Skip to main content
Legal

Privacy Policy

Last updated: 20 July 2026

This Privacy Policy explains how Self-Control ("Self-Control", "we", "us"), a recurring-tasks tracker provided by Skadi International Corporation ("the Provider"), collects, uses, and protects your personal data when you use our website, web application, and mobile apps (together, "the Service").

We are the data controller for the personal data described below. If you have any questions, contact us at privacy@self-control.app.

1. Summary

  • We collect the minimum we need to run the Service: your account details, the content you create, and basic technical and usage data.
  • We do not sell your personal data.
  • Payments are handled by our merchant of record, Paddle — we never see or store your full card details.
  • You can export all your data or delete your account at any time from within the app.
  • We use a small number of trusted sub-processors, all listed in our Sub-processor List and kept in sync with this policy.

2. What data we collect

Account data. When you sign up we collect your email address, your display name, and (optionally) a profile image. Authentication is handled by Self-Control directly — your credentials are stored and verified on our own infrastructure, not by a third-party identity provider.

Content you create. The tasks, items, occurrences, checklist entries, notes, and team/sharing relationships you create in the Service. This is yours; we process it only to provide the Service.

Billing data. If you subscribe to Pro, our merchant of record Paddle collects and processes your payment details, billing address, and tax information. We receive only a subscription status, a Paddle subscription identifier, and the billing period — never your full card number.

Technical and security data. IP address and browser/device user-agent associated with active sessions (stored with refresh tokens for security and abuse-prevention), and server logs needed to operate and secure the Service.

Usage analytics. We run our own first-party, cookieless, anonymous usage analytics — self-hosted, with no third-party product-analytics service and no third-party tracker. As you use the Service we collect aggregate, non-identifying signals (which page is viewed — as a fixed page name; the broad category of referring site; roughly how long a page stays open; and whether the visitor is signed in) to understand which features are used so we can improve the Service. These signals set no cookie, store nothing on your device, and carry no persistent identifier, so they cannot be tied back to you across visits; personal identifiers are redacted before any telemetry reaches storage (see §5). Because it is cookieless and anonymous it requires no consent, but we honor your browser's Do Not Track and Global Privacy Control signals, and signed-in users can turn it off in Settings. If we ever introduce a third-party product-analytics service, we will update this policy and our Sub-processor List first, and we will collect non-essential analytics only with your consent where required.

Ad-click attribution. If you arrive from an advertisement we run, the link may carry the ad platform's click identifier (for example Google's gclid, Microsoft's msclkid, or Reddit's rdt_cid). We read it in the moment — no cookie, no pixel, nothing stored on your device — and it identifies that single ad click, not you across visits. If you then create an account in that same session, we store the identifier server-side for up to 90 days and use it solely to report to that platform, server to server, that its ad led to a sign-up or subscription, so we can measure our advertising. The report never includes your name or email. The identifier is deleted after 90 days at the latest — immediately if you delete your account — and appears in your data export while we hold it.

We do not intentionally collect special-category data (health, biometrics, etc.). The Service is intended for adults; it is not directed at children under 16.

3. How and why we use your data (legal bases)

PurposeData usedLegal basis (GDPR Art. 6)
Provide the Service (your account, tasks, occurrences, sharing)Account + content dataPerformance of a contract
Authenticate you and keep sessions secureAccount + technical/security dataPerformance of a contract; legitimate interests (security)
Process subscriptions and billingBilling data (via Paddle)Performance of a contract; legal obligation (tax)
Send transactional email (verification, reminders, invites, account notices)Email addressPerformance of a contract
Operate, debug, and secure the ServiceTechnical/security dataLegitimate interests
Measure our advertising (report that an ad led to a sign-up/subscription)Ad-click identifier (≤90 days)Legitimate interests (measuring advertising effectiveness)

4. Cookies and local storage

The web app keeps your access token in memory only and stores a single HttpOnly refresh cookie scoped to our API origin so you stay signed in. We also use local storage for interface preferences (such as filters and timezone). Paddle may set its own cookies during checkout. See our Cookie & Storage Notice for the full breakdown. The mobile apps use secure device storage instead of cookies.

5. Who we share data with (sub-processors)

We share personal data only with the service providers that help us run Self-Control, each bound by a data-processing agreement:

  • Paddle — payments, billing, and tax (merchant of record).
  • Neon — database hosting (Neon Postgres).
  • Cloudflare — application runtime (Workers), DNS, and content delivery.
  • Resend — transactional and reminder email delivery.

Our self-hosted observability stack (logs, metrics, and traces) runs on our own corp-controlled infrastructure and is not a third-party sub-processor. Identifiers such as email addresses and user IDs are redacted before any telemetry reaches that storage.

The current canonical list, including each provider's role and processing location, is maintained in our Sub-processor List and updated before any change takes effect.

6. International transfers

Some of our sub-processors process data outside your country, including in the United States. Where personal data is transferred out of the EEA/UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision.

7. How long we keep your data

  • Account and live content — your account, tasks, items, teams, and settings are kept for as long as your account is active.
  • History — dated occurrence records (including their completion history and comments) and team activity entries are kept for up to 3 years, measured from each record's date or from when it was added, whichever is later. Older history is permanently deleted by a daily cleanup. You can choose a shorter window (3, 6, 12, or 24 months) for the tasks you own in Settings → Account → Your data; the export tools below let you download a copy at any time before records age out.
  • Account deletion — when you delete your account we begin a 30-day soft-delete window, after which all your personal data is permanently and irreversibly erased from our primary database. Signing in again during that window cancels the deletion and restores your account.
  • Session/security records — refresh-token records are pruned automatically (typically within ~37 days of issue).
  • Operational telemetry — logs are retained for up to 30 days and metrics for up to 90 days, with personal identifiers redacted before storage.
  • Short-lived backups — deleted data can persist in encrypted point-in-time recovery backups for up to 7 days before it ages out of them.
  • Billing records — retained by Paddle and by us as required by tax and accounting law.

8. Your rights

Depending on where you live (including under the GDPR and the CCPA/CPRA), you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate data;
  • Erase your data ("right to be forgotten");
  • Export / port your data in a machine-readable format;
  • Object to or restrict certain processing; and
  • Withdraw consent at any time, where we rely on consent.

You can exercise the two most common rights yourself, directly in the app: Export my data and Delete my account in Settings → Account. For anything else, email privacy@self-control.app and we will respond within the timeframes required by law (generally one month under the GDPR). You also have the right to lodge a complaint with your local data-protection authority.

9. Security

We protect your data with encryption in transit (HTTPS/TLS), short-lived access tokens, rotating refresh tokens with replay detection, rate limiting, and the principle of least privilege. No system is perfectly secure, but we work to protect your data and will notify you and the relevant authorities of a breach where required by law.

10. Changes to this policy

We may update this policy as the Service evolves. We will update the "Last updated" date above and, for material changes, notify you in-app or by email.

11. Contact

Self-Control (operated by Skadi International Corporation)