Privacy policy

Last updated 28 August 2026

Zeylix PMT is a work-management application operated by Zeylix. Accounts are created by an administrator; if you do not have one, the application holds no data about you.

What we store

  • Your account — name, work email, designation, role, avatar and notification preference.
  • Your work — projects, tasks, comments, documents, meetings, work logs and attachments.
  • An audit trail — who changed what and when, readable only by administrators.

All of it is held in a Supabase-hosted PostgreSQL database, with access enforced in the database itself rather than in the user interface alone.

Google account data

Connecting Google Calendar is optional — meetings work without it. If you connect, Zeylix PMT requests these scopes and no others:

  • openid and email — to identify which Google account you connected and to refresh access.
  • https://www.googleapis.com/auth/calendar.events — to create, update and delete the calendar events for meetings you schedule in Zeylix PMT.

The narrower calendar.events scope is used deliberately in place of the broader calendar scope, which would also grant control over sharing and permissions on every calendar you can access. Zeylix PMT does not read your existing calendar entries, and only touches events it created.

What is stored: the Google account email you connected, the target calendar identifier, the granted scopes, and the OAuth access and refresh tokens needed to keep the connection working. The token columns are not readable by any signed-in client — only server-side code can use them — and each row is restricted to the person it belongs to. Supabase encrypts stored data at rest.

Limited use

Zeylix PMT’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the calendar features described above. It is never sold, never used for advertising, never used to train machine-learning models, and never transferred to anyone else except as needed to provide those features, to comply with the law, or as part of a merger or acquisition following notice.

Disconnecting and deletion

  • Disconnect Google Calendar at any time from Settings. The stored tokens are deleted.
  • You can also revoke access from your Google account permissions page. The application detects this and stops attempting calendar writes.
  • Events already created remain in your calendar after disconnecting; delete them in Google Calendar if you do not want them.
  • When an administrator deletes your account, the account record and any stored Google tokens are removed. Work you created remains, as it belongs to the business.

Who else sees it

Your work is visible to colleagues using the application. Outside the company, data is handled only by the services needed to run it: Supabase (database, authentication, file storage), Microsoft Azure (hosting), Brevo (transactional email) and Google (only if you connect Calendar). We do not sell data, and there is no advertising or third-party tracking.

Email

Transactional email only — invitations, password resets, and notifications about work assigned to or mentioning you. There is no marketing email. Notifications can be turned off in Settings; invitations and password resets are sent regardless, because they are needed to access the account.

Contact

Questions about this policy or the data held about you: pmt@zeylix.com. If the policy changes materially, the date at the top of this page changes with it.