Privacy Policy

Last Updated: September 7, 2026

This Privacy Policy explains how Nooshee Inc., doing business as OnTopOfIt (“OnTopOfIt,” “we,” “us,” or “our”) collects, uses, stores, and shares personal data through the OnTopOfIt desktop application, the OnTopOfIt mobile companion application, and ontopofit.ai (collectively, the “Service”).

OnTopOfIt is a Nooshee Inc. product, operated alongside the company’s other applications, including MarkMate.

This Privacy Policy should be read together with our Terms and Conditions.

1. The Short Version

OnTopOfIt is designed to minimize the information that we receive from your device.

Your AI provider’s Admin or Provisioning API key is stored only on your device in encrypted operating-system credential storage. OnTopOfIt does not receive, store, or transmit your API key to our servers.

Your detailed AI usage history, including individual model calls, token counts, and timestamps, is also stored locally on your device and is not transmitted to OnTopOfIt.

We collect and process information needed to operate your account, provide the Service, process payments, provide customer support, and protect the Service.

If you are a Premium subscriber, the desktop application also sends certain limited information derived from your local usage data to our cloud infrastructure. This enables features such as off-device alerts and Remote Cutoff.

The information we collect and process is described in detail below.

2. What We Collect

2.1 Account Information

If you create or link an OnTopOfIt account, we collect and store:

  • Your email address;
  • A hashed record of any sign-in code we send you;
  • A hashed record of the resulting session token;
  • An identifier for each device linked to your account;
  • The display name you have assigned to each linked device; and
  • Timestamps indicating when a device was linked and when it was last seen online.

An account is required for paid plans, the mobile companion application, and cross-device features.

The plaintext sign-in code exists only transiently, including in the email sent to you and during a short server-side processing period, as described in Section 6.

An account may have up to two linked devices at a time.

2.2 Subscription and Billing Information

Payments are processed by Stripe, Inc.

OnTopOfIt does not receive or store your payment-card number or other raw payment credentials. Stripe processes those payment credentials directly.

In connection with your OnTopOfIt account, we receive and store:

  • A Stripe customer identifier;
  • Your subscription status, such as active, canceled, or past due;
  • Your current billing period;
  • Whether you hold a One-Time Unlock, independent of any subscription; and
  • Basic invoice metadata, such as amount, date, and plan, needed to reconcile your account and subscription status.

2.3 Information We Do Not Receive: Your Provider API Key and Detailed Usage Data

Your Anthropic, OpenAI, and/or OpenRouter Admin or Provisioning API key is stored only on your device in encrypted operating-system credential storage.

Requests to your AI provider’s usage, cost, or key-management APIs are made directly from your device and are not routed through or logged by servers operated by OnTopOfIt.

Your detailed usage history, including individual model calls, token counts, and timestamps, is stored only in a local database on your device and is not transmitted to OnTopOfIt.

Accordingly, OnTopOfIt does not receive or store your AI provider API key or your detailed AI usage history.

2.4 Derived Information Received by OnTopOfIt — Premium Plan Only

If you are a Premium subscriber, the desktop application sends certain information derived from your local usage data to our cloud infrastructure on a recurring basis.

This information is used to provide features including off-device alerts and Remote Cutoff.

The information may include:

InformationDescription
Daily and monthly spend totalsA dollar amount calculated from your local usage data and transmitted to our cloud infrastructure.
Risk statusA status such as “normal” or “unusual,” together with a computed severity level generated by the Risk Engine.
Tracked key’s display nameThe name assigned to the tracked API key in Anthropic’s, OpenAI’s, or OpenRouter’s dashboard.
Device statusInformation indicating whether a linked device is online, together with a push-notification token used to deliver notifications to that device.
Cutoff event recordsInformation indicating that a Remote Cutoff was requested, executed, failed, or expired, together with the relevant time information.

The information described in this section is limited to the information necessary to provide the applicable Premium features. The underlying API key and detailed usage history described in Section 2.3 are not transmitted to OnTopOfIt.

2.5 Key Display Names

A tracked API key’s display name is supplied by you or by a teammate through Anthropic’s, OpenAI’s, or OpenRouter’s own dashboard. It is not generated by OnTopOfIt.

Because a key display name may contain a client name, project name, or other identifying text, we do not assume that such names are non-sensitive.

If you are a Premium subscriber, a tracked key’s display name may be displayed on your linked mobile device and stored on our servers as described in Section 2.4.

We recommend that you avoid including sensitive or unnecessary personal information in API key names.

2.6 Technical and Log Data

Our cloud infrastructure providers may generate standard technical request logs that include information such as your IP address and basic request metadata at the network level.

As of the date of this Privacy Policy, the OnTopOfIt desktop and mobile applications do not use third-party analytics, advertising, or crash-reporting SDKs.

3. How We Use Information

We use the information described in Section 2 for the following purposes:

  • To create and operate your OnTopOfIt account;
  • To authenticate your account and linked devices;
  • To process and manage subscriptions and payments;
  • To provide the features included in the plan you have purchased;
  • To provide Premium features, including off-device alerts and Remote Cutoff;
  • To maintain and manage linked devices;
  • To detect, prevent, and investigate abuse or misuse of the Service;
  • To maintain the security and reliability of our systems;
  • To provide customer support; and
  • To comply with applicable legal obligations and protect our legal rights.

We do not sell personal data.

We do not use the information described in this Privacy Policy for advertising purposes.

4. Who We Share Data With

We share information with service providers that help us operate the Service (“subprocessors”). These providers process information on our behalf and for the purposes described in this Privacy Policy.

Google Firebase / Google Cloud

Role: Account database, cloud functions, and push notifications.

Information processed: Account, subscription, device, and Premium-derived information described in Sections 2.1, 2.2, and 2.4.

Our cloud infrastructure is hosted in the United States, including the Google Cloud us-central1 region.

Stripe, Inc.

Role: Payment processing.

Information processed: Payment credentials are handled directly by Stripe. OnTopOfIt receives only the account and billing metadata described in Section 2.2.

Resend

Role: Transactional email delivery, including delivery of sign-in codes.

Information processed: Your email address and the sign-in code required for authentication during the applicable processing period.

We do not sell, rent, or disclose your personal data to third parties for their own marketing purposes.

5. International Data Transfers

Our cloud infrastructure is hosted in the United States, including the Google Cloud us-central1 region.

If you access the Service from outside the United States, information collected through the Service may therefore be transferred to, stored in, and processed in the United States.

Where applicable, we will use appropriate mechanisms for international transfers of personal data as required by applicable law.

6. Data Retention

We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to applicable legal, accounting, security, and other legitimate requirements.

Sign-In Codes

The sign-in code itself is single-use, permitted a maximum of five incorrect attempts, and expires 10 minutes after it is sent. It is used only for the authentication process and is not retained as a permanent account record.

The underlying email delivery record (used to send the code to you) is automatically deleted after approximately one week, separately from the code’s own much shorter validity period above.

Remote Cutoff Commands

A resolved Remote Cutoff command record, including a command that was executed, failed, or expired, is automatically deleted after 30 days.

A command that remains pending is retained until it is resolved or superseded.

Account and Device Information

Account records and linked-device information are retained while your account exists.

The latest spend and risk summary for each provider is also retained while your account exists.

You may delete this information by deleting your account through the self-service account-management functionality described in Section 8, or by contacting us as described in Section 9.

Legal and Operational Retention

Certain information may need to be retained for longer where reasonably necessary for purposes such as security, fraud prevention, tax and accounting requirements, resolving disputes, enforcing our agreements, or complying with legal obligations.

7. Security

We use reasonable technical and organizational measures designed to protect the information we collect and maintain.

These measures include encryption in transit and hashing of sign-in codes and session tokens at rest.

OnTopOfIt’s architecture also reduces certain security risks by keeping AI provider API keys on the user’s device rather than transmitting those keys to OnTopOfIt’s servers.

No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security.

8. Managing Your Linked Devices and Account

Each OnTopOfIt account may have up to two linked devices at a time, such as one desktop computer and one mobile phone.

Removing a Linked Device

If a linked device is lost, sold, replaced, or is otherwise no longer under your control, you may remove its access through the device-management functionality provided by the Service.

The desktop application’s Settings allow you to view linked devices and remove a device following the applicable confirmation process. The mobile companion application also provides device-management functionality.

When a device is removed, it can no longer authenticate to the account, receive applicable alerts, or be reached for Remote Cutoff through the account.

A removed device must complete the sign-in process again to reconnect.

Deleting Your Account

You may permanently delete your OnTopOfIt account through the account-management functionality in the desktop application’s Settings.

Deleting your account:

  • Cancels any active Premium subscription;
  • Removes access for linked devices; and
  • Initiates deletion of your account data from our servers, subject to the retention requirements described in Section 6.

If You Cannot Access Your Linked Devices

If you cannot access either of your linked devices, contact us. We may ask you to verify your identity before assisting with account or device management.

9. Your Privacy Rights

You may contact us to request:

  • Access to personal data we hold about you;
  • Correction of inaccurate or incomplete personal data;
  • Deletion of your personal data;
  • Information about how your personal data is processed; or
  • Objection to or restriction of certain processing, where applicable.

Depending on where you live, you may also have additional rights under applicable privacy laws, including rights relating to data portability or other forms of control over your personal data.

To exercise your privacy rights, contact us at ontopofitai@gmail.com.

We will consider and respond to requests in accordance with applicable law.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our data practices, or applicable legal requirements.

If we make a material change to this Privacy Policy, we will provide reasonable notice before the change takes effect, such as by email or through an in-app notice.

The “Last Updated” date at the beginning of this Privacy Policy indicates when it was most recently revised.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

Email: ontopofitai@gmail.com

Mailing address:
Nooshee Inc.
411 NW 52nd St
Oakland Park, FL 33309
USA