etappi
One etappi at a time

etappi

© 2026 etappi

PricingDownloadHow to use?BlogChangelogPrivacyTermsSupportContactEmail support at support@etappi.app
Privacy Policy · etappi

Last updated: July 20, 2026 · v1.3.0

Privacy Policy

Last updated: July 20, 2026

1. Who we are

Etappi is operated by Oles Didukh, an individual sole proprietor resident in Ukraine. Questions about this policy or the data we hold about you can be sent to support@etappi.app.

2. What we collect

  • Account information. Your email address and display name, provided through Clerk when you sign up or sign in.
  • Your content. Tasks, projects, notes, tags, and related metadata that you create in the app. Stored in a Postgres database operated by Neon.
  • Product usage analytics. Anonymous events describing how you navigate and use the app (pages visited, features used), collected via PostHog — and, where consent is required, only after you opt in. See section 4.
  • Crash and error telemetry. Stack traces, device model, operating system version, and anonymous session identifiers, collected via Sentry when the app encounters an error.
  • Push delivery metadata. Expo push tokens tied to your account so we can deliver reminders and notifications.
  • Rate-limiting metadata. Your user ID (or IP address for unauthenticated requests) and short-lived request counters, held in Redis to prevent abuse.

We do not use advertising identifiers, and we do not sell your data. For a full description of the cookies we set — including the analytics and attribution cookies and how to control them — see section 4 ("Cookies and consent").

3. Why we collect it

  • To operate the service you signed up for.
  • To understand and improve how the app is used.
  • To debug crashes and errors so we can fix them.
  • To deliver push notifications you have asked to receive.

For users in the European Economic Area and the United Kingdom, the legal bases under Art. 6 GDPR are:

  • Performance of a contract (Art. 6(1)(b)) — account information, your content, and push delivery metadata: we cannot provide the service without them.
  • Legitimate interest (Art. 6(1)(f)) — crash and error telemetry, and rate-limiting metadata: keeping the service secure and working. You can object by emailing us.
  • Consent (Art. 6(1)(a)) — (a) product analytics and first-touch attribution cookies: for visitors in the EEA and the UK these run only after you opt in, and you can withdraw at any time (see section 4); and (b) sending your content to the AI processor: in-app AI actions run only when you trigger them, and email capture runs AI extraction only on messages sent to the private inbox alias you set up (available on AI plans). No content reaches the AI processor outside these flows.

4. Cookies and consent

We keep cookie use to a minimum and sort every cookie into one of three categories.

  • Necessary — always active; the service cannot run without them, and they are exempt from consent. These are Clerk's authentication session cookie (keeps you signed in) and etappi_consent, which stores your own cookie choices so we do not have to ask again.
  • Analytics — a first-party PostHog cookie that records anonymous product usage (pages visited, features used) so we can understand and improve the app. We do not use it for advertising, we do not sell it, and session replay is disabled.
  • Marketing — a single first-party attribution cookie (etappi_attribution) that remembers where you first arrived from, so that if you sign up we can attribute the signup to its source. It is not shared with any advertising network.

How consent works. If you visit from the European Economic Area or the United Kingdom, the Analytics and Marketing cookies are switched off by default and set only after you opt in. A banner on your first visit lets you accept all, reject all, or choose per category, and nothing non-essential is stored until you choose. Everywhere else these cookies are on by default, and you can still switch them off.

Changing your mind. You can review or change your choices at any time from Settings → Legal → Cookie preferences. Withdrawing analytics consent stops collection immediately and clears the PostHog cookie; withdrawing marketing consent stops the attribution cookie from being set. Withdrawal is as easy as opting in.

5. Processors

We share data with the following third-party processors. Each is used only for the purpose described.

Processor Purpose Region Status
Clerk Authentication and session management United States Active
Neon Postgres database hosting United States Active
PostHog Product usage analytics (anonymous events; EEA/UK visitors are tracked only after opt-in; no session replay, no advertising) European Union Active
Sentry Crash and error telemetry United States Active
Expo Push Push notification relay to APNs / FCM United States Active
Upstash Redis-backed rate limiting (stores user-ID- or IP-keyed request counters, no content) United States Active
Cloudflare R2 Storage for user-uploaded file attachments and export archives Global Active
Anthropic AI features (task decomposition, planning, prioritisation, scheduling, quick-add parsing, email capture) — receives the text you submit to an AI action, the titles, descriptions, due dates, deadlines, priorities, and durations of the tasks involved, and the subject and body of messages sent to your private inbox alias; not used to train models United States Active
Resend Transactional email delivery United States Planned

"Planned" processors may be added in a future release. This policy will be updated before any planned processor begins handling your data.

6. Retention

  • Account deletion triggers a hard delete of your account and content within 30 days.
  • Crash telemetry is retained in Sentry for 90 days and then deleted automatically.
  • Product analytics events are retained by PostHog for 12 months and then deleted automatically.
  • Database backups are retained per Neon's backup window for the plan we use.

7. Your rights

You can export all of your data at any time, on any plan, from Settings → Account → Data export (instant JSON/CSV download, or an emailed archive). You can also request access to, correction of, or deletion of your personal data by emailing support@etappi.app. We respond to valid requests within 30 days.

8. International transfers

Data is stored with processors operating in the United States, the European Union, or with globally distributed infrastructure. By using the service you consent to your data being transferred to and stored in these regions. We rely on the processors' own safeguards for cross-border data handling.

9. Children

Etappi is intended for users aged 13 and older. We do not knowingly collect personal data from anyone under 13. If you believe we have collected data from a child under 13, email us and we will delete it.

10. Browser extension ("Save to Etappi")

The optional "Save to Etappi" browser extension lets you capture the page you are viewing as a task in your account. It handles data as follows:

  • What it reads. Only the current tab's URL and title, and only at the moment you open the extension and choose to save. It does not read page contents, track your browsing, or access other tabs.
  • What it stores. A single Etappi access token, held locally on your device in the browser's extension storage. The token is not synced across devices and is sent only to Etappi to authenticate your requests. Disconnecting in the extension or uninstalling it removes the token.
  • What it transmits. When you save, it sends the task title you confirmed, the source page URL, and the project you selected — to the Etappi API only, over HTTPS. It contains no analytics, no advertising, and no third-party tracking, and it loads no remote code.

The extension introduces no new processors beyond those listed in section 5.

11. Changes to this policy

We may update this policy. Material changes will trigger an in-app notification. The effective date at the top of this page always reflects the current version.

12. Contact

support@etappi.app