect your email address, password, and account metadata such as account creation time. If you sign in with Google, we receive your email address, Google account ID, and basic profile name fields returned during the Google sign-in flow.

Profile data you choose to provide

You may optionally provide profile fields such as first name, last name, date of birth, primary goal, timezone, notification preference, wake time, and sleep time.

Energy tracking and reflection data

We collect the content you enter into Enerio, including energy transactions, titles, descriptions, tags, categories, charger/drainer classification, amounts, daily summaries, weekly summaries, goals, achievement progress, and related feedback you submit inside the product.

Technical and analytics data

We use analytics tools to understand how the site and application are used. This may include page visits, approximate geography, browser or device characteristics, referrer information, and performance data. Where optional analytics consent controls are shown, those analytics are only loaded after the relevant user choice has been granted.

3. How We Use Personal Data

  • To create and manage your account
  • To authenticate you and keep the service secure
  • To store, display, and organise your energy tracking data
  • To generate AI-assisted classifications, summaries, goals, and insights
  • To operate achievements, XP, and level-based engagement features
  • To improve the product, debug issues, and review feedback you submit
  • To comply with legal obligations or protect the service from misuse

4. AI Processing and Automated Decision-Making

Some features of Enerio use AI models to classify energy entries, generate summaries, identify patterns, and propose weekly goals. This means the content you enter into the product may be processed by AI-related infrastructure operated by Enerio and its service providers.

These AI features are used to assist your self-reflection and do not produce decisions that have legal or similarly significant effects on you. You are free to disregard any AI-generated output.

We do not describe Enerio as a medical, therapeutic, or diagnostic service. The outputs are intended for reflection and productivity support, not clinical decision-making.

5. Legal Bases (GDPR/UK GDPR)

Where GDPR or UK GDPR applies, we generally process personal data on one or more of the following bases:

  • Performance of a contract — to provide the Enerio service you signed up for
  • Legitimate interests — to secure, maintain, improve, and analyse the service
  • Consent — where we rely on an optional permission or voluntary submission. Where we process data based on your consent, you can withdraw that consent through the product's analytics consent controls where available, or by contacting us at contact@enerio.app. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal
  • Legal obligation — where required by applicable law

6. Sharing and Service Providers

We do not sell personal data.

We may share data with service providers that help us operate Enerio, such as:

  • hosting and infrastructure providers
  • analytics providers
  • authentication providers such as Google
  • AI/model providers used to power Enerio features

We may also disclose information if required by law, to enforce our terms, or to protect Enerio, our users, or others.

7. International Transfers

Depending on the providers used to operate Enerio, your data may be processed outside your country of residence, including outside the UK or EEA. Where applicable, we aim to rely on appropriate transfer mechanisms made available by law and our vendors.

8. Data Retention

We retain account and product data for as long as it is needed to provide the service, maintain account integrity, resolve disputes, comply with legal obligations, and protect the platform.

Where you request deletion, we may need reasonable time to process that request and may retain limited records where required for security, fraud prevention, legal compliance, or backup cycles.

9. Security

We use reasonable technical and organisational measures to protect personal data, including access controls, encrypted connections, secure password storage, and account isolation.

However, no method of electronic transmission or storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

10. Your Rights

Depending on where you live, you may have rights to:

  • request access to your personal data
  • request correction of inaccurate data
  • request deletion of personal data
  • request restriction of certain processing
  • object to certain processing
  • request a portable copy of data where applicable

To make a request, contact us at contact@enerio.app. We will respond to your request within one month, or inform you if we need additional time as permitted by law.

If you are located in the UK, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk. If you are located in the EEA, you may lodge a complaint with your local data protection authority.

11. California Privacy Notice (CCPA/CPRA)

We do not sell personal information as those terms are generally used in the CCPA/CPRA context. Subject to applicable law, California residents may request access to, deletion of, or correction of personal information we hold about them, and may request more detail about categories of information collected and disclosed.

12. Children

Enerio is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children under 16. If you believe personal data has been provided by a child under 16, please contact us so we can investigate and, where appropriate, delete that information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we may update the date above and provide additional notice where appropriate.

14. Contact

For privacy or data requests, contact: contact@enerio.app