TidyPepple

Privacy Policy for TidyPepple

Last updated: 3 October 2026

This privacy policy explains how personal data is processed when you use TidyPepple (“the App”) and this website. TidyPepple is an installable web app (progressive web app, “PWA”) for task management that runs in your browser.

In case of doubt, the German version of this privacy policy prevails.


1. Data controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Frank Röseler
c/o POSTFLEX PFX-656-694
Emsdettener Straße 10
48268 Greven
Germany

Email: tidypepple@roeslr.com


2. Principle: local first, encrypted otherwise

TidyPepple is a local-first app. Everything you enter (tasks, notes, projects, contexts, attachments) is stored and processed on your device or in your browser.

  • Without the optional sync, your content never leaves the device. There is then no user account, no sign-in and no registration.
  • With sync, your content is end-to-end encrypted on your device before it is transmitted. Neither the controller nor the hosting provider can read it (see section 5).
  • There is no tracking, no analysis of individual users' behaviour and no advertising. No cookies are set for analytics or advertising. We only count, anonymously, how many devices start the App per day (see section 4).

3. Data stored on your device or in your browser

For the App to work, the following is stored locally in your browser (technically in IndexedDB, localStorage and the service worker cache):

  • your tasks with title, notes, status, dates, contexts and attachments,
  • technical data for sync (device ID, timestamps, list of changes not yet sent),
  • settings such as language, text size, sorting and filters,
  • if you use sync: the unlocked key of your vault as a non-exportable browser key object, and your sign-in session,
  • the App files themselves, so the App starts offline.

This data stays on your device. You can delete it at any time by deleting tasks in the App, clearing the site data for TidyPepple in your browser or uninstalling the App. Under *Settings → Data* you can export your tasks as a JSON file.

Legal basis: Art. 6(1)(b) GDPR (providing the features you use) and § 25(2) no. 2 TDDDG (storage on the device that is strictly necessary).


4. Server log files when the website and App are loaded

The website and the App are delivered as static files by a web server. As with any website, connection data is processed in server log files when they are requested:

  • IP address of the requesting device,
  • date and time of access,
  • name of the requested file and amount of data transferred,
  • status code, referring page (referrer), browser and operating system.

This data is needed to deliver the website and the App and to keep the server stable and secure. It is not combined with other data sources.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and reliable delivery).

The hosting provider, acting as processor under Art. 28 GDPR, is netcup GmbH, Emmy-Noether-Straße 10, 76185 Karlsruhe, Germany. A data processing agreement is in place. Server log files are deleted automatically after 30 days.

Counting App starts. So that we know how many devices use the App, the App sends a short request to our web server (/beacon) each time it starts. It only contains whether the App is installed or running in the browser and the App version, plus whether sync is used (local only, account without sync, syncing). The App assigns no device identifier for this and stores nothing on your device for it; no content is transmitted.

When the request arrives, the IP address and browser identifier are processed – as with any request. They go into a separate log file that is normally evaluated and deleted automatically within one hour at the latest. In doing so, the IP address and browser identifier are combined with a random value generated anew each day into a one-way hash. Its only purpose is to count several starts of the same device on the same day once. The random value is deleted at the end of the day; after that only daily totals remain (e.g. "120 devices, 80 of them installed"). This does not allow us to identify individual persons, and the data is not combined with any other data.

If you do not want to be counted, you can block requests to /beacon, e.g. with a content blocker; the App keeps working unchanged.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in knowing how widely the App and its versions are used in order to plan development and operation).


5. Optional sync

Sync between several devices is an optional, paid feature. Data is only transmitted to a server if you set it up.

Sign-in. You sign in with your email address and receive a sign-in link by email. No password is stored. This processes your email address, a user ID and sign-in times.

Encrypted content. Your tasks and attachments are encrypted on your device with a key only you hold (AES-256-GCM), which is protected by your passphrase or recovery key. The server stores encrypted records only. Titles, notes, contexts, file names and file contents are not readable by the controller or the hosting provider. Your passphrase and recovery key never leave your device.

Technically visible metadata. For syncing, the following is unencrypted on the server: random record IDs, times of changes, the number of records, whether a record was deleted, and the number and size of attachments.

Provider. Sign-in, database and file storage are operated by Supabase, Inc. (USA) as processor. The data is stored in a data centre in the European Union. A data processing agreement including the EU Standard Contractual Clauses for any access from third countries is in place.

Sending emails. Supabase sends sign-in and confirmation links through the email service Resend, operated by Plus Five Five, Inc. (USA), as processor. This processes your email address, the content of the respective email (the sign-in or confirmation link) and delivery details (time, delivery status). A data processing agreement including the EU Standard Contractual Clauses is in place with Resend; as Resend is a US provider, data may be transferred to the USA. The content of your tasks is never sent this way.

Retention. Deleted records are reduced to an empty marker after 90 days. All other data is kept until you ask for your account to be deleted (see section 9); it also stays retrievable after a subscription ends, so no data is lost.

Legal basis: Art. 6(1)(b) GDPR (performance of the sync contract).


6. Buying the sync subscription via Lemon Squeezy

Purchase and payment of the sync subscription are handled by Lemon Squeezy, operated by Lemon Squeezy, LLC, USA. You are redirected to Lemon Squeezy's checkout page for this. Lemon Squeezy acts as the seller (Merchant of Record) and payment processor and processes the data arising during the order (e.g. name, email address, payment and billing data) as an independent controller in accordance with its own privacy policy: https://www.lemonsqueezy.com/privacy

If you are already signed in, the App passes your user ID and email address to the checkout page so the subscription can be linked to your account. Lemon Squeezy then informs the controller of the subscription status (email address from the order, order and subscription IDs, status, end of term). The controller does not receive full payment details.

As Lemon Squeezy is a US provider, data may be transferred to the USA. Lemon Squeezy relies on appropriate safeguards under Art. 44 et seq. GDPR (including Standard Contractual Clauses).

Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract) and Art. 6(1)(c) GDPR (retention obligations under tax and commercial law).


7. Contact by email

If you email us, we process the data you send (name, email address, content of the message) solely to handle your request.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in answering enquiries) or Art. 6(1)(b) GDPR if the enquiry relates to a purchase.


8. No third-party content on the website

This website loads no fonts, scripts or other content from third-party servers. There are no analytics tools, no social media plugins and no embedded videos.


9. Your rights

Subject to the statutory requirements, you have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR).

You can view, export and delete locally stored data yourself at any time in the App or through your browser settings. To delete your sync account including all encrypted data, an email to the address above is sufficient.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.


10. Changes to this privacy policy

This privacy policy may be updated to reflect changes in the law or in the App's features. The current version published on this website applies.