Privacy policy
Privacy policy
This policy explains what information MAUJr collects when you use Task Tamer, what it is for, and what rights you have over it.
In short
Four lines before the legal text. Everything below says the same thing, more precisely.
- We store your name, your email address and whatever you write in your lists.
- We do not sell or share that information, and we do not use it for advertising or to train models.
- When you use the assistant, the text of that list is sent to the model provider so it can answer — and for nothing else.
- You can ask for a copy, or delete everything, from inside the app.
What we collect
We collect three kinds of information. The second is the largest and the one that matters most: it is what you write in the app.
We do not collect location data, the contacts on your device, or special categories of data within the meaning of Article 9 of the GDPR.
- Account informationName and email address
- Content you createLists, tasks, folders, tags, notes, due dates and the files you attach to tasks
- Technical diagnosticsCrash and performance logs, without the content of your lists, on the terms set out in Preferences and consent
How it reaches us
Information reaches us in two ways.
What you give us. When you create an account, your name and email. When you use the app, the content you write and the files you attach.
What is collected automatically. Technical device information tied to crashes and performance, on the terms set out in Preferences and consent.
If you choose to sign in with Google, Microsoft or GitHub, your identity provider passes us the name and email address on that account. It is the only information about you that reaches us from a third party.
We do not buy or receive information about you from data brokers, online directories, marketplaces or data exchanges, or any similar service.
Cookies
We do not use tracking cookies or similar technologies, and there are no advertising or third-party cookies on our pages.
The web app keeps a few preferences in your browser's local storage — the theme, the language, and your diagnostics choice. They are not cookies, they are never sent to us, and they are erased when you clear your browser data.
“Do not track” requests. We do not change our behaviour in response to the browser's Do Not Track signal, because there is no uniform technical standard for interpreting it. Since we do no cross-site tracking, the signal would have nothing to switch off.
Preferences and consent
Account content is processed persistently, so that your lists are available across sessions and across devices. That is the service: there is no way to turn it off and still have sync.
Collecting diagnostics — crash and stability logs — is separate from that, and it is yours to decide. It starts switched off and is only collected if you switch it on, and your choice applies to both surfaces. The logs are handled by a different service on each: Firebase Crashlytics on Android, Sentry in the web app. You can switch collection on and off at any time, in the app's settings, under Privacy. Diagnostics never include the content of your lists.
Declining diagnostics limits nothing in the app: the features, the sync and the support are exactly the same.
Why we collect it
The content of your lists is not used for advertising, is not used to train artificial-intelligence models, and is not read by us in the normal course of running the service.
- To provide the serviceStoring your lists, syncing them across devices, authenticating you and keeping your account working
- To answer supportWhen you write to us, we use what you send to deal with the matter
- To fix faultsTechnical logs, on the terms of the previous section
- To comply with the lawWhere legal obligations apply
- To answer the assistantWhen you ask it for something, the text of the list in question and your request are used to generate that answer, and for nothing else
Where it is processed
Your lists, tasks, folders and tags are held in Google Cloud Firestore in the European Union (eur3 multi-region: data centres in Belgium and the Netherlands).
Your account and sign-in data are handled by Firebase Authentication. Google offers no regional guarantee for this service, so this information may be processed outside the European Union.
Profile photos and the files you attach to tasks are held in Google Cloud Storage, in the United States, for a delivery-latency reason. The files are protected by access rules that allow only you to read them.
Assistant requests are handled by Vertex AI in the European Union (region europe-west1, Belgium — next to the database that holds your lists). In app versions before 0.27.0 they were handled in the United States. The service uses the Gemini 2.5 Flash model on the paid tier: Google does not use your prompts or the assistant's responses to train or improve models, and they are not read by human reviewers for that purpose. They are retained briefly only for abuse detection and to meet legal obligations.
Crash logs, where you have allowed them to be collected, are handled on Android by Firebase Crashlytics (Google) and, in the web app, by Sentry, whose organisation is configured in the European Union data region. Neither of them receives the content of your lists.
Deleting your account removes the information we hold, with one exception: the messages you send us through in-app support cannot be altered or deleted from inside the app, because a support record either party can rewrite is not a reliable record. Write to us if you need a support message removed.
Where information is processed outside the European Economic Area, those transfers are made under the European Commission's Standard Contractual Clauses, incorporated into our data processing agreement with Google Cloud.
Export and restore
You can ask for a copy of everything we hold, from the app's settings. What you get is a readable, unencrypted text file — whoever holds it, reads it. It includes your lists, tasks, folders and tags, and also your profile — name, profession, date of birth, gender and the address of your photo. Subscription status is not in the file, because it is not recorded in your account with us.
The Vault is included only if you ask. By default, lists marked as secret are left out and never leave the app. If you ask for them to be included, they go in the clear, in the same file. The PIN and biometrics protect access inside the application; they do not protect the exported file. Those are different things.
The copy carries the addresses of the files you attached, not the files. Attachments and photos go on living in storage, and the exported file points at them — if the account is deleted, those addresses stop answering. Save your attachments separately before deleting your account.
How long we keep it
We keep your account information and the content you create for as long as the account exists. There is no clock running behind it: a list written two years ago is still there because the account is still there.
When you ask for your account to be deleted, the account and its content are held for 30 days before being permanently removed. During that period, simply signing in cancels the request. After the 30 days, removal is permanent and nothing can be recovered.
Diagnostics: if you allow collection, crash logs are kept for 90 days on Android (Firebase Crashlytics), after which removal begins, and for 30 days in the web app (Sentry).
Support messages: kept for 24 months from the last message in the conversation.
When we no longer have a legitimate need to process information, we delete it or anonymise it. Where that is not immediately possible — because it sits in backups, for instance — we keep it in isolation, with no further processing, until deletion becomes possible.
Who we share it with
We do not sell or rent your information, and we do not share it for advertising. There are three situations in which information leaves us.
Processors. The Google Cloud and Firebase services listed under Where it is processed handle information on our behalf, under a data processing agreement. Sentry handles the web app's crash logs on the same terms, if you allow diagnostics. None of them may use it for their own purposes.
Legal obligations. Where we are legally required to disclose information to comply with the law, an authority's request, legal proceedings or a court order.
Business transfer. In the event of a merger, sale of assets, financing or acquisition, in whole or in part, information may be transferred to the entity involved. If that happens, we will tell you before the information changes hands.
Links out. Our pages may link to sites that are not ours. That link does not bring them inside this policy, and we recommend reading the policy of whoever operates them.
GDPR and your rights
Automated processing. We do not make automated decisions with legal effects concerning you, and we do not build profiles from the content of your lists.
The only automated processing of any significance is the assistant: when you use it, the text of the list in question and your request are sent to the model provider to generate the answer, on the terms described under Where it is processed. It happens when you use it, and not in the background.
Your rights. Under Articles 12 to 23 of the GDPR, you have the right to: access and a copy of your information in an accessible format; rectification; erasure; restriction of processing; objection to processing; portability; and to withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand.
To exercise any of these rights, write to the contact address at the end. We reply within 30 days.
Complaints. If you believe we have handled your information unlawfully, you may complain to the Comissão Nacional de Proteção de Dados (CNPD), the Portuguese supervisory authority.
- Performance of a contractStoring, syncing and serving your lists, and keeping your account. This is the core of the service
- ConsentTechnical diagnostics
- Legal obligationWhere the law requires us to retain or disclose
- Legitimate interestApplication security and abuse prevention, within a scope that does not interfere with your rights
Children
Task Tamer is not directed at children under 16 and we do not knowingly collect information from anyone below that age. If you are a parent or legal guardian and believe your child has given us information without your consent, write to us: once we have verified it, we will remove that information.
Security
We take reasonable measures to keep the information we collect secure: communications with our services are encrypted in transit, and access to account content is limited by rules that allow only you to read what is yours.
In the app, the PIN or biometric lock and the vault are additional layers on your side: the PIN is stored encrypted in the device's own secure storage and never reaches us.
Those layers hold inside the application. A copy you export leaves unencrypted and, if you ask for the Vault, with the Vault in the clear — on the terms set out under Export and restore.
Even so, no method of transmission over the internet or of digital storage is completely secure, and we cannot guarantee absolute security.
Changes
We may update this policy to reflect changes in the law or in our practices. The effective date is at the top of the page and is the date from which the published version applies.
Where a change is material — a new category of information, a new purpose, a new processor or a change of region — we show a notice in the app and update the date at the top of this page.
Contact
- Address
- Avenida Dom Nuno Álvares Pereira 16 CV Direita, 2735-147 Sintra, Portugal
- contact@maujr.com
For any privacy question, or to exercise your rights, write to the address above. MAUJr is the controller of this information.