Legal

Privacy Policy

Last updated: August 19, 2026

Who's responsible for your data

TaskPocket is operated by Bohdan Stefaniuk, a sole proprietor based in Ontario, Canada. For any privacy question, email [email protected].

Our approach to privacy

We respect your privacy. The goal is to collect as little data as possible while still giving you a reliable, useful service. We do not sell your data to anyone — not to advertisers, data brokers, or third parties. Your tasks, projects, and everything else you create are yours alone.

The content you create never leaves our own service. The text of your tasks, notes, descriptions, the names of your projects, areas, and sections, and your checklist items are stored only in our own database so we can show them back to you and sync them across your devices. We never send that content to analytics providers or advertisers, and the outside services we rely on (listed below) receive the minimum needed to do their job — none of them receive the content of your tasks, the only exception being anything you choose to quote yourself in a message you send us.

We will never train machine-learning models on your content, and we will never sell it. Treat that as permanent. Separately, and as a matter of fact today: TaskPocket has no AI features, so your content isn't sent to any AI provider at all. If that ever changes it will be a feature you switch on yourself, off by default, and we'll name the provider and say exactly what it receives before you do — with the no-training promise carried through in our contract with them.

One clarification, so the promise above means what you think it means rather than more than we can keep. It is about your content — the things you write. It doesn't stop us counting. We may work out and publish totals and averages across everyone using TaskPocket — how many tasks were completed last month, say, or how many people use projects — where the result is about the group and cannot be traced back to any individual. That kind of number is how we decide what to build, and publishing one tells you nothing about anybody. Nothing you wrote is in it.

We do not collect health or fitness data. TaskPocket does not connect to Apple Health, Google Fit, or any other health service, and asks for no health permission on any platform. It also collects no precise location, no contacts, no calendar data, no photos, and no microphone or camera access.

What we collect

We collect only what we need to run the service:

  • Account information: Your email address. If you sign in with Google or Apple, we also store the account identifier we receive from them so we can link your account on subsequent sign-ins — we do not store your name or profile picture from either provider. If you use a password, we store it only as a salted hash, never in plain text.
  • Your content: The data you create in TaskPocket: tasks, projects, areas, sections, checklist items, due dates, deadlines, repeat rules, notes, and the descriptions you add. This is necessary to provide the core functionality of the app. It is stored privately for your use and is never shared with third parties or used for advertising. TaskPocket does not currently support file uploads or attachments, so we hold no documents or images of yours.
  • Account preferences: Settings such as your timezone, the day your week starts on, when completed tasks move to Completed, your theme, and small display choices. We pick reasonable defaults and let you change them in Settings.
  • Billing metadata: If you upgrade to Premium — by subscription or a one-time lifetime purchase — we store the identifiers tied to your account so we can manage your plan: a Stripe customer ID for web purchases, or an identifier shared with RevenueCat for App Store purchases, together with your subscription status. We never see or store your card number; that lives with the payment processor.
  • Sessions and devices: To keep you signed in securely we store one record per session: a hashed token, a randomly generated device identifier, a device label, and the dates the session was created, last used, and expires or was revoked — the last-used date is what lets you tell which device is which when you review your sessions. On the web that label is a coarse platform name such as “Mac” or “iPhone”; on iOS it is the device name iOS reports, which may be one you chose yourself. The device identifier is generated on first launch and is not an advertising identifier. We do not store your IP address or your browser's user-agent string alongside your account. Like any service on the internet, our servers see your IP address in order to answer your request and to apply rate limits, but it is held only in memory and never written to your account record.
  • An analytics visitor identifier: If you signed up in a browser where our analytics script was running, we keep the random visitor identifier it generated, together with a short checklist of which one-off milestones have already been counted for your account (see “Analytics” below). The identifier is what lets a signup be joined to the visit it came from, and the checklist is what stops the same milestone being counted twice. Neither carries anything you wrote.
  • Connected apps: If you connect our browser extension, we store an access token for it — stored as a hash, never in full — along with its first few characters so you can tell one connection from another, a label such as “Web Clipper — Chrome”, and the date it was last used, so you can review and revoke it in Settings.
  • Sign-in records: When you request a sign-in link or code by email, we store the email address it was sent to and a hashed copy of the link and code, so we can verify them once and only once. These records are short-lived and are deleted automatically (see “Retention and deletion” below).
  • What you send us: If you use the in-app feedback form, or ask us to unlock a suspended account, we receive the message you wrote along with your name and email address so we can reply.
  • Account status: If a payment on your account is disputed or our payment processor flags it as fraudulent, we record that the account was suspended, when, and why, plus the date of any request you send us to review it. We use this only to protect the service and to handle your appeal.

We don't ask you for sensitive personal data — for example, health information, financial details, or precise location. If you choose to put any of that into a task, note, or project name, we treat it the same way as the rest of your content: privately, and only for your use.

How we use your data and why we're allowed to

Under EU and UK law we have to tell you the legal ground for each thing we do with your data. Here it is, in plain terms.

What we doWhy we're allowed to do it
Run your account and sync your tasks across devicesNecessary to perform our contract with you
Process your subscription or one-time purchaseNecessary to perform our contract with you
Keep the service secure (authentication, rate limiting, fraud and abuse prevention, error reporting)Our legitimate interest in operating a reliable service
Send you the welcome email, sign-in links, password resets, and respond to your support messagesNecessary to perform our contract with you
Email you before an annual subscription renews, to tell you the date and the amountLegal obligation, and necessary to perform our contract with you
Understand in aggregate how people find and start using TaskPocketYour consent, where we asked for it before storing anything on your device; otherwise our legitimate interest in improving the product
Comply with legal obligations (tax records, lawful requests)Legal obligation

We do not use the content of your tasks, projects, or notes for advertising, profiling, model training, or any third-party analytics. We send no marketing emails at all — no newsletters, no product announcements, no re-engagement nudges. The only emails you will ever get from us are the ones listed above: the welcome message, sign-in links and codes, password resets, our reply when you write to us, and — if you are on an annual subscription — a notice about a month before it renews telling you the date and the amount, which the law in some places requires and which we would send anyway.

One decision is made automatically, and you should know about it. If a payment on your account is disputed with your card issuer, or our payment processor's fraud systems flag one, our system suspends the account straight away — no one reviews it first. We act on that signal immediately because by the time a person could look, the money is usually gone.

What a suspension does is deliberately limited: Premium is revoked and you can't make changes, but you can still sign in, read everything, and export all of it. Your data is never held hostage over a payment dispute. And because an automated fraud signal is sometimes simply wrong, you can ask a human — us — to look again: use the appeal link shown in the app or email [email protected]. We read every appeal personally, you can tell us your side, and we restore access unless the evidence really does point to fraud.

We do not sell your data

Your personal data and your content are not sold to anyone. We do not share them with advertisers or data brokers. We share data only with the service providers that help us run the product:

  • DigitalOcean — hosts everything in their Canada region: our managed PostgreSQL database, the server running our API, and the static websites.
  • Stripe — processes subscription and one-time payments made on the web, and receives your email address to create your customer record.
  • RevenueCat — mediates App Store purchases in the iOS app and tells us when a purchase starts or ends, so we can grant or revoke Premium. It receives an account identifier, not your email.
  • MailTrap — delivers our transactional emails: the welcome email, sign-in links and codes, password resets, and the notice we send before an annual subscription renews.
  • Sentry — receives error reports and basic performance data from the web app and our API so we can diagnose problems. See “Diagnostics and error reporting” below for exactly what those reports contain.
  • PostHog — page-view analytics on our marketing site (taskpocket.io) only. It is not loaded inside the logged-in app.
  • DataFast — lightweight product analytics on the marketing site and inside the web app. It records page views and a short list of milestones, each counted once per account: that someone signed up, created their first task, completed their first task, created their first project, and anything to do with upgrading. We never send it your tasks, notes, or anything you create; only that an event happened. For visitors in the EEA, the UK or Switzerland it is not loaded unless they agree to it. See “Analytics” below for the full list.
  • Telegram — carries our internal operational alerts. Because TaskPocket is run by one person, these alerts arrive as messages in a private Telegram chat, and they may include your email address and any message you send us — for example when an account is created, when a subscription or payment changes, when a payment is flagged as fraudulent, and when you submit feedback or ask us to unlock an account. They never contain your tasks, and they never contain anything about your card — not the number, not the last four digits, not the brand or the country that issued it. That information stays with Stripe, where we can look it up if we genuinely need to. But if you quote a task in the message you write to us, that quote travels with it, so please leave out anything you'd rather we didn't see.
  • Google and Apple — only if you choose to sign in with them. They tell us your verified email address and an account identifier; we tell them nothing about what you do in TaskPocket.
  • Expo — delivers over-the-air updates to the iOS app, so it receives an update check from your device. It receives no account data.

Each of these providers handles your data under confidentiality and data-processing terms, only for the purpose described above, or when required by law.

Where your data lives

Your account and content are stored on managed DigitalOcean infrastructure in Canada. Connections between your device and our servers are always encrypted over HTTPS.

The iOS app also keeps a copy of your tasks in a local database on your device, so it works without a connection; changes sync back to our servers when you reconnect. Your sign-in token is held in the iOS Keychain. When you send something to TaskPocket from another app's share sheet, the app keeps a small handover file — your project list, and the item you shared — in a storage area shared between the app and its share extension on your own device; it never leaves the device except as the task you created. The web app keeps no copy of your tasks on your computer — it stores only your theme choice, your sign-in state, a device identifier, and, if you were asked the cookie question, your answer to it.

International transfers

If you're in the European Economic Area or the United Kingdom, your data is transferred to Canada when you use TaskPocket. The European Commission has recognised Canada as providing an adequate level of data protection for transfers to private-sector organisations covered by Canada's federal privacy law (PIPEDA), which we are, so no additional safeguard is required for that transfer.

Some of the providers listed above are based in the United States — Stripe, RevenueCat, Sentry, PostHog, DataFast, and Expo. They handle personal data from the EEA and the UK under the European Commission's Standard Contractual Clauses or, where applicable, the EU–US Data Privacy Framework.

Telegram, which carries our internal operational alerts, is based outside those arrangements and is not covered by an adequacy decision. We use it only to deliver a message to ourselves that is necessary to run your account or to answer something you asked us — which is the basis on which that transfer is made. If you'd rather your support message did not travel that way, email us directly at [email protected] instead of using the in-app form.

Analytics

To be upfront about the split: the iOS app carries no analytics and no crash reporting of our own — there is no measurement kit inside it, and it reports nothing about how you use it. One nuance we'd rather spell out than have you find: the one-off milestones described below are recorded by our server when the action reaches it, so if you happen to create your very first task on your phone, that first-time milestone is still counted — and only if you had already agreed to analytics in a browser, since that is the only place the identifier it needs comes from. Nothing about the task travels with it. The other thing that phones home is our payments provider RevenueCat, whose kit starts with the app and receives technical details of the device (model, operating system, app version, and region) along with purchase and paywall events, whether or not you ever buy anything. The marketing site and the web app use two privacy-respecting analytics tools, and neither one ever receives the content of your tasks, notes, projects, or anything else you create:

  • PostHog — page-view analytics on the marketing site (taskpocket.io) only; it is not loaded inside the logged-in app. It sees general information such as approximate location (country or region), device type, which page was viewed, and which things on that page were clicked. It does not record your screen: session replay is switched off in our code, not merely left unticked in a dashboard. There is nothing you create on the marketing site, so it never sees your content.
  • DataFast — product analytics on the marketing site and inside the web app. It records page views and a fixed, short list of named events. Almost all of them are counted once per account and never again: signing up (along with whether you used email, Google, Apple, or a sign-in link), creating your first task, completing your first task, and creating your first project. Your thousandth task sends nothing. The rest are about upgrading: reaching a limit on the free plan and which limit it was, being shown the upgrade screen, starting a checkout, and completing one — those last two include which plan you chose. That is the entire list.

Most of those events are now sent by our own server rather than by your browser, at the moment the action actually succeeds. What travels is the event name, a small label of the kind described above, and the random visitor identifier that ties it to a visit — never your email, your account, or anything you created.

If you're in the EEA, the UK, or Switzerland, DataFast doesn't run unless you said it could. Not in a reduced form and not without cookies — the script simply never loads, on the marketing site or in the app, and nothing about your visit reaches it. If you accepted, it behaves exactly as described above and no differently from anywhere else. You can change that answer at any time from the Cookies section below.

The content you create is never sent to any analytics provider, and we carry no advertising trackers or advertising pixels on any surface.

Cookies

We use no advertising cookies and run no ad network. Beyond the storage the app cannot work without — what keeps you signed in, what remembers your theme, and the identifier that lets you see and revoke your own sessions — the only things stored on your device are what our two analytics tools need to recognise a return visit: a pair of first-party cookies from DataFast, one for the visitor and one for the session, and a small amount of browser storage from PostHog holding its own identifier. They contain random identifiers and nothing else. Whether any of it is set depends on where you are.

In the EEA, the UK, and Switzerland, we ask first. You'll see a small panel with two buttons, and until you press one of them nothing is stored: DataFast isn't loaded at all, and PostHog runs in a mode that keeps what it needs in the page's memory and forgets it when you close the tab. Saying no is a button of the same size, sitting right next to yes. There's no close button, because dismissing a question isn't an answer to it.

If you say no, that's the end of DataFast — it never loads, and if it had already set its cookies we delete them. PostHog stays in the memory-only mode described above and keeps counting page views for as long as the tab is open, which is the one thing worth being precise about: your visit is still counted, we just can't tell it apart from anyone else's tomorrow. Nothing is left on your device, and nothing you create is ever involved. If you'd rather not be counted at all, a content blocker will do it, and we'll delete what's already there if you ask.

Your answer is remembered in a cookie of its own, shared across taskpocket.io and the app, so you're asked once rather than on every site we run. It's the one cookie set no matter what you choose — including when you choose no, because forgetting that would mean asking again forever. We keep it for about six months and then ask again. Your answer follows you rather than your timezone: a no given in Europe is still a no from a laptop set to New York time.

Everywhere else, the two analytics cookies are set without asking, which is what the law in those places allows.

We work out which of those applies from your browser's own timezone, read on your device. We don't look your location up with a third party, because sending your address to somebody else in order to decide whether we may set a cookie would rather defeat the point. It errs on the cautious side: anywhere in Europe, or a timezone we can't read, gets asked.

If you'd like us to delete what has already been collected about your visits, email [email protected] and we'll do it. A private window, a content blocker, or a browser that blocks trackers by default also works — though note that both cookies are first-party, so a third-party cookie setting alone won't stop them.

This applies to the marketing site and to the logged-in web app. PostHog runs on the marketing site only; DataFast runs on both — and in the app it reads the answer you already gave, rather than asking again. If you've never visited taskpocket.io and went straight to the app, no answer exists, so nothing loads. The iOS app sets no cookies at all.

Diagnostics and error reporting

When something breaks, we use Sentry to find out why. It receives technical information: the error message and stack trace, the screen or API endpoint involved, a correlation identifier, and the internal identifier of your account — a random one we generated, not your email — so that an error in your browser and the request that caused it on our server can be matched up. When an error happens in the web app, Sentry may also record a short replay of the moments leading up to it — that replay is captured with all text masked and all media blocked, so it shows the shape of the screen but not the words of your tasks or notes.

Our server sends its application logs to Sentry too. Those logs are technical, but a small number of billing-related events include the email address of the account involved so we can trace a payment problem to the right person. No task content is ever logged. The iOS app sends nothing to Sentry.

One caveat we'd rather state than leave you to discover: an error report is delivered over the internet like any other request, so Sentry can see the address it arrived from. We have asked them not to keep it, and it never reaches our own records — but it passes through their systems on the way, and saying otherwise would be a technicality dressed up as a promise.

Retention and deletion

We retain your account and your content for as long as your account is active. When you delete your account from Settings › Account › Danger zone, every task, project, area, section, checklist, session, connected app, and account record is removed from our database immediately — it is a real deletion, not a hidden flag — and we ask Stripe to delete your customer record too. Two things outlive that click by a little: a recent sign-in link or code, which is filed under your email address rather than your account and is swept away within 24 hours; and, if you subscribed through the App Store, your record at RevenueCat, which we'll delete on request. Your data may still exist briefly in recent backups, but it is overwritten as newer backups are created and old ones rotate out within 30 days.

Some records are cleaned up automatically on their own schedule even while your account is open: sign-in links and codes are deleted within 24 hours of being used or expiring, expired sessions within 7 days and revoked ones within 30 days, and the bookkeeping records that make sync work within 30 to 90 days.

You own your data. Before deleting — or any time — you can export everything as a JSON file straight from Settings › Account › Your data, on every plan, with no request or support ticket needed.

Security

We use industry-standard measures to protect your data in transit and at rest. Connections are encrypted over HTTPS, passwords are stored as bcrypt hashes, and session tokens, sign-in links, and API tokens are stored only as hashes — so even we cannot read them back. Sign-in endpoints are rate-limited to slow down guessing. No system is perfect; if we ever become aware of a breach that affects you, we'll let you know as the law requires.

App Store privacy label

The disclosures below mirror the privacy nutrition label on our App Store listing. Apple sorts data into three buckets, and we want the website policy and the App Store label to say the same thing.

Data not used to track you

We do not collect any data used to track you across other apps or websites. No advertising SDKs, no third-party trackers, no fingerprinting. The corresponding category on our App Store label is empty.

Data linked to your identity

  • Contact info: your email address, used for sign-in and account communication.
  • Purchases: your plan status (Free or Premium). The card details themselves live with Apple or Stripe; we never see them.
  • Identifiers: an account identifier we generate so we can attach your tasks to your account, and a per-install device identifier used to manage your sign-in sessions.
  • User content: the tasks, projects, areas, sections, and checklists you create, plus any message you send us through the feedback form.

Data not linked to your identity

The iOS app contains no analytics kit and no diagnostics of our own; it measures nothing locally and sends no usage reports. Our payments provider RevenueCat does receive an identifier and basic device information from the app — before you sign in, that identifier is anonymous and is not tied to you.

Browser extension

Our browser extension only reads a page when you click it, and it reads only three things: the page address, its title, and any text you had selected. The title and the selected text are put in front of you in a form, so what actually gets sent is what you decided to send: the task title (prefilled from the page title, yours to edit), the page address, an optional note (prefilled from your selection), and the list or project you picked as the destination. That goes to TaskPocket's own API to create the task and nowhere else. It contains no analytics and no error reporting, and it can only reach our own domain. Your access token is kept in the extension's own protected storage, never in the pages you visit, and you can revoke it from Settings at any time.

Children's privacy

TaskPocket is not directed at children. We don't knowingly collect personal data from anyone under 13. If you're a parent and believe your child has created an account, contact us at [email protected] and we'll delete it.

Your rights

Depending on where you live, you have rights over the personal data we hold about you, including the right to access it, correct it, delete it, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent where we relied on consent. You can do most of these directly from Settings (export your data; delete your account). For anything you can't do yourself, email us at [email protected] and we'll respond within 30 days, or sooner if we can. For unusually complex requests we may extend that period as the law allows, and we'll tell you why. We may also need to verify it's really you before acting on the request.

If you're in the European Economic Area, the United Kingdom, or Switzerland and you believe we're not handling your data properly, you have the right to lodge a complaint with your local data protection authority. We'd appreciate the chance to address your concern first.

California residents

California law requires that we tell you, in plain terms, the categories of personal information we collect about you (described in “What we collect” above), the purposes we use it for (in “How we use your data”), and who we share it with (in “We do not sell your data”). We do not sell or share your personal information for cross-context behavioural advertising, and we have not done so in the previous twelve months. California residents have the same rights of access, deletion, correction, and non-discrimination as described in “Your rights” above.

If the business changes hands

If TaskPocket is sold, merged, or otherwise transferred to a new owner, your data may transfer with it. We'll tell you before that happens and you'll have a chance to delete your account first.

Changes to this policy

We may update this privacy policy from time to time. The updated version goes on this page and the “Last updated” date at the top changes. If changes are significant, we'll notify you by email or in the product.

Contact

Questions about this privacy policy or your data? Email [email protected]. You can also read our Terms of Service.

← Back to TaskPocket