Privacy

What NeatTick collects, how long we keep it, and how to ask us to delete it.

Account data

When you create an account, AWS Cognito stores your email address and password credentials (or your Google account link if you sign in with Google). We also store a profile with your screen name and optional avatar image. Screen names appear to people you share checklists with. We use your email for sign-in, password reset, and sharing-related notices you trigger in the product.

Lists, templates, and checklists you create are stored so the product can show them to you and to people you share them with. We do not sell this content.

Feedback and support messages

When you use the contact form, bug report, feature request, broken-link reporter, or thumbs controls, we create a tracked incident. Email is optional on every channel — leave it only if you want a reply. Name is optional and only collected on the contact form.

Unless you choose to omit technical context, each report's context envelope includes these fields (from the client builder):

  • versionContext schema version (always 1)
  • appIdApplication id (checklist)
  • appVersionApp version / deploy stamp
  • surfaceIdWhich form / tool surface
  • routeCurrent page path (tokens redacted)
  • occurredAtTimestamp when the report was built
  • timezoneTimezone
  • localeLocale
  • viewportViewport size
  • deviceClassDevice class (mobile / tablet / desktop)
  • browserBrowser (family + major version)
  • osOperating system
  • prefersColorSchemeColor scheme preference
  • sessionRefEphemeral browser-session id (not a login id)
  • payloadOptional allowlisted facts only — counts, kind, model id, cache-hit, HTTP status, or error name/message/truncated stack. Never list names, item text, notes, other members' emails, share tokens, or invite tokens

Share-link paths are redacted before they leave your browser (for example /s/[token]), so a capability token is not stored with the incident.

Retention

  • Incident records: 24 months
  • contactEmail / contactName: 12 months after the incident closes (fields are purged; the row may remain)
  • Large context blobs: 12 months
  • Rate-limit IP hashes: up to 72 hours

Account data (Cognito credentials and your profile) is kept while your account exists. Deleting your account removes the profile and associated app data we control; Cognito deletion follows the same request path below.

Third-party scripts

Feedback forms may load Cloudflare Turnstile to reduce automated spam. That script runs in your browser when you open a form and sends a challenge token with the submission. See Cloudflare's own privacy documentation for how Turnstile processes data.

Incidents are stored in a shared feedback service operated alongside this site. Owner notification and optional auto-reply email are sent via Amazon SES from noreply@neattick.com.

Deletion requests

To request deletion of feedback you submitted (or of your account and profile), use the contact form and include your ticket reference if you have one, or the email on the account. We will confirm when the deletion is done.

Changes

If this policy changes in a material way, we will update this page. Continued use of the site after a change means you have seen the updated terms.