Privacy
What Todayish knows about you
Todayish is a habit tracker. It needs to know what your habits are and when you did them, and it tries very hard not to need anything else. This page says exactly what is collected, why, and what you can do about it.
Effective[EFFECTIVE DATE]
The short version
- Your habits, your Google account details, a timezone, and — only if you switch reminders on — a push subscription. That is the whole list.
- It lives in a Postgres database on Railway, plus a copy in your own browser so the app works offline.
- Google sees your sign-in. Railway hosts the database. Nobody else gets any of it, and none of it is ever sold.
- You can export everything and delete everything from inside the app, whenever you like.
A summary, not the agreement. The numbered sections below are what applies.
1Who is responsible
Todayish is operated by [OPERATOR NAME], who decides what is collected and why, and is the person to contact about any of it. Contact details are in section 12.
2What is collected, and why
- Your Google account details — your name, email address and profile picture URL, passed to us by Google when you sign in. They identify your account and are what your data is attached to. Todayish never sees your Google password.
- What you type into the app — habit titles, notes, cadence settings, effort, priority and location, the days you marked complete, your daily points goals and their history. This is the product; without it there is nothing to show you.
- A timezone and a week-start day — first suggested by your browser, then editable in Settings. Used to work out what “today” means for you and to group weeks correctly.
- A push subscription — only if you turn reminders on. This is an address your browser gives us to deliver a notification to, along with the keys needed to encrypt it. Turning reminders off removes it.
- A sign-in session — a session record and a cookie, so you stay signed in between visits.
- Ordinary server logs — our host records requests, including IP address, timestamp and the page requested, for security and debugging. They are not used to build a profile of you.
3What is not collected
There is no analytics, no crash or telemetry reporting, no advertising, no advertising identifiers, no fingerprinting, no third-party trackers and no social media pixels anywhere in Todayish. No third party is embedded in these pages to watch you read them.
Your data is never sold, rented, or shared for anyone else’s marketing, and it is never used to train a machine-learning model.
4Where it is stored
Everything lives in a PostgreSQL database run by Railway, our hosting provider, in [HOSTING REGION]. Traffic between your browser and the app is encrypted with HTTPS.
Todayish is also offline-capable, so a copy of your own data is kept in your browser’s local storage on each device you sign in on. Signing out or clearing your browser data removes that local copy; the server copy is unaffected.
5Who else can see it
- Google, for sign-in only. Google tells us who you are; we never send your habit data to Google.
- Railway, who run the servers and the database on our behalf and may not use the data for anything else.
- Your browser’s push service — Apple, Google or Mozilla, depending on the browser — and only if you turn reminders on. A reminder contains the habit’s title, so a notification you enable does travel through that service, encrypted in transit.
Beyond that, your data is disclosed only if the law requires it, and only to the extent it requires.
6How long it is kept
Your data is kept for as long as your account exists. Deleting a habit deletes its completion history with it, immediately and permanently. Deleting your account removes your habits, completions, goals, sessions and push subscriptions from the live database straight away.
Encrypted database backups can hold a copy for up to [BACKUP RETENTION PERIOD] after that, after which they expire on their own.
7Your rights, and how to use them
- Export. The app exports your full dataset, in a file you can keep. No request needed.
- Deletion. The app deletes individual habits, and your whole account, from Settings. No request needed.
- Correction. Everything Todayish stores about you is editable in the app, apart from your Google account details, which come from Google and are best changed there.
- Objection, restriction and portability. Depending on where you live — the UK, the EU, California and several other places give you these explicitly — you may have further rights over your data. Ask, and they will be honoured.
If any of that fails, write to the address in section 12. If you are in the UK or EU you may also complain to your local data protection authority.
8Cookies
Todayish sets one cookie: the one that keeps you signed in. It is essential to the service and there is no way to use the app without it. There are no analytics, advertising, or third-party cookies, which is why there is no cookie banner.
9Security
Sign-in is handled by Google, so no password of yours is stored here. Traffic is served over HTTPS, and database access is restricted to the application itself. No system is perfectly secure, and nobody honest claims otherwise — but the less that is collected, the less there is to lose, which is the main reason so little is collected.
10Children
Todayish is not directed at children and is not intended for anyone under [MINIMUM AGE]. If you believe a child has an account, write to us and it will be removed.
11Changes to this policy
If this policy changes, the effective date at the top changes with it. If a change materially affects what is collected or who it goes to, you will be told in the app before it takes effect, not afterwards.
12Contact
Questions, requests, or complaints about privacy go to [CONTACT EMAIL ADDRESS], or by post to [POSTAL ADDRESS]. The terms of service cover the rest of the relationship.