Privacy & your data
Everyday Task is a small app run by one person. It has no advertising, no trackers, no third-party scripts watching you, and nothing about you is sold, shared or profiled. This page says exactly what is stored and how to get rid of it.
What is stored
- Your email addressIt is your account name — it is how you sign in, and where a password reset link is sent. Nothing else is ever sent to it, and it is never given to anyone.
- Your password, hashedStored as a scrypt hash with its own random salt, never as the password itself. Nobody, me included, can read it back.
- Your timezoneRead from your browser when you sign in, so that “today” means your today and the daily reminder lands at your chosen hour, not mine.
- Your tasks and what you tickedThe app itself: the title of each task, how often it repeats, its subtasks, and one row per day you ticked it, with the points and the streak that tick was worth.
- Your points, badges and rewardsThe score, the badges awarded, and whatever you bought with points. Cosmetic, and computed only from your own ticks.
- Your reminder devicesOnly if you turn notifications on: one row per device, holding the push address your browser generated and the keys that encrypt the message. It identifies a browser, not a person, and turning reminders off deletes it.
- Messages you send meThe contact form stores what you wrote and the address to reply to, so a message is never lost if the email fails to go out.
- Failed sign-in and reset countsA counter per email address and per IP, kept for a few minutes to a few hours and then deleted automatically. It is what stops someone guessing passwords or flooding an inbox with reset links.
Why it is allowed to be stored
Everything above exists to give you the app you asked for — that is the contract between us (GDPR art. 6.1.b), except the sign-in counters, which are there to keep the accounts safe and rest on a legitimate interest (art. 6.1.f). Nothing here relies on consent except notifications, which you turn on yourself and can turn off at any time.
How long
For as long as your account exists, and no longer. Delete the account and every row listed above is deleted with it, at once — there is no soft delete, no thirty-day grace period and no backup you could be restored from. The only thing that survives is the record of a tip, kept as an accounting entry with your identity stripped out of it.
Cookies
One, called et_session. It holds a random session token, cannot be read by JavaScript, and expires after a year or the moment you sign out. There is no advertising cookie and no analytics cookie: page views are counted by Vercel Analytics, which is cookieless and never identifies a visitor.
Who else ever sees it
- VercelRuns the site. Functions are pinned to Paris (cdg1).
- MongoDB AtlasHolds the database, in AWS eu-west-3 (Paris).
- BrevoSends password reset emails. Only sees the address it delivers to.
- Apple, Google or MozillaDeliver a push notification to your device, if you turned reminders on. The content is encrypted with your device's own keys before it leaves the server.
- Buy Me a CoffeeOnly if you choose to tip. They tell the app an address bought a coffee so the badge lands; no card detail ever reaches this site.
Your rights
You can ask for a copy of your data, have it corrected, or have it erased, and you can object to any of it. Erasure is the button at the bottom of this page and needs no request. For anything else, write to me through the contact form in the app — settings panel, Contact — and I answer personally. If you are in the EU and my answer does not satisfy you, you can complain to your national data protection authority; in France that is the CNIL.
Delete your account
Sign in first, then come back to this page — the delete button appears here, and it does not go through me.
Sign inLast updated 31 August 2026.