This Privacy Policy explains how Tickr ("we", "us", "our") collects, uses, and stores your personal data when you use the Tickr application (the "Service"), and describes your rights under UK GDPR.
Tickr is operated by Luke Turner, based in the United Kingdom. Luke Turner is the data controller for your personal data.
When you sign in, we receive your name and email address from your chosen sign-in provider — Google or Apple. We never receive your Google or Apple password.
If you use Sign in with Apple and choose Apple's "Hide My Email" option, we receive a private relay email address provided by Apple (which forwards to your real address) instead of your personal email. Apple provides your name only the first time you sign in, and only if you choose to share it.
We store the data you create while using the Service:
You may optionally attach before/after progress photos to tasks. These images are uploaded to and stored on Cloudflare R2 (see Section 5). Photo upload is entirely optional.
When you upload a photo, a downscaled copy is automatically scanned for explicit or prohibited content by our moderation provider, Amazon Web Services (AWS Rekognition), to keep the Service and its community feed safe and to enforce our content policies. This automated scan runs on every uploaded photo, whether or not you later choose to share it, and is not used to identify you.
Tickr includes optional social features. If you choose to share a completed task to the public community feed, the photos, title, and any note you add become visible to other Tickr users, shown alongside your public username (or your display name if you enable that option). If you connect with another user, you each become able to see the other's shared tasks. These features are entirely optional — you control what, if anything, you share, and you can remove shared posts or block other users at any time.
If you grant notification permission on your device, we store a device push token to deliver task reminders and summary notifications via Firebase Cloud Messaging. You can revoke this permission at any time in your device settings.
Our servers automatically log IP addresses and request timestamps for security and reliability purposes.
| Processing activity | Lawful basis |
|---|---|
| Providing the core Service (account, tasks, projects, time tracking, sync) | Contract — Art. 6(1)(b) UK GDPR |
| Storing and delivering push notifications | Consent — Art. 6(1)(a) UK GDPR (you grant device permission) |
| Security monitoring, abuse prevention, server logs | Legitimate interests — Art. 6(1)(f) UK GDPR |
| Automated moderation of uploaded photos (safety, content policy) | Legitimate interests — Art. 6(1)(f) UK GDPR |
| Product analytics and error tracking (PostHog) | Legitimate interests — Art. 6(1)(f) UK GDPR |
We do not use your data for advertising, marketing emails, or profiling.
We use your data solely to:
We use the following third-party services to operate the Service. Each acts as a data processor under a contractual arrangement:
| Processor | Purpose | Data involved | Location |
|---|---|---|---|
| Google (OAuth) | Sign-in authentication | Name, email | USA |
| Apple (Sign in with Apple) | Sign-in authentication | Name (first sign-in only), email or Apple private relay email | USA |
| Google Firebase (FCM) | Push notification delivery | Device push token, notification content | USA |
| Cloudflare R2 | Photo storage | Task photos you upload | USA |
| Amazon Web Services (AWS Rekognition) | Automated image content moderation | A downscaled copy of photos you upload | USA |
| Railway | Backend hosting and database | All personal data | USA (US East) |
| PostHog | Product analytics and server error tracking | User ID; email and display name (web only); feature usage events (e.g. task created, timer started, photo uploaded); server error data (exception type, request path). Automatic page/click capture is disabled. | EU |
Transfers outside the UK/EEA are made under the UK International Data Transfer Agreement (IDTA) or equivalent safeguards maintained by each processor.
We do not sell your data to any third party. We do not share your data with advertisers or unlisted business partners.
We retain your personal data for as long as your account is active. When you delete your account:
Under UK GDPR, you have the right to:
To exercise any of these rights, contact us at tickr.user.feedback@gmail.com. We will respond within one month.
To delete your account and all associated data, you can either use the account deletion option within the app, or submit a request by email. Deletion requests are processed within 30 days.
Request account & data deletion →
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority:
We use HTTPS for all data in transit and rely on Railway's and Cloudflare's infrastructure for data at rest. No internet-based system is completely secure, and we cannot guarantee absolute security.
The Service is not directed at anyone under the age of 16. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this policy from time to time. We will notify you by posting the updated policy in the app and updating the "Last updated" date above. Continued use of the Service after a change constitutes acceptance of the updated policy.