Skip to content
TapTidy
Privacy by design
HomeSecurity

Security and privacy

A task app should explain its trust model in plain language.

TapTidy uses offline-first storage, optional end-to-end encryption (E2EE), and less telemetry than the average subscription task app. This page gives the short, honest version of that model.

Offline-first writes AES-256-GCM E2EE in Pro Zero telemetry defaults in Pro
Diagram showing tasks encrypted on-device, relayed through the server as sealed packets, and decrypted on the recipient device.
When you enable E2EE, your device encrypts task content before the content leaves the device.
Explicit server visibility model E2EE available in Pro Open sync where it matters

What the server can see

The server sees enough to operate the service.

The server stores account identity, subscription status, and operational metadata. TapTidy uses this data to authenticate you and enforce plan limits.

What the server should not need

The server does not need your task content on Pro with E2EE.

When you enable E2EE, your devices encrypt and decrypt task contents. The server only transports and stores ciphertext.

What differs by plan

The plans change telemetry defaults, not the owner of your data.

TapTidy does not train models on your task data on any tier. Pro adds zero-telemetry defaults and encrypted content.

Threat model

TapTidy protects against ordinary privacy risks. It does not sell spy-movie claims.

  • Offline-first local writes reduce dependency on constant cloud reachability.
  • Encrypted content in Pro reduces what the hosted service can read.
  • Direct APK (Android application package) downloads support users who do not want the Play Store.
  • Open standards reduce lock-in and make export and interoperability easier.

AI and telemetry

TapTidy does not train AI models on your task data.

TapTidy does not use your task contents to train machine-learning models. TapTidy collects less telemetry than typical subscription software. Pro defaults to zero telemetry.

Control surface

A summary of the security model.

Users usually check these controls before they put household or personal data into an app.

TapTidy security controls at a glance
Area TapTidy posture What that means
Task storage Offline-first local storage Your device stays authoritative for writes, even without connectivity.
Encrypted task content E2EE in Pro Your device can encrypt task contents before it sends them to the server.
Telemetry defaults Zero telemetry default in Pro Pro removes ordinary analytics and crash-reporting defaults unless you explicitly opt in.
AI training Never on your task data TapTidy does not use your tasks for model training.
Android distribution Standard and no-Google APKs You can choose the dependency profile you are comfortable with.
Open standards CalDAV / WebDAV support TapTidy supports interoperability as a core feature.

Security FAQ

Common questions from security-conscious evaluators.

These answers show which privacy claims the product architecture enforces.

No. TapTidy does not use your task data to train machine-learning models. That is true on every tier.

The product model matches the privacy model.

TapTidy gives you local-first writes, optional encrypted content, and small telemetry defaults. These controls are concrete, not marketing.

Download Android Or start in the web app first if you want to evaluate the workflow.