Privacy Policy

Last updated: 19 July 2026

This Privacy Policy explains how Tickr ("we", "us", "our") collects, uses, and stores your personal data when you use the Tickr application (the "Service"), and describes your rights under UK GDPR.

1. Who We Are

Tickr is operated by Luke Turner, based in the United Kingdom. Luke Turner is the data controller for your personal data.

Contact: tickr.user.feedback@gmail.com

2. Data We Collect

2.1 Account Information

When you sign in, we receive your name and email address from your chosen sign-in provider — Google or Apple. We never receive your Google or Apple password.

If you use Sign in with Apple and choose Apple's "Hide My Email" option, we receive a private relay email address provided by Apple (which forwards to your real address) instead of your personal email. Apple provides your name only the first time you sign in, and only if you choose to share it.

2.2 App Content

We store the data you create while using the Service:

2.3 Photos

You may optionally attach before/after progress photos to tasks. These images are uploaded to and stored on Cloudflare R2 (see Section 5). Photo upload is entirely optional.

When you upload a photo, a downscaled copy is automatically scanned for explicit or prohibited content by our moderation provider, Amazon Web Services (AWS Rekognition), to keep the Service and its community feed safe and to enforce our content policies. This automated scan runs on every uploaded photo, whether or not you later choose to share it, and is not used to identify you.

2.4 Community Feed and Connections

Tickr includes optional social features. If you choose to share a completed task to the public community feed, the photos, title, and any note you add become visible to other Tickr users, shown alongside your public username (or your display name if you enable that option). If you connect with another user, you each become able to see the other's shared tasks. These features are entirely optional — you control what, if anything, you share, and you can remove shared posts or block other users at any time.

2.5 Push Notification Token

If you grant notification permission on your device, we store a device push token to deliver task reminders and summary notifications via Firebase Cloud Messaging. You can revoke this permission at any time in your device settings.

2.6 Technical Data

Our servers automatically log IP addresses and request timestamps for security and reliability purposes.

3. Lawful Basis for Processing

Processing activity Lawful basis
Providing the core Service (account, tasks, projects, time tracking, sync) Contract — Art. 6(1)(b) UK GDPR
Storing and delivering push notifications Consent — Art. 6(1)(a) UK GDPR (you grant device permission)
Security monitoring, abuse prevention, server logs Legitimate interests — Art. 6(1)(f) UK GDPR
Automated moderation of uploaded photos (safety, content policy) Legitimate interests — Art. 6(1)(f) UK GDPR
Product analytics and error tracking (PostHog) Legitimate interests — Art. 6(1)(f) UK GDPR

We do not use your data for advertising, marketing emails, or profiling.

4. How We Use Your Data

We use your data solely to:

5. Third-Party Processors

We use the following third-party services to operate the Service. Each acts as a data processor under a contractual arrangement:

Processor Purpose Data involved Location
Google (OAuth) Sign-in authentication Name, email USA
Apple (Sign in with Apple) Sign-in authentication Name (first sign-in only), email or Apple private relay email USA
Google Firebase (FCM) Push notification delivery Device push token, notification content USA
Cloudflare R2 Photo storage Task photos you upload USA
Amazon Web Services (AWS Rekognition) Automated image content moderation A downscaled copy of photos you upload USA
Railway Backend hosting and database All personal data USA (US East)
PostHog Product analytics and server error tracking User ID; email and display name (web only); feature usage events (e.g. task created, timer started, photo uploaded); server error data (exception type, request path). Automatic page/click capture is disabled. EU

Transfers outside the UK/EEA are made under the UK International Data Transfer Agreement (IDTA) or equivalent safeguards maintained by each processor.

We do not sell your data to any third party. We do not share your data with advertisers or unlisted business partners.

6. Data Retention

We retain your personal data for as long as your account is active. When you delete your account:

7. Your Rights

Under UK GDPR, you have the right to:

To exercise any of these rights, contact us at tickr.user.feedback@gmail.com. We will respond within one month.

To delete your account and all associated data, you can either use the account deletion option within the app, or submit a request by email. Deletion requests are processed within 30 days.

Request account & data deletion →

8. Right to Complain

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority:

9. Security

We use HTTPS for all data in transit and rely on Railway's and Cloudflare's infrastructure for data at rest. No internet-based system is completely secure, and we cannot guarantee absolute security.

10. Children

The Service is not directed at anyone under the age of 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to This Policy

We may update this policy from time to time. We will notify you by posting the updated policy in the app and updating the "Last updated" date above. Continued use of the Service after a change constitutes acceptance of the updated policy.

12. Contact

For any questions about this Privacy Policy or your personal data:
Email: tickr.user.feedback@gmail.com