Legal

Privacy policy

Tickbase collects as little as possible, sells nothing, and lets you export or delete everything. Here's exactly what that means.

Last updated: · Applies to the Tickbase apps and tickbase.app

The short version

  • If you use Tickbase without an account, your tasks stay on your device and we receive nothing.
  • If you use Premium, we store your name, email address and your tasks so that they can sync and be backed up. Your tasks are encrypted on your device before upload; our database holds only ciphertext (see Encryption).
  • Payments are handled by Stripe, Apple or Google. They never see your tasks; we never see your card number.
  • No third-party analytics, no advertising, no selling or sharing data for marketing.
  • Export your data as JSON any time. Delete your account, and everything on our servers, in one tap.

1. Who we are

Tickbase is an independently built to-do app, designed and operated in the United Kingdom by Caesoose Studios, [Legal entity name and registered address — placeholder] (“Tickbase”, “we”, “us”). We are subject to the UK GDPR and the Data Protection Act 2018, and you can complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with how we handle your data. We are the data controller for the personal data described in this policy. You can reach us at hello@tickbase.app.

2. What we collect

Using Tickbase without an account (Free)

Nothing. The free app stores your tasks, lists, tags, notes and settings locally on your device. No account is created and no data is sent to us. If you use the web app at app.tickbase.app without signing in, your data lives in your browser's storage.

Using Tickbase Premium

DataWhere it comes fromWhy
Email address and nameYour Google or Apple sign-in. (Apple lets you hide your email; we support that.)To create and identify your account and to contact you about it.
Your tasks, lists, tags, notes, completion history and settingsEntered by you in the app. Encrypted on your device before upload; we store ciphertext plus the ids and timestamps needed for sync (see Encryption).To sync them between your devices and keep a backup.
Subscription status, the date your first paid year started (“Premium since”) and whether that date fell within the founding period (Founder)Stripe, Apple or Google.To know whether Premium is active on your account and to show your Premium-since and Founder badges.
Basic technical logs (IP address, device type, timestamps, error details)Generated automatically when the app talks to our servers.To keep the service running securely and to diagnose faults. Tickbase for a short period only (see Retention).

We do not collect your contacts, location, calendar, photos or anything else from your device. Reminders are notifications scheduled on your device (on iOS and Android; browser notifications on web and desktop while the app is open); they do not pass through our servers.

3. How we use it

  • To provide Premium: storing your tasks and delivering them to the devices signed in to your account.
  • To run your account: sign-in, subscription status, trial reminders, and replying when you email us.
  • To keep the service secure and working: rate limiting, abuse prevention, and fixing faults.
  • To meet legal obligations, such as tax records for payments.

We do not use your tasks to train or feed any machine-learning or AI model, ours or anyone else's, and we do not read them. Synced data is encrypted on your device before upload; the only way we would ever see it in plain form is if you ask us to recover your account and have left support recovery on (see Encryption). Our legal bases under GDPR are performance of a contract (providing the service you signed up for), our legitimate interests in keeping the service secure, and compliance with legal obligations.

4. Where it's stored

Synced data is stored on Cloudflare's infrastructure. It is encrypted in transit (TLS), and your tasks are encrypted on your device before they are sent, so what is stored is ciphertext (see Encryption). Access to production systems is limited to the people who operate Tickbase and is protected by multi-factor authentication. Cloudflare's data centres are located worldwide; where data is transferred outside the UK or EEA, it is covered by Cloudflare's standard contractual clauses and equivalent safeguards.

Nothing is perfectly secure. If we ever become aware of a breach affecting your data we will tell you and the relevant regulator without undue delay, as the law requires.

5. Encryption

Every synced item (tasks, lists, tags, habits, habit logs, countdowns and focus sessions) is encrypted on your device with AES-256-GCM under a random key that belongs to your account, before it is uploaded. Our database holds only the ciphertext, together with each item's random id, last-updated time and a deleted flag, which sync needs in order to merge changes. A copy of the database on its own reveals nothing about your tasks.

Standard mode (default)

Your account key is stored sealed, two ways: encrypted with a secret that is kept outside the database, and separately to an offline recovery key held by the founder. Signing in on a new device unlocks the key; you have no passphrase to remember. We don't read your data and the database on its own can't reveal it. To be precise: someone with the database and that separate secret, or the founder's offline key, could read it. That is the trade-off for a passphrase-free account, and it is what allows us to give your data back if you ask for help.

Strict mode (optional)

In Settings → Encryption you can set a passphrase. Your key is then re-sealed with the passphrase and a one-time recovery code, and the server deletes its own copy of the seal. From that point the service cannot read your account and every new device must enter the passphrase or recovery code. A separate setting, Allow support recovery, controls whether the offline recovery key is kept: on, the founder can restore access at your request; off, nobody but you can open the account, and losing both the passphrase and the recovery code means the data is unrecoverable. The app tells you this before you turn it off.

What the service can still see

Encryption covers the content of your items. In either mode we still know:

Profile pictures are the one exception to encryption: a picture you upload in Settings is stored as an ordinary image so that your other devices can display it. It is served from an unguessable URL tied to your account, is never shown to other users (Tickbase has no social features), and is deleted with your account or whenever you remove it in Settings.

  • your email address and name, from your Google or Apple sign-in;
  • your subscription status (a Stripe customer reference, or App Store / Google Play status);
  • when you sync and how much data is transferred;
  • how many encrypted rows of each kind (tasks, lists, tags, and so on) your account holds;
  • each item's random id, last-updated time and deleted flag, which carry no content or dates.

On your devices

So that Tickbase opens instantly and works offline, each signed-in device keeps your account key and a plain local copy of your data, protected by the device's own security (the system keychain or secure storage on iOS and Android; browser storage on the web and desktop). In Strict mode, “Lock this device” forgets the key. Encrypting the local copy at rest is on the roadmap.

6. Who we share it with

We share personal data only with the processors needed to run the service, and only what each one needs:

  • Cloudflare — hosting, storage and delivery of the service.
  • Stripe — payments on the web. Stripe receives your email and payment details; we receive a confirmation and a customer reference. Stripe never sees your tasks and we never see your card number.
  • Apple and Google — sign-in, and payments made through the App Store or Google Play. They see what they need to process the sign-in or purchase and nothing about your tasks.
  • An email provider — to send account emails such as sign-in links or receipts. [Name the provider before launch — placeholder.]

We do not sell personal data. We do not share it with advertisers, data brokers or analytics companies. We will disclose data if legally compelled to, and will tell you unless the law prevents it.

7. Analytics and tracking

There are no third-party analytics, advertising SDKs, tracking pixels or social-media embeds in the apps or on this website. The only cookies or local storage we use are strictly necessary: your sign-in session, and your theme preference. Because we don't use cookies for anything else, there is no cookie banner.

Our hosting provider records standard server logs (see section 2), which we use only for security and fault-finding.

8. Retention

  • Account and task data: kept while your account exists. When you delete your account, it is removed from live systems immediately and from backups within 30 days.
  • Server logs: 30 days.
  • Payment records: as long as tax and accounting law requires (typically 6–7 years), held by Stripe and in our accounting records; these contain the transaction, not your tasks.

9. Your rights

Wherever you live, you can do the following directly in the app, without asking us:

  • Export everything as a JSON file: Settings → Export.
  • Delete your account and all data on our servers: Settings → Account → Delete account. One tap, with one confirmation.
  • Correct your name in Settings; your email comes from your Google or Apple sign-in.

If you are in the UK, EU or EEA, you also have rights under the UK GDPR and EU GDPR to access, rectify, erase, restrict and port your data, to object to processing based on legitimate interests, and to complain to a supervisory authority (in the UK, the Information Commissioner's Office; in the EU, your national data-protection authority). Residents of other places, including California, may have similar rights under local law. To exercise any right not covered by the in-app controls, email hello@tickbase.app; we respond within 30 days and never charge for it.

10. Children

Tickbase Premium accounts are for people aged 16 and over (or the age of digital consent where you live, if higher). The free app collects nothing and can be used by anyone. If you believe a child has created an account, contact us and we will delete it.

11. Changes to this policy

If we change this policy in a way that matters, we'll email account holders and show a notice in the app before the change takes effect. The “last updated” date at the top always tells you the current version. Previous versions are available on request.

12. Contact

Questions, requests or complaints: hello@tickbase.app. Postal address: [Address — placeholder].