1. Introduction
TodoTicked is a productivity product of Phoenix Digital, LLC ("TodoTicked," "we," "us," or "our"). This Privacy Policy applies to our websites (including todoticked.com and app.todoticked.com), web and desktop applications, mobile applications, APIs, and related services (collectively, the "Services").
By using the Services, you acknowledge the practices described in this Policy. If you do not agree, do not use the Services. For contractual terms governing use of the Services, see our Terms of Service.
When you use TodoTicked in a personal capacity, we act as the data controller for the personal information described here. When you use TodoTicked as a member of an organization that is our customer (for example, a team workspace administered by your employer), that organization may be the controller for workspace content, and you should also review that organization’s policies.
2. Information We Collect
2.1 Information you provide
- Account information: name, email address, password (stored as a secure hash by our authentication provider), profile photo, and account preferences.
- User content: tasks, projects, notes, journal entries, tags, filters, comments, attachments, and other content you create or upload.
- Communications: messages you send to support, feedback, and survey responses.
- Marketing subscriptions: your email address, consent date, and the page where you joined our mailing list. You can unsubscribe at any time.
- Billing information: subscription plan, billing status, and related transaction metadata. Card numbers are collected and stored by our payment processors (such as Stripe or Apple), not by TodoTicked.
2.2 Information collected automatically
- Usage data: features used, actions taken, approximate session timing, and performance metrics.
- Device and log data: IP address, browser type, operating system, device type, language, referrer, and diagnostic or error logs.
- Cookies and similar technologies: used for authentication, preferences, security, and analytics as described in Section 14.
2.3 Information from third-party sign-in
If you sign in with Google or Apple, we receive basic account identifiers permitted by those providers—typically your name and email address (or Apple’s private relay email)—to create and authenticate your TodoTicked account. See Sections 4 and 5.
2.4 Information from integrations
If you connect third-party integrations (for example Slack or other OAuth-connected services), we receive the data those services authorize for the scopes you approve, such as account identifiers needed to deliver notifications or sync.
3. How We Use Your Information
We use personal information to:
- Provide, operate, maintain, and improve the Services
- Create and authenticate accounts, including Google and Apple sign-in
- Sync your data across devices and collaborate with teammates you invite
- Process subscriptions, payments, renewals, cancellations, and invoices
- Send transactional messages (security alerts, billing notices, product updates)
- Send marketing email when you have expressly joined our mailing list
- Provide customer support and respond to requests
- Monitor reliability, prevent abuse, and protect the security of the Services
- Analyze aggregated or de-identified usage to improve product quality
- Comply with law and enforce our Terms of Service
We do not sell your personal information. We do not use Google user data obtained through Google Sign-In or Google APIs to serve ads.
4. Google Sign-In and Sign in with Apple
TodoTicked offers optional sign-in with Google and Apple in addition to email and password.
- Data received: typically your name and email address (or Apple Hide My Email relay address) and a stable provider user identifier.
- Purpose: account creation, authentication, and account recovery only.
- Storage: we store the identifiers needed to link your provider account to your TodoTicked account.
- Control: you can disconnect third-party sign-in where supported, or delete your TodoTicked account at any time from Settings → Security.
- Apple account deletion: if you delete your TodoTicked account, we delete associated account data from our systems as described in Section 10. Users who signed in with Apple should also manage Apple ID app permissions in their Apple ID settings.
5. Google API Services User Data Policy
TodoTicked’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you authenticate with Google for sign-in, we access only basic profile information needed to create and authenticate your account (such as name and email). We do not use Google user data for advertising, and we do not sell Google user data.
6. Subscriptions and Payments
Paid plans may be purchased through Stripe (web and some platforms) or through Apple’s In-App Purchase / App Store billing (iOS and other Apple platforms where offered).
- Stripe: payment card details are entered on Stripe’s hosted checkout or portal. TodoTicked stores Stripe customer and subscription identifiers, not full card numbers.
- Apple App Store: Apple processes payment. We receive purchase and subscription status information needed to unlock entitlements. Manage or cancel Apple subscriptions in your Apple ID subscription settings: apps.apple.com/account/subscriptions.
Billing practices, renewals, and cancellations are further described in our Terms of Service.
7. Third-Party Services
We use trusted processors to operate the Services. Categories and examples include:
| Category | Examples | Purpose |
|---|---|---|
| Infrastructure & auth | Managed infrastructure | Database, authentication, storage, realtime sync |
| Hosting / CDN | Cloudflare | Serve websites and apps over HTTPS |
| Payments | Stripe and Apple | Checkout, subscriptions, invoices |
| Sign-in | Google, Apple | Optional OAuth authentication |
| Analytics & product | PostHog | Product analytics |
| Error monitoring | Sentry, LogRocket (production) | Diagnostics and session replay for reliability |
| Email delivery | Resend | Transactional email and mailing-list communications |
| AI features (optional) | OpenAI (via our servers) | AI assistant features you choose to use |
These providers process data on our behalf under contractual obligations. We require that third parties with whom we share user data provide protection consistent with this Policy and applicable law.
9. Security and Encryption
We implement technical and organizational measures designed to protect personal information, including HTTPS/TLS in transit, row-level security in our database, optional two-factor authentication, and optional client-side encryption for certain note content. Details are described on our Security page.
No method of transmission or storage is completely secure. If you enable optional end-to-end encryption for notes, encryption keys are derived on your device; we store ciphertext for that content and cannot recover plaintext if you lose your passphrase and recovery materials.
10. Data Retention and Deletion
- We retain account and content data while your account is active and as needed to provide the Services.
- Soft-deleted items (for example tasks, notes, or journal entries moved to the recycle bin) are typically purged after about 30 days.
- You may export a copy of your data and permanently delete your account from Settings → Security in the app, or by contacting privacy@todoticked.com.
- When account deletion succeeds, we remove associated content from our primary systems. Residual copies may remain briefly in encrypted backups maintained by infrastructure providers until those backups rotate.
- We may retain limited records as required by law (for example billing records) or for fraud prevention and dispute resolution.
11. Your Privacy Rights
11.1 Access, correction, export, and deletion
Depending on your location, you may have the right to:
- Access and receive a copy of personal information
- Correct inaccurate information
- Delete personal information
- Export data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
In-product controls: Settings → Security for export and account deletion; Privacy Choices for California opt-out information.
11.2 California (CCPA/CPRA)
California residents have rights to know, delete, correct, and opt out of sale/sharing, and to non-discrimination for exercising those rights. We do not sell personal information. To exercise rights, use in-app settings or email privacy@todoticked.com. We will verify requests and respond within the timeframes required by law.
11.3 EEA/UK (GDPR)
If you are in the EEA or UK, you may have additional rights under the GDPR/UK GDPR, including data portability and the right to lodge a complaint with a supervisory authority. Our legal bases include contract performance, legitimate interests (security, product improvement), consent where required, and legal obligation.
12. Children’s Privacy
The Services are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
13. International Data Transfers
We are based in the United States. Personal information may be processed in the United States and other countries where we or our processors operate. Those countries may have different data protection laws than your country of residence. Where required, we use appropriate safeguards for cross-border transfers.
15. Browser, Safari, Mail, and Share Extensions
TodoTicked extensions act only when you explicitly choose to save something. Depending on what you select, an extension may process the page title and URL, selected text, or the email or shared-item context needed to create your task.
Authentication tokens are stored using secure storage provided by your browser or operating system. If a task cannot be sent immediately, it may be held in an encrypted or platform-protected local retry queue limited to 100 items and seven days.
We may collect content-free lifecycle events such as a successful capture, retry, or error category to operate and improve the extensions. Those events do not include page content, selected text, email content, task titles, or task notes.
TodoTicked does not sell extension data, create advertising profiles, collect browsing history, or use extension data for advertising. Disconnecting an extension revokes its authorization and removes its locally stored credentials.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated Policy on this page and revise the "Last updated" date. Material changes may also be communicated by email or in-product notice. Continued use of the Services after an update becomes effective constitutes acceptance of the revised Policy.
17. Contact Us
Questions about this Privacy Policy or our privacy practices:
Phoenix Digital, LLC
TodoTicked
Privacy: privacy@todoticked.com
Support: support@todoticked.com