Privacy
What NeatTick collects, how long we keep it, and how to ask us to delete it.
Account data
When you create an account, AWS Cognito stores your email address and password credentials (or your Google account link if you sign in with Google). We also store a profile with your screen name and optional avatar image. Screen names appear to people you share checklists with. We use your email for sign-in, password reset, and sharing-related notices you trigger in the product.
Lists, templates, and checklists you create are stored so the product can show them to you and to people you share them with. We do not sell this content.
Feedback and support messages
When you use the contact form, bug report, feature request, broken-link reporter, or thumbs controls, we create a tracked incident. Email is optional on every channel — leave it only if you want a reply. Name is optional and only collected on the contact form.
Unless you choose to omit technical context, each report's context envelope includes these fields (from the client builder):
version— Context schema version (always 1)appId— Application id (checklist)appVersion— App version / deploy stampsurfaceId— Which form / tool surfaceroute— Current page path (tokens redacted)occurredAt— Timestamp when the report was builttimezone— Timezonelocale— Localeviewport— Viewport sizedeviceClass— Device class (mobile / tablet / desktop)browser— Browser (family + major version)os— Operating systemprefersColorScheme— Color scheme preferencesessionRef— Ephemeral browser-session id (not a login id)payload— Optional allowlisted facts only — counts, kind, model id, cache-hit, HTTP status, or error name/message/truncated stack. Never list names, item text, notes, other members' emails, share tokens, or invite tokens
Share-link paths are redacted before they leave your browser (for example /s/[token]), so a capability token is not stored with the incident.
Retention
- Incident records: 24 months
- contactEmail / contactName: 12 months after the incident closes (fields are purged; the row may remain)
- Large context blobs: 12 months
- Rate-limit IP hashes: up to 72 hours
Account data (Cognito credentials and your profile) is kept while your account exists. Deleting your account removes the profile and associated app data we control; Cognito deletion follows the same request path below.
Third-party scripts
Feedback forms may load Cloudflare Turnstile to reduce automated spam. That script runs in your browser when you open a form and sends a challenge token with the submission. See Cloudflare's own privacy documentation for how Turnstile processes data.
Incidents are stored in a shared feedback service operated alongside this site. Owner notification and optional auto-reply email are sent via Amazon SES from noreply@neattick.com.
Deletion requests
To request deletion of feedback you submitted (or of your account and profile), use the contact form and include your ticket reference if you have one, or the email on the account. We will confirm when the deletion is done.
Changes
If this policy changes in a material way, we will update this page. Continued use of the site after a change means you have seen the updated terms.