Category
Account
- What we collect
- First name, last name, email address, and a bcrypt-hashed password
- Retention
- Until you delete your account
Privacy Policy
How TidalTask collects, uses, and protects your account and task data across web, iOS, and Android, and how to access, correct, or delete it at any time.
Introduction
TidalTask ("TidalTask," "we," "us," or "our") is an ADHD-focused task management app developed by Daniel Wedding. This Privacy Policy explains what information we collect through the TidalTask web app, Progressive Web App, iOS app, and Android app (together, the "Service"), how we use it, who we share it with, and the choices you have.
By creating a TidalTask account or using the Service, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.
This policy was last updated on July 6, 2026. If you have questions, contact us at [support@tidaltask.app](mailto:support@tidaltask.app).
Data we collect
TidalTask collects only the information needed to run the app, keep your account secure, and support the features you choose to use.
Category
Category
Category
Category
Category
Category
Category
Category
Category
Category
Category
Category
Category
| Category | What we collect | Retention |
|---|---|---|
| Account | First name, last name, email address, and a bcrypt-hashed password | Until you delete your account |
| Tasks | Title, description, due date, completion status, repeat schedule, reminder time, priority, group, tags, and assigned collaborators | Until the task or account is deleted |
| Sessions | A session token stored in an httpOnly cookie and your last login timestamp | 30 days, or until you log out |
| Two-factor authentication | An AES-256-GCM encrypted TOTP secret and hashed backup codes | Until 2FA is disabled or the account is deleted |
| Passkeys | WebAuthn credential ID, public key, device type, backup status, and transport hints | Until the passkey is removed or the account is deleted |
| Device tokens | A SHA-256 hash of Siri/API tokens, an expiry date, and a label | Until expired or the account is deleted |
| API keys | A SHA-256 hash of the key only; the raw value is never stored | Until revoked or the account is deleted |
| Notifications | Message title, body, type, scheduled time, and delivery time | Until the account is deleted |
| Notification preferences | Push settings, reminder cadence, summary schedule, and timezone offset | Until the account is deleted |
| Reviews | Star rating and an optional message | Kept indefinitely in anonymized form; the link to your account is removed on deletion |
| OAuth clients | Client name, redirect URIs, grant types, and scope | Until the client is removed |
| Calendar export token | A random token used to generate your calendar feed | Until regenerated or the account is deleted |
| Announcement reads | IDs of announcements you have viewed or clicked | Until the account is deleted |
How we use data
We use the information above to:
We do not sell your personal information, and we do not use your tasks or account data to build third-party advertising profiles.
Third-party services
We use a small number of providers to run the Service. We share only what each provider needs to do its job.
Service
Service
Service
Service
| Service | Purpose | Data shared |
|---|---|---|
| Resend | Sending transactional email, such as password resets and welcome messages | Email address and name |
| MongoDB Atlas / self-hosted database | Storing all account and app data described above | All data listed in the table above |
| Apple APNs / Google FCM | Delivering push notifications to your device via Capacitor | Device push token |
| Discord webhook | Internal operational logging for the team | User ID only — no name or email |
Your rights
Wherever you are located, you have the following rights over your TidalTask data, and we have built in-app tools so you can exercise them yourself at any time:
If you would rather make one of these requests by email, contact us at [support@tidaltask.app](mailto:support@tidaltask.app) and we will respond within 30 days.
Security
We apply the following technical safeguards to the data described in this policy:
No method of storage or transmission is perfectly secure, but these measures reflect current good practice for an app handling personal task and account data.
More information
Data retention. We keep each category of data for as long as described in the table above — generally for as long as your account is active, plus a limited period for sessions and security logs. When you delete your account, associated data is deleted or, in the case of anonymized reviews, disconnected from your identity.
Children's privacy. TidalTask is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at support@tidaltask.app and we will delete it.
International users. TidalTask is operated from the United States, and your data is processed and stored on infrastructure governed under the laws of the State of Texas, regardless of where you access the Service from.
Changes to this policy. We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through an in-app notice. Continued use of the Service after a change takes effect means you accept the updated policy.
Contact us. Questions about this policy or your data can be sent to [support@tidaltask.app](mailto:support@tidaltask.app).
Related pages
Page
Read the TidalTask Terms of Service covering accounts, acceptable use, API keys and integrations, termination, disclaimers, and governing law.
Read moreAbout
Learn what TidalTask is trying to build: an ADHD-friendly planning app focused on quick capture, flexible routines, and clarity without guilt.
Read moreFAQ
Read the TidalTask FAQ to learn who it is for, how it fits ADHD planning needs, and how it differs from generic task apps.
Read moreFAQ
No. TidalTask does not sell personal information. Data is shared only with the service providers listed above, strictly to operate the app.
Go to Settings → Delete Account in the app. This immediately and permanently deletes your tasks, sessions, passkeys, device tokens, notifications, and OAuth codes.
Your data is stored in MongoDB Atlas or a self-hosted MongoDB instance, governed under the laws of the State of Texas.
Next step
Reach out any time — we are happy to walk through what TidalTask stores and why.