Privacy Policy

Effective Date: December 29, 2024 · Last Updated: August 19, 2026 · Version 1.2.1

1. Data Controller

Your data is controlled by:


Email: support@tactido.com

This Privacy Policy describes how we collect, use, and protect your data when you use the Tactido app.


2. What Data We Collect

2.1. Data Stored LOCALLY on Your Device

Tactido is an offline-first application. Core activities, notes, photos and settings stay on your device. Data is sent to a provider only when it is needed to operate a subscription, an account or cloud feature that you choose, or a diagnostic service that you enable.

Data Purpose Storage
Activities and time history Tracking time spent on various tasks Local, encrypted
App settings Personalization (theme, language, notifications) Local, encrypted
Subscription status Verifying access to premium features Local, encrypted
Backups Data recovery when you create or restore a backup Local, encrypted; a selected cloud provider is used only when you enable its backup feature
Calendar event cache Integration with device calendar Local

Encryption: Your data is protected with AES-256 encryption (GCM and CBC), with keys stored in iOS Keychain or Android Keystore.

2.2. Account and Subscription Data

You can use the core app without signing up. When the account feature is available, Tactido may create a technical anonymous identifier for a session and subscription mapping. You may also choose to sign in with Apple, with Google, or with an email address and password. This is not a public profile.

Service Data Purpose Your Control
Firebase Authentication Technical user ID; authentication provider; and, if returned by the provider, account name or email address (including an Apple Private Relay address). If you set a password for your account, it is held only by Firebase Authentication as a salted hash — Tactido does not store it. Sign-in, account linking, security and account deletion Use the in-app account controls or the account deletion page
Adapty Pseudonymous customer ID, entitlement status, subscription and purchase metadata Subscription access, paywalls and restoring purchases Manage or cancel a subscription through Apple or Google; see the store's controls
Apple App Store / Google Play Purchase and subscription information handled by the relevant store Payment processing and subscription management Managed under the store's account and privacy controls

2.3. Diagnostics and App Configuration

To improve app quality, we use the following external services:

Service Data Purpose Your Control
Firebase Analytics Anonymous events, device ID App usage analysis Can be disabled in settings
Firebase Crashlytics Error reports, stack traces Bug fixing Can be disabled in settings
Firebase Performance Performance metrics App optimization Can be disabled in settings
Firebase Remote Config App version, technical configuration request and feature-flag response Configure and safely roll out app features Required for the configuration request; it does not create a marketing profile
Sentry Error reports, stack traces Bug tracking and fixing Can be disabled in settings
NTP Servers Time query Clock synchronization Automatic

Diagnostics and identity are separate: analytics and diagnostics use the controls described above. Authentication data is processed only for the account feature; it is not used to sell ads or build an advertising profile.

Your choice: Analytics, crash reporting, and performance monitoring are off by default. On first launch the app asks for your consent, and nothing is collected unless you agree. You can change your choice anytime in Settings → Privacy.

2.4. Optional Services (Only With Your Consent)

The following services are entirely optional and only activated when you explicitly enable them:

Service Data Purpose Your Control
Google Calendar API Activity names and times Sync activities to your Google Calendar Optional - requires OAuth consent
Apple EventKit Activity names and times Sync activities to your iOS Calendar Optional - requires calendar permission
Apple Speech Recognition Voice data (processed by Apple) Voice input for adding activities Optional - requires microphone permission
Google Speech Services Voice data (processed by Google) Voice input for adding activities Optional - requires microphone permission

Important: Calendar sync and voice input are disabled by default. The app works fully without them. If you enable these features, your activity names may be transmitted to Google or Apple.


3. What We Do NOT Collect

Tactido does NOT collect the following data:


4. App Permissions

Tactido may request the following permissions:

Permission Purpose Required?
Calendar Sync activities with device calendar (read/write if sync enabled) Optional
Notifications Activity reminders Optional
Microphone Speech-to-text (for creating notes) Optional
Camera Adding photos to activities Optional
Photo Library Selecting photos as attachments Optional
Reminders (iOS) Reading and creating reminders when calendar sync is enabled Optional
Display over other apps (Android) Floating timer widget shown on top of other apps Optional
Alarms and full-screen alerts Departure and activity alarms at the exact time you set Optional

All permissions are optional - the app works without them, but some features will be unavailable.


5. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

5.1. Right of Access

You can check what data the app stores at any time:

5.2. Right to Erasure ("Right to be Forgotten")

You can request deletion of the data associated with your account and remove local data:

5.3. Right to Data Portability

You can export your data in JSON format:

5.4. Right to Object

You can disable analytics data collection:

5.5. Right to Restriction of Processing

The app works offline - you can use it without an internet connection, which automatically limits data processing.


6. Children's Privacy

6.1. User Age

Tactido is intended for users of all ages. However:

6.2. Parental Consent

If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us: support@tactido.com

6.3. Deleting Children's Data

Upon parental request, we will delete any data associated with the child's account.


7. Data Security

We implement the following security measures:

Measure Description
AES-256 Encryption (GCM + CBC) All local data is encrypted
iOS Keychain / Android Keystore Encryption keys in secure system storage
HMAC-SHA256 Data integrity verification
Service separation Core activity data remains on-device unless you use an optional cloud, calendar, account or support feature that needs a provider

8. Data Retention Period

Data Retention Period
Local data (activities, settings) Until deleted by user
Firebase Analytics 45 days (Google policy)
Firebase Crashlytics 30 days (Google policy)
Backups Until deleted by you, through the selected backup provider, or as part of an accepted deletion request
Account and subscription identifiers For as long as needed to provide the account or subscription feature; deleted or minimized after an accepted deletion request, subject to legal, security or accounting obligations
Support requests For as long as needed to resolve the request and meet any applicable legal obligations

9. Third-Party Services

We use services from the following providers:

9.1. Google Firebase

9.2. Adapty

9.3. Sentry (Functional Software, Inc.)

9.4. Apple App Store / Google Play Store

9.5. Calendar Services (Optional)

If you enable calendar synchronization:

9.6. Speech Recognition Services (Optional)

If you use voice input:


10. International Data Transfers

Data transmitted to Firebase may be processed on Google servers located outside the European Economic Area (EEA). Google ensures an adequate level of data protection in accordance with Standard Contractual Clauses (SCCs).


11. Changes to This Privacy Policy

We will notify you of significant changes to this Privacy Policy through:

We recommend periodically reviewing this page.


12. Contact Us

For privacy-related questions, please contact us:

Email: support@tactido.com

We respond to inquiries within 30 business days.


13. Legal Basis for Processing

Processing Purpose Legal Basis (GDPR)
Service provision (time tracking) Art. 6(1)(b) - contract performance
Analytics and app improvement Art. 6(1)(a) - consent
Error reporting Art. 6(1)(a) - consent
Subscription handling Art. 6(1)(b) - contract performance
Account security and deletion requests Art. 6(1)(b) - contract performance, or Art. 6(1)(c) where a legal obligation applies

Tactido - Your time, your control.

© 2024-2026 . All rights reserved.