Privacy Policy
Last updated: August 13, 2026
1. Who we are
Etappi is operated by Oles Didukh, an individual sole proprietor resident in Ukraine. Questions about this policy or the data we hold about you can be sent to support@etappi.app.
2. What we collect
- Account information. Your email address and display name, provided through Clerk when you sign up or sign in.
- Your content. Tasks, projects, notes, tags, and related metadata that you create in the app. Stored in a Postgres database operated by Neon.
- Location (optional). If you attach a place to a task, the coordinates you pick are stored with that task and synced like the rest of your content. We collect this only while you are actively choosing a place — Etappi never tracks your location in the background, and the app does not run location services when you are not using it. Tasks without a place carry no location data.
- Product usage analytics. Events describing how you navigate and use the app (pages visited, features used), collected via PostHog — and, where consent is required, only after you opt in. See section 4. Before you sign in, these events carry only a random identifier generated in your browser. Once you sign in, they are linked to your Etappi account identifier, so this data is pseudonymous rather than anonymous. We also attach a one-way SHA-256 hash of your email address, used solely to recognise the same person across our web, desktop, and mobile apps; the address itself is never sent to PostHog and the hash cannot be reversed back into it.
- App and platform. Which Etappi app an event came from (web, desktop, iOS, or Android), attached to every analytics event so we can tell the surfaces apart.
- Approximate location (country). A two-letter country code derived from your network address by our hosting provider when you load the web app. We store only the country code — never your IP address — and use it to understand where the product is used. This is separate from the per-task location described above.
- First-party product measurement. A record, on our own servers, of significant account events — for example signing up, completing onboarding, or changing a subscription — stored in our database alongside your account. Each record holds the event name, when it happened, the app and platform it came from, and the country code. This measurement is first-party: it is not shared with any third party beyond the processors listed in section 5, and it is not cookie-based, so it is not covered by the analytics toggle in section 4. See section 3 for the legal basis and your right to object.
- Crash and error telemetry. Stack traces, device model, operating system version, and anonymous session identifiers, collected via Sentry when the app encounters an error.
- Push delivery metadata. Expo push tokens tied to your account so we can deliver reminders and notifications.
- Rate-limiting metadata. Your user ID (or IP address for unauthenticated requests) and short-lived request counters, held in Redis to prevent abuse.
- Waitlist email address. If you enter your address in the Android waitlist form on our website, we store that address along with the site language you were using, so we can email you when the Android app is available. No Etappi account is needed to do this and the address is not linked to one. It is also added to a contact list held by Resend (section 5), the provider that sends the announcement. We delete it from both places within 12 months, or sooner if you ask.
We do not use advertising identifiers, and we do not sell your data. For a full description of the cookies we set — including the analytics and attribution cookies and how to control them — see section 4 ("Cookies and consent").
3. Why we collect it
- To operate the service you signed up for.
- To understand and improve how the app is used.
- To debug crashes and errors so we can fix them.
- To deliver push notifications you have asked to receive.
- To show a task's location when you have chosen one.
- To tell you when the Android app launches, if you asked us to.
For users in the European Economic Area and the United Kingdom, the legal bases under Art. 6 GDPR are:
- Performance of a contract (Art. 6(1)(b)) — account information, your content (including any location you attach to a task), and push delivery metadata: we cannot provide the service without them. On plans that include AI this also covers the background embedding described below, because the "similar tasks" feature is part of the plan you subscribed to and cannot work without it.
- Legitimate interest (Art. 6(1)(f)) — crash and error telemetry, and rate-limiting metadata: keeping the service secure and working. Also first-party product measurement (the server-side record described in section 2, including the app, platform, and country code): knowing how many people use the service and whether it works for them. This does not read or write anything on your device, so no consent is required for it; you can object to it by emailing us, and we will stop recording these events for your account.
- Consent (Art. 6(1)(a)) — (a) product analytics and first-touch attribution cookies: for visitors in the EEA and the UK these run only after you opt in, and you can withdraw at any time (see section 4); and (b) sending your content to Anthropic, the AI processor behind our in-app AI features: those actions run only when you trigger them, and email capture runs AI extraction only on messages sent to the private inbox alias you set up (available on AI plans). No content reaches Anthropic outside these flows; and (c) the Android waitlist: you give us your address to receive one launch announcement, and can withdraw by emailing us, which removes it from our database and from the Resend contact list.
Background embedding for "similar tasks". If your account is on a plan that includes AI, the title and description of each task you create or edit are sent to Voyage AI (section 5) shortly afterwards, to produce an embedding — a numerical representation used to find tasks that resemble one another. This runs automatically on a schedule rather than on a separate action of yours, which is why it sits under the contract basis above and not under consent. It is scoped to your own account: if you are not on an AI plan, your task content is never sent to Voyage AI, including when you work in a shared project owned by someone who is. Embeddings are stored with the task and are deleted when the task is deleted.
4. Cookies and consent
We keep cookie use to a minimum and sort every cookie into one of three categories.
- Necessary — always active; the service cannot run without them, and they are exempt from consent. These are Clerk's authentication session cookie (keeps you signed in) and
etappi_consent, which stores your own cookie choices so we do not have to ask again. - Analytics — a first-party PostHog cookie that records product usage (pages visited, features used) so we can understand and improve the app. While you are signed out it holds only a random identifier; once you sign in, the events it produces are linked to your account as described in section 2. We do not use it for advertising, we do not sell it, and session replay is disabled.
- Marketing — a single first-party attribution cookie (
etappi_attribution) that remembers where you first arrived from, so that if you sign up we can attribute the signup to its source. It is not shared with any advertising network.
How consent works. If you visit from the European Economic Area or the United Kingdom, the Analytics and Marketing cookies are switched off by default and set only after you opt in. A banner on your first visit lets you accept all, reject all, or choose per category, and nothing non-essential is stored until you choose. Everywhere else these cookies are on by default, and you can still switch them off.
Changing your mind. You can review or change your choices at any time from Settings → Legal → Cookie preferences. Withdrawing analytics consent stops collection immediately and clears the PostHog cookie; withdrawing marketing consent stops the attribution cookie from being set. Withdrawal is as easy as opting in.
In the mobile apps. There are no cookies in the apps, but the analytics SDK stores an identifier on your device, which needs the same permission a cookie does. Settings → Privacy → Share usage data controls it: on a device set to an EEA or UK region it starts off and nothing is stored until you turn it on; elsewhere it starts on and you can switch it off. Turning it off there does one thing more than the web toggles do — it also records your objection to the first-party measurement described below, so both stop together.
What these toggles do not cover. The first-party product measurement described in section 2 stores nothing on your device and sets no cookie, so it falls outside these cookie categories and continues regardless of your choices here. It runs on the legitimate-interest basis in section 3. You can object to it by switching off Share usage data in the mobile app or by emailing us; either way we stop recording it and delete what we have already recorded for your account.
5. Processors
We share data with the following third-party processors. Each is used only for the purpose described.
| Processor | Purpose | Region | Status |
|---|---|---|---|
| Clerk | Authentication and session management | United States | Active |
| Neon | Postgres database hosting | European Union (eu-central-1) | Active |
| PowerSync | Sync service that replicates your tasks, projects, and related content between our database and your devices, and holds a copy of that content while it is in transit | Global | Active |
| PostHog | Product usage analytics (events are linked to your account identifier and a one-way hash of your email once you sign in; EEA/UK visitors are tracked only after opt-in; no session replay, no advertising) | European Union | Active |
| Vercel | Web and marketing site hosting; derives the two-letter country code described in section 2 from your network address at the edge | Global | Active |
| Fly.io | Real-time update fan-out over WebSocket, so your other devices know when to refetch. Receives record identifiers and the names of the endpoints affected — never the content of a task or project. | United States | Active |
| Sentry | Crash and error telemetry | United States | Active |
| Expo Push | Push notification relay to APNs / FCM | United States | Active |
| Upstash | Redis-backed rate limiting (stores user-ID- or IP-keyed request counters, no content) | United States | Active |
| Cloudflare R2 | Storage for user-uploaded file attachments and export archives | Global | Active |
| Anthropic | AI features (task decomposition, planning, prioritisation, scheduling, quick-add parsing, email capture) — receives the text you submit to an AI action, the titles, descriptions, due dates, deadlines, priorities, and durations of the tasks involved, and the subject and body of messages sent to your private inbox alias; not used to train models | United States | Active |
| Voyage AI | Text embeddings that power the "similar tasks" suggestion — receives the title and description of tasks you create or edit | United States | Active |
| Resend | Transactional email delivery (welcome, invitation, and waitlist messages) | United States | Active |
| Paddle | Subscription checkout and billing for web purchases, acting as merchant of record — receives your name, email address, billing address, and country. We never receive or store your card number. | Global | Active |
| Apple | In-app purchase and subscription management for the iOS app. Apple, not us, processes the payment and holds the payment details. | Global | Active |
| Google Play | In-app purchase and subscription management for the Android app. Google, not us, processes the payment and holds the payment details. | Global | Active |
| Todoist | Optional one-off task import. Contacted only if you connect a Todoist account, and only with the access token you grant, to read the tasks you choose to import. | Global | Active |
Every processor listed above is in use today. If a new processor is added, this policy is updated before it begins handling your data.
6. Retention
- Account deletion triggers a hard delete of your account and content within 30 days.
- Crash telemetry is retained in Sentry for 90 days and then deleted automatically.
- Product analytics events are retained by PostHog for 12 months and then deleted automatically.
- First-party product measurement events are retained for 24 months and then deleted automatically. They are tied to your account, so deleting your account deletes them sooner.
- When you delete your account we also ask PostHog to delete the person profile associated with it.
- Waitlist email addresses are deleted within 12 months of the day you submitted them, by a daily job that removes the address from the Resend contact list first and from our database second. There is no account behind a waitlist entry, so this job is what deletes it — nothing else does.
- Database backups are retained per Neon's backup window for the plan we use.
7. Your rights
You can export all of your data at any time, on any plan, from Settings → Account → Data export (instant JSON/CSV download, or an emailed archive). You can also request access to, correction of, or deletion of your personal data by emailing support@etappi.app. We respond to valid requests within 30 days.
Full deletion instructions — including how to request deletion once the app is no longer installed — are on the account deletion page.
8. International transfers
Data is stored with processors operating in the United States, the European Union, or with globally distributed infrastructure. By using the service you consent to your data being transferred to and stored in these regions. We rely on the processors' own safeguards for cross-border data handling.
9. Children
Etappi is intended for users aged 13 and older. We do not knowingly collect personal data from anyone under 13. If you believe we have collected data from a child under 13, email us and we will delete it.
10. Browser extension ("Save to Etappi")
The optional "Save to Etappi" browser extension lets you capture the page you are viewing as a task in your account. It handles data as follows:
- What it reads. Only the current tab's URL and title, and only at the moment you open the extension and choose to save. It does not read page contents, track your browsing, or access other tabs.
- What it stores. A single Etappi access token, held locally on your device in the browser's extension storage. The token is not synced across devices and is sent only to Etappi to authenticate your requests. Disconnecting in the extension or uninstalling it removes the token.
- What it transmits. When you save, it sends the task title you confirmed, the source page URL, and the project you selected — to the Etappi API only, over HTTPS. It contains no analytics, no advertising, and no third-party tracking, and it loads no remote code.
The extension introduces no new processors beyond those listed in section 5.
11. Changes to this policy
We may update this policy. The effective date and version number at the top of this page always reflect the current version, so you can tell at a glance whether anything has changed since you last read it. We do not send a notification for every revision — check this page if you want to be sure.