Privacy Policy
1. Data Controller
Your data is controlled by:
Email: support@tactido.com
This Privacy Policy describes how we collect, use, and protect your data when you use the Tactido app.
2. What Data We Collect
2.1. Data Stored LOCALLY on Your Device
Tactido is an offline-first application. Core activities, notes, photos and settings stay on your device. Data is sent to a provider only when it is needed to operate a subscription, an account or cloud feature that you choose, or a diagnostic service that you enable.
| Data | Purpose | Storage |
|---|---|---|
| Activities and time history | Tracking time spent on various tasks | Local, encrypted |
| App settings | Personalization (theme, language, notifications) | Local, encrypted |
| Subscription status | Verifying access to premium features | Local, encrypted |
| Backups | Data recovery when you create or restore a backup | Local, encrypted; a selected cloud provider is used only when you enable its backup feature |
| Calendar event cache | Integration with device calendar | Local |
Encryption: Your data is protected with AES-256 encryption (GCM and CBC), with keys stored in iOS Keychain or Android Keystore.
2.2. Account and Subscription Data
You can use the core app without signing up. When the account feature is available, Tactido may create a technical anonymous identifier for a session and subscription mapping. You may also choose to sign in with Apple, with Google, or with an email address and password. This is not a public profile.
| Service | Data | Purpose | Your Control |
|---|---|---|---|
| Firebase Authentication | Technical user ID; authentication provider; and, if returned by the provider, account name or email address (including an Apple Private Relay address). If you set a password for your account, it is held only by Firebase Authentication as a salted hash — Tactido does not store it. | Sign-in, account linking, security and account deletion | Use the in-app account controls or the account deletion page |
| Adapty | Pseudonymous customer ID, entitlement status, subscription and purchase metadata | Subscription access, paywalls and restoring purchases | Manage or cancel a subscription through Apple or Google; see the store's controls |
| Apple App Store / Google Play | Purchase and subscription information handled by the relevant store | Payment processing and subscription management | Managed under the store's account and privacy controls |
2.3. Diagnostics and App Configuration
To improve app quality, we use the following external services:
| Service | Data | Purpose | Your Control |
|---|---|---|---|
| Firebase Analytics | Anonymous events, device ID | App usage analysis | Can be disabled in settings |
| Firebase Crashlytics | Error reports, stack traces | Bug fixing | Can be disabled in settings |
| Firebase Performance | Performance metrics | App optimization | Can be disabled in settings |
| Firebase Remote Config | App version, technical configuration request and feature-flag response | Configure and safely roll out app features | Required for the configuration request; it does not create a marketing profile |
| Sentry | Error reports, stack traces | Bug tracking and fixing | Can be disabled in settings |
| NTP Servers | Time query | Clock synchronization | Automatic |
Diagnostics and identity are separate: analytics and diagnostics use the controls described above. Authentication data is processed only for the account feature; it is not used to sell ads or build an advertising profile.
Your choice: Analytics, crash reporting, and performance monitoring are off by default. On first launch the app asks for your consent, and nothing is collected unless you agree. You can change your choice anytime in Settings → Privacy.
2.4. Optional Services (Only With Your Consent)
The following services are entirely optional and only activated when you explicitly enable them:
| Service | Data | Purpose | Your Control |
|---|---|---|---|
| Google Calendar API | Activity names and times | Sync activities to your Google Calendar | Optional - requires OAuth consent |
| Apple EventKit | Activity names and times | Sync activities to your iOS Calendar | Optional - requires calendar permission |
| Apple Speech Recognition | Voice data (processed by Apple) | Voice input for adding activities | Optional - requires microphone permission |
| Google Speech Services | Voice data (processed by Google) | Voice input for adding activities | Optional - requires microphone permission |
Important: Calendar sync and voice input are disabled by default. The app works fully without them. If you enable these features, your activity names may be transmitted to Google or Apple.
3. What We Do NOT Collect
Tactido does NOT collect the following data:
- Payment card or bank-account details
- Phone number
- GPS location
- Browsing history
- Contact list
- Photo content (no image analysis)
- Advertising identifier
- Advertising profiles or the sale of personal data
4. App Permissions
Tactido may request the following permissions:
| Permission | Purpose | Required? |
|---|---|---|
| Calendar | Sync activities with device calendar (read/write if sync enabled) | Optional |
| Notifications | Activity reminders | Optional |
| Microphone | Speech-to-text (for creating notes) | Optional |
| Camera | Adding photos to activities | Optional |
| Photo Library | Selecting photos as attachments | Optional |
| Reminders (iOS) | Reading and creating reminders when calendar sync is enabled | Optional |
| Display over other apps (Android) | Floating timer widget shown on top of other apps | Optional |
| Alarms and full-screen alerts | Departure and activity alarms at the exact time you set | Optional |
All permissions are optional - the app works without them, but some features will be unavailable.
5. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
5.1. Right of Access
You can check what data the app stores at any time:
- Settings → Backup & Restore → Manage - create a backup and share it as a .json file with all your data
5.2. Right to Erasure ("Right to be Forgotten")
You can request deletion of the data associated with your account and remove local data:
- Delete individual activities - in the app
- Delete account - in the app's Account settings when the account feature is available
- Delete all local data - in the app or by removing the app from your device
- Delete backups - through the selected backup provider or as part of an account-deletion request
- Can't access the app? Use our public account-deletion page
5.3. Right to Data Portability
You can export your data in JSON format:
- Settings → Backup & Restore → Manage - create a backup and share it as a .json file
5.4. Right to Object
You can disable analytics data collection:
- Settings → Privacy → Analytics (disable)
- Settings → Privacy → Error Reporting (disable)
5.5. Right to Restriction of Processing
The app works offline - you can use it without an internet connection, which automatically limits data processing.
6. Children's Privacy
6.1. User Age
Tactido is intended for users of all ages. However:
- If you are under 16, you need the consent of a parent or legal guardian to use the app. This reflects the digital-consent age under the GDPR and Polish law.
- We do not knowingly collect personal data from children without parental consent.
6.2. Parental Consent
If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us: support@tactido.com
6.3. Deleting Children's Data
Upon parental request, we will delete any data associated with the child's account.
7. Data Security
We implement the following security measures:
| Measure | Description |
|---|---|
| AES-256 Encryption (GCM + CBC) | All local data is encrypted |
| iOS Keychain / Android Keystore | Encryption keys in secure system storage |
| HMAC-SHA256 | Data integrity verification |
| Service separation | Core activity data remains on-device unless you use an optional cloud, calendar, account or support feature that needs a provider |
8. Data Retention Period
| Data | Retention Period |
|---|---|
| Local data (activities, settings) | Until deleted by user |
| Firebase Analytics | 45 days (Google policy) |
| Firebase Crashlytics | 30 days (Google policy) |
| Backups | Until deleted by you, through the selected backup provider, or as part of an accepted deletion request |
| Account and subscription identifiers | For as long as needed to provide the account or subscription feature; deleted or minimized after an accepted deletion request, subject to legal, security or accounting obligations |
| Support requests | For as long as needed to resolve the request and meet any applicable legal obligations |
9. Third-Party Services
We use services from the following providers:
9.1. Google Firebase
- Purpose: Authentication, analytics, crash reporting, performance monitoring and Remote Config
- Privacy Policy: firebase.google.com/support/privacy
9.2. Adapty
- Purpose: Subscription access, entitlement status, paywalls and purchase restoration
- Data: Pseudonymous customer ID and subscription/purchase metadata
- Privacy Policy: adapty.io/privacy
9.3. Sentry (Functional Software, Inc.)
- Purpose: Error tracking, crash reporting, performance monitoring
- Data collected: Anonymous error data, stack traces, device information
- No personal data: Activity names and personal information are never transmitted to Sentry
- Privacy Policy: sentry.io/privacy
9.4. Apple App Store / Google Play Store
- Purpose: Subscription and purchase handling
- Apple Privacy Policy: apple.com/legal/privacy
- Google Privacy Policy: policies.google.com/privacy
9.5. Calendar Services (Optional)
If you enable calendar synchronization:
- Google Calendar API: Activity names and times are sent to Google to create calendar events
- Apple EventKit: Activity names and times are written to your local/iCloud calendar
- Your consent required: Calendar sync is disabled by default and requires your explicit permission
- Revocable: You can disable sync at any time in Settings
9.6. Speech Recognition Services (Optional)
If you use voice input:
- Apple Speech Recognition (iOS): Voice data is processed by Apple's speech recognition system
- Google Speech Services (Android): Voice data is processed by Google's speech recognition system
- We don't store voice data: We don't record or store your voice - it's processed by Apple/Google
- Optional: You can always use keyboard input instead
10. International Data Transfers
Data transmitted to Firebase may be processed on Google servers located outside the European Economic Area (EEA). Google ensures an adequate level of data protection in accordance with Standard Contractual Clauses (SCCs).
11. Changes to This Privacy Policy
We will notify you of significant changes to this Privacy Policy through:
- In-app notification
- Updating the "Last Updated" date at the top of this document
We recommend periodically reviewing this page.
12. Contact Us
For privacy-related questions, please contact us:
Email: support@tactido.com
We respond to inquiries within 30 business days.
13. Legal Basis for Processing
| Processing Purpose | Legal Basis (GDPR) |
|---|---|
| Service provision (time tracking) | Art. 6(1)(b) - contract performance |
| Analytics and app improvement | Art. 6(1)(a) - consent |
| Error reporting | Art. 6(1)(a) - consent |
| Subscription handling | Art. 6(1)(b) - contract performance |
| Account security and deletion requests | Art. 6(1)(b) - contract performance, or Art. 6(1)(c) where a legal obligation applies |
Tactido - Your time, your control.
© 2024-2026 . All rights reserved.