Privacy Policy
Last updated and effective: 24 August 2026. Contact: productivica.help@gmail.com
Introduction
This policy explains what Productivica does with your information. It is written by the one person who builds the app, in plain language, because that is the only way it would be honest.
The short version: your tasks and habits stay on your device. There is no account, no server, and no cloud backup, so we cannot see or retrieve your task content even if we wanted to. We use a small number of outside services for analytics and subscriptions, and we explain exactly what each one gets below.
Please do not put sensitive information in your tasks or notes, such as health details, financial account numbers, government ID numbers, or anything about your racial or ethnic origin, religion, or sexual orientation. Your data stays on your device and is protected by your device's own security, but Productivica is a productivity app, not a secure vault, and we would rather tell you that plainly than let you assume otherwise.
Who We Are
Productivica is built and operated by one person, not a company. There is no legal department, no dedicated privacy officer, and no outside investors.
- Data controller: Eryk Włoszczyński
- Postal address: Ul. Murna 12, 63-720 Koźmin Wielkopolski, Poland
- Email: productivica.help@gmail.com
What Data We Collect
Your tasks, habits, and settings
Task titles, descriptions and notes, habits and streaks, yearly goals, due dates, completion status, themes and notification times, and custom categories are all stored locally on your device using AsyncStorage, React Native's local storage. This data never leaves your device unless you export it yourself. It is permanently deleted when you uninstall the app. There is no server copy and no way for us to recover it, because we never had it.
Calendar
Productivica can read and write your device calendar. These are two separate things:
- Reading: if you grant calendar access, the app reads your existing calendar events so it can show them alongside your tasks in the Timeline view. Your events are displayed, never modified.
- Writing (Premium, off by default): if you turn on Calendar Sync, the app creates a separate calendar on your device named "Productivica" and writes your dated tasks into it as events. It only ever writes to that one calendar; it never touches your existing calendars. This is one way only: changes you make in your calendar app, including to events Productivica created, are never read back into Productivica.
Calendar data is processed entirely on your device and is never sent to us or to anyone else. You can revoke calendar access at any time in your device settings, and turning off Calendar Sync deletes the "Productivica" calendar and nothing else.
Your calendar may contain sensitive things you put there yourself, such as a medical appointment or a religious observance. Productivica never analyses that. Event titles are drawn on your screen and nothing more: the app does not scan them, categorise them, infer anything from them, store them, or send them anywhere, and it behaves identically whatever an event says. Because the app draws no conclusions from event content, it does not set out to process the special categories of data that Article 9 of the GDPR covers, and it has no feature that would benefit from doing so. If you would rather it did not see your calendar at all, decline the permission or revoke it later. The timeline then simply shows your tasks, and nothing else in the app changes.
Analytics
We use Mixpanel, configured with EU data residency, to understand how the app is used. This includes which features you use, which screens you visit, your device type and OS version, your app version, and your subscription tier or trial status. It does not include your task titles, notes, or any content you type into the app. A random device ID is generated on first open so events from the same device can be grouped together; it is not tied to your name, email, or any other identifying information, and it is deleted when you uninstall the app.
Here is the part we want to be straightforward about rather than paper over: we currently treat this analytics collection as resting on our legitimate interest in improving the app. There is a real, well-argued position under EU and Polish law that storing or reading anything on your device, including an analytics identifier, requires your opt-in consent from the start, not a legitimate-interest justification applied afterward. We have not yet rebuilt the app so that analytics only begins after you say yes; today it runs by default and you turn it off in Settings. Until that changes, turning analytics off is the more cautious choice if this distinction matters to you, and we are not going to claim a compliance position we have not actually built.
Subscriptions
We use RevenueCat to manage Premium subscriptions. It receives your purchase receipt, subscription status, and a device identifier separate from the analytics one, from Apple or Google. It does not receive your payment details: your card information is handled only by Apple or Google, never by us or RevenueCat.
Notifications
Productivica sends reminders, such as a morning summary or a streak warning, and Premium weekly-review alerts. These are scheduled and delivered entirely by your phone's own operating system. Nothing about your reminders, including their content or timing, is sent to us or to any third-party server. You choose the times in Settings, and you can turn notifications off entirely at any time.
Other permissions
Our Android app package currently declares a microphone-related permission. It is a byproduct of the sound-effects library we use to play a small sound when you complete a task, which only plays audio and does not require microphone access to do so. Productivica does not access your microphone, listen to audio, or record anything, on either platform.
Data Processing Summary
A short table of what we process, why, and on what legal basis.
| Data type | Why | Legal basis | Who can access it | Retention |
|---|---|---|---|---|
| Tasks, habits, settings | To run the app | Contract (needed to provide the service) | No one; stays on your device | Until you uninstall the app |
| Calendar events, read and written | Timeline display, and (Premium, opt-in) adding tasks to your calendar | Consent, given through the permission prompt and, for writing, a separate toggle | No one; stays on your device | Until you revoke calendar access, or turn off Calendar Sync |
| Usage events (screens, features, subscription status) | To understand how the app is used and fix problems | Legitimate interest, see the note above on why this is contested | Mixpanel | Up to 2 years, then automatically deleted by Mixpanel, unless you ask us to delete it sooner |
| Device ID for analytics | To group events from the same device | Same as above | Mixpanel | Until app uninstall |
| Purchase and subscription status | To verify Premium access | Contract (needed for the Premium feature you are paying for) | RevenueCat, Apple/Google | As required by tax and accounting law |
| Reminder times and content | To deliver your notifications | Consent, via your device's notification permission | No one; scheduled and shown entirely on your device | Not applicable; nothing is sent anywhere |
Third-Party Services
Three companies process data on our behalf. Each one is contractually required to provide the same or equal protection of your data as this policy sets out, to use it only for the purpose we engaged them for, and not to sell it or use it for their own advertising. We do not share your data with anyone else.
Mixpanel (analytics)
Receives usage events, device type, app version, and the anonymous device ID described above. Never receives task titles, notes, or any content you type. Data is stored and processed under Mixpanel's EU data residency setting; some incidental processing, such as customer support, may still involve systems outside the EU, which Mixpanel covers under the EU-US Data Privacy Framework and Standard Contractual Clauses. Mixpanel's own privacy policy: https://mixpanel.com/legal/privacy-policy/
RevenueCat (subscriptions)
Receives your purchase receipt, subscription status, and a device identifier. Based in the United States; transfers are covered by Standard Contractual Clauses. RevenueCat's privacy policy: https://www.revenuecat.com/privacy/
Apple and Google
Apple and Google process your purchase and handle your payment details directly; we never see them. For your purchase and payment data, Apple and Google act independently, under their own privacy policies, not on our instructions. Apple: https://www.apple.com/legal/privacy/. Google: https://policies.google.com/privacy
International Data Transfers
| Data | Stored where | Safeguard |
|---|---|---|
| Tasks, habits, calendar data | Your device only | Never transferred; your device's own security |
| Analytics | Mixpanel, EU data residency | EU-US Data Privacy Framework and Standard Contractual Clauses for any incidental US processing |
| Subscriptions | RevenueCat, United States, plus Apple/Google | Standard Contractual Clauses |
The EU-US Data Privacy Framework is currently in force under an EU adequacy decision, though it is the subject of an active legal challenge as of this writing. This is an area of law that can change; we will update this policy if it does.
Data Retention
| Data | How long |
|---|---|
| Tasks, habits, notes | Until you delete them or uninstall the app |
| Calendar events read for the timeline | Not stored. They are read from your calendar each time the view is drawn, and stop being read the moment you revoke calendar access |
| Tasks written into the Productivica calendar | Until you turn Calendar Sync off, which removes that calendar, or delete it yourself in your calendar app |
| Analytics events | Up to 2 years, Mixpanel's current default, unless you ask us to delete it sooner |
| Subscription records | As required by tax and accounting law |
| Device ID (analytics) | Until app uninstall or your deletion request |
Your Privacy Rights
European Union and Poland (GDPR / RODO)
You have the right to: access a copy of your data; correct inaccurate data; ask us to erase your analytics data; get your local task data in a portable format, which you can already do yourself with the in-app export; restrict or object to our use of your analytics data; turn analytics off at any time in Settings, and withdraw the calendar and notification permissions you granted; and lodge a complaint with a supervisory authority. We say "object" rather than "withdraw consent" for analytics on purpose, because that is the correct mechanism for the legitimate-interest basis described above. If we move analytics to opt-in consent, this wording changes with it.
Because your task data never reaches us, we cannot personally retrieve or hand you a copy of it: the in-app export is the only copy that exists outside your device, and it is the same data you already have. For the analytics data we do hold, email us and we will tell you what is on file.
Nothing in Productivica is mandatory to provide. The app is fully usable with analytics off and calendar access denied; declining either has no effect beyond disabling that specific feature.
Supervisory authority in Poland: Urzad Ochrony Danych Osobowych (UODO), ul. Stanislawa Moniuszki 1A, 00-014 Warszawa, Poland. Website: https://uodo.gov.pl/
United States
California's CCPA/CPRA, and similar laws in Virginia, Colorado, Connecticut, Utah, and Texas, apply to businesses that meet specific size or revenue thresholds, such as handling data for 25,000 to 100,000 or more residents of that state, or crossing a revenue figure in the tens of millions of dollars. As a single developer with a small user base, we almost certainly do not meet any of these thresholds, so these laws likely do not legally apply to us. We are telling you that plainly rather than asserting rights infrastructure we have not built.
That said: we do not sell your personal information, and we do not share it for cross-context behavioral advertising, which is what California's "do not sell or share" right is about. Mixpanel receives usage data to help us understand the app, not to show you ads, on our behalf or anyone else's. If your state gives you a right we have not listed here, contact us and we will do what we reasonably can.
How to Exercise Your Rights
Export your data
In the app: Settings, then Data and Privacy, then Export My Data. This exports your tasks, notes, completions, and statistics as a JSON file you can save or share.
Delete your analytics data
Email productivica.help@gmail.com with the subject "Delete My Analytics Data" and include your device ID, found in Settings, Data and Privacy, View Device ID.
Delete everything
Uninstalling the app deletes all local data (tasks, notes, settings) immediately. Your analytics data stays with Mixpanel until you ask us to delete it. Subscription records stay with RevenueCat as required for billing and refunds.
Turn off analytics
Settings, then Data and Privacy, then turn Analytics off. No new events are tracked after that; data already collected stays with Mixpanel until you request deletion.
Response time and fees
We respond to privacy requests as promptly as we can, in practice within a few weeks, and within one month for GDPR/RODO requests. For complex requests we may extend by up to two further months and will tell you why. Every request gets a free response unless it is manifestly unfounded or excessive, for example the same request repeated many times in a short period; if that happens we will explain why before doing any work. There is no formal appeal process built into this policy: if you are unhappy with our response, you can contact UODO (details above) if you are in the EU or Poland, or your state Attorney General if you are in the United States.
Data Security and Breaches
Your task data is stored using your device's own encryption and never transmitted anywhere, so it cannot be exposed through a breach of our systems, because there are no such systems holding it. Connections to Mixpanel and RevenueCat use HTTPS/TLS encryption in transit. There is no user account and no password to steal, and no central database of user data to hack; your security here depends mainly on your own device's lock screen and software updates.
If a breach affecting Mixpanel or RevenueCat data occurs, we will notify Poland's supervisory authority, UODO, without undue delay and within 72 hours where feasible, if the breach is required to be reported. If the breach is likely to put you at high risk, we will also tell you directly without undue delay: by email if we have one for you, an in-app notice, and a notice on productivica.com.
Children's Privacy
Productivica is rated 13+. We do not knowingly collect data from children under 13, and we do not ask for or verify age. If you are under 13, please do not use the app. If we learn that a user is under 13, we will delete their analytics data.
For users aged 13 to 17: a parent or guardian can contact us on the user's behalf. Because there are no accounts, we cannot verify a family relationship, so we act on these requests in good faith rather than through a formal verification process.
Cookies and Tracking
Productivica is a native mobile app, not a website, so cookies do not apply to it. The app uses the Mixpanel and RevenueCat SDKs described above, local storage on your device, and an anonymous analytics device ID. We do not use advertising trackers, and we do not track you across other apps. You can turn off analytics tracking at any time in Settings, Data and Privacy.
Changes to This Policy
We may update this policy as the app changes or the law requires it. When we do, we update the date at the top. For a significant change, such as a new third party gaining access to your data or a change to your rights, we will also show a notice in the app. Continuing to use the app after a change takes effect means you accept the updated policy; if you disagree, you can stop using the app and ask us to delete your analytics data.
Contact Us
Email: productivica.help@gmail.com. This is a one-person project, so please allow a few days for a response.
For a privacy request, put "Privacy Request" in the subject line and say what you need: export, deletion, correction, or information. Include your device ID if you are asking us to delete analytics data.
For a security concern, put "Security Incident" in the subject line and describe what you found; we will respond as quickly as we can.