Legal
Privacy Policy
What Four80 reads, why, where it goes, and how to make it stop.
Last updated 18 September 2026
Four80 is a task-capture and time-budget service operated by Courageous Spirits Ltd (“Four80”, “we”, “us”). This policy explains what personal data we process when you use Four80, the legal basis for it, who we share it with, and the rights you have. It is written to be read, not to hide behind length. If anything here is unclear, email privacy@four80.ai.
01Who we are
The data controller for your account is Courageous Spirits Ltd, a company registered in the United Kingdom. For questions about this policy or to exercise any right below, contact privacy@four80.ai. Where you use Four80 for your business and connect your colleagues’ or company accounts, your organisation is the controller of that data and Four80 acts as its processor.
02What we collect
We process three kinds of data.
Account data — the details that make your account work: your name, email address, a hashed password (we never store the password itself), your timezone, working hours, notification preferences, the devices you sign in from, and your IP address at sign-in. If you subscribe, our payment processor (Stripe) handles your card details; we never see or store them.
Content you connect — this is the heart of the product and the part that matters most. When you connect an account, Four80 reads, on your behalf and only to find and prepare your tasks:
- your email (to surface commitments you agreed to and did not write down);
- your calendar (to schedule your day around your meetings);
- meeting transcripts from Microsoft Teams and Google Meet, and phone-call notes via Pocket;
- notes and lists you capture by voice, photo or typing.
Third-party content. The mail, transcripts and notes above inevitably contain the words of other people — the person who emailed you, the others on your call. We treat all of it as personal data, we minimise how long we keep it (see retention below), and we never use it to build any profile of those people or for any purpose other than preparing your own tasks.
03How we use it, and our legal basis
We process account data to provide the service and to bill you — the legal basis is performance of our contract with you. We process the content you connect to detect the tasks you agreed to, draft the groundwork for them, and schedule your day — the legal basis is your explicit consent, given each time you connect a source, and which you can withdraw at any time by disconnecting it. We may process limited account data to keep the service secure and to meet our legal obligations, on the basis of our legitimate interests and legal duties.
We do not sell your data, and we do not use it for advertising.
04AI processing
Four80 uses AI models from Anthropic to read the content you connect and prepare your tasks and drafts. Content is sent to Anthropic only to produce your result and is not used by Anthropic to train its models. Four80 keeps the working copy of any content it reads only briefly — long enough to produce the task — and then discards it; only the task it produced is kept.
05Who we share it with (sub-processors)
We use a small set of trusted providers to run the service. Each processes data only on our instructions and under contract:
- Vercel — hosts the web application.
- Neon — hosts the database.
- Fly.io — runs the background processing.
- Anthropic — the AI models that read content and draft tasks (no training on your data).
- Google and Microsoft — the mail, calendar and meeting sources you connect.
- Resend — sends transactional email (password resets, notifications).
- Stripe — processes payments.
- Expo — delivers mobile push notifications.
A current list is maintained here and updated as it changes. Some of these providers may process data outside the UK/EU; where they do, that transfer is covered by appropriate safeguards.
06How long we keep it
We keep your account and your tasks for as long as your account is open. The raw content we read to create a task — the mail excerpts, transcripts and notes — is minimised: by default it is deleted after 90 days, and you can shorten or extend that window in Settings → Data retention. When you delete a task it is removed; our audit records of security-relevant events are kept for up to 400 days and then deleted.
07Security
Connections and tokens are encrypted at rest. Access to your data is isolated to your account at the database level, every request is authenticated, and support staff cannot read your mailbox or content. Traffic is encrypted in transit. No system is perfect, but security is designed in rather than added on. If we ever suffer a breach affecting your data, we will notify you and the relevant regulator as the law requires.
08Your rights
Under UK GDPR you have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to its processing, and to data portability. You can withdraw consent for any connected source at any time by disconnecting it in Settings. To exercise any of these rights, email privacy@four80.ai and we will respond within one month. Account deletion and a full data export can be requested by the same route while we finish building the self-service versions. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
09Changes
We will update this policy as the product changes and will revise the date at the top. For material changes affecting how we use your data, we will tell you before they take effect.