TackieLog in →

Privacy Policy

Your Secrets Stay on the Mountain

The plain-language version: your goals are yours, and we work hard to keep them that way.

Last updated June 23, 2026

Effective June 23, 2026.

The short version

You tell Tackie what you want to achieve, and we help you climb toward it. To do that, we store the things you create (your goals, plans, tasks, and progress) and your account details. We do not sell your data, we do not rent or trade it, and we never hand it to advertisers. We do not use your data to target ads or to make automated decisions about you that have legal or similarly significant effects. The longer version below explains exactly what we collect, why, who helps us run the app, how long we keep each kind of data, and the controls you have, including how to delete everything.

This page uses warm, plain language on purpose. Where the law needs specific terms (like “legal basis” or “controller”), we include them too, so this policy does double duty as both a friendly explainer and a real, compliant notice.

Who we are

Tackie is an AI-assisted goal-planning app at tackie.io. The service is operated by Pinn.Media LLC, and it will transition to Tackie LLC once that entity is formed. For privacy law, the operator is the “data controller” (GDPR / UK GDPR) and “business” (US state laws) for the personal information described here, which means we decide what is collected and why.

  • Company / legal entity: Pinn.Media LLC (transitioning to Tackie LLC once formed), organized in Wyoming, United States.
  • Mailing address: 30 N Gould St #43324, Sheridan, Wyoming 82801, United States.
  • Contact for privacy questions: privacy@tackie.io
  • EU / UK users: if you are in the EU or UK and have questions about your data, you can reach us at privacy@tackie.io and we will help.
  • Data protection contact: privacy@tackie.io (a formal Data Protection Officer is not currently mandatory for us under GDPR Art. 37; we will reassess as we grow).

If you ever want to reach a human about your data, email us at privacy@tackie.io and we will help.

California notice at collection (short layered notice)

For California residents, here is the at-a-glance notice the CCPA/CPRA expects, with the full detail in the sections below.

Category of personal information we collectWhy we collect itDo we sell or share it?How long we keep it
Identifiers (email, name, phone, account ID)Create and secure your account, sign you in, contact youNoLife of the account, then deleted on the timeline below
Customer records / profile (date of birth, country, city, photo, timezone, pacing prefs)Confirm eligibility (13+), personalize and pace your planNoLife of the account, then deleted
Your content (goals, your “why”, answers, plans, tasks, streaks, reckons, reports, certificates)Deliver the core productNoLife of the account, then deleted
Geolocation (city-level only, never precise)Suggest nearby resources and show local weatherNoLife of the account, then deleted
Visual content (profile photo, completion photos, share graphics you upload)Show your avatar and let you celebrate or share a summitNoLife of the account, then deleted
Push subscription details (browser push endpoint and keys), reminder and notification settingsSend the reminders and nudges you opt intoNoOnly while you keep that reminder on; deleted when you turn it off or close your account
Ratings, testimonials, and feedback you choose to submitPublish approved testimonials and improve the productNoTestimonials until you change or we remove them; feedback for the life of your account
Support and chatbot messages (email and message you send us)Answer your question and provide supportNoAs long as needed to handle and document your request
Internet/usage and product activity (first-party usage events, plus aggregate cookieless analytics)Understand the activation funnel and improve the appNoUsage events tied to your account ID until deletion; cookieless analytics aggregate only
Diagnostic data (error reports and technical logs)Find and fix bugs, keep the app reliable and secureNoKept in deduplicated form for triage, then cleared
Inferences and sensitive data implied by your goalsSee “Consumer health data” and “Sensitive data” belowNoNot derived or persisted beyond the safety guardrail

We do not sell personal information, do not share it for cross-context behavioral / targeted advertising, and do not use it for profiling that produces legal or similarly significant effects. This notice is provided at or before the point of collection; the full policy is always linked from sign-up and from the footer.

What we collect, why, and our legal basis

Here is the honest, code-accurate list of what Tackie collects. “Legal basis” is the GDPR / UK GDPR justification; if you are in the US, think of it as “the reason we are allowed to do this.”

Lawful basis per purpose (GDPR / UK GDPR Art. 6)

PurposeWhat it coversLawful basis
Run your accountSign-up, sign-in, security, account emailsContract (Art. 6(1)(b)); legal obligation for account-security confirmations (Art. 6(1)(c))
Deliver the productStoring and adapting your goals, plans, tasks, progressContract (Art. 6(1)(b))
AI goal-sharpening and planningSending your goal text and answers to our AI provider to generate questions, plans, and reportsContract (Art. 6(1)(b)); see “Consumer health data” for the health-implicating layer
Location featuresCity lookup and local weatherConsent (Art. 6(1)(a)) via the browser permission prompt; withdraw any time
Reminders and notificationsThe nudges and cadence you switch on, including browser/PWA pushConsent (Art. 6(1)(a)) for the reminders and push you opt into; withdraw any time
Service emails (welcome, account, weekly recap)Confirmations and an optional weekly progress nudgeContract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) for account-security mail; legitimate interests or consent for the weekly recap, which you can switch off
Testimonials and feedbackPublishing approved testimonials and triaging feature requestsConsent (Art. 6(1)(a)) when you choose to submit; legitimate interests in improving the product
Support and chatbotAnswering your questions (the Ranger guide and support tickets)Contract (Art. 6(1)(b)) and our legitimate interest in supporting you
First-party product analytics, error monitoring, securityActivation funnel, bug triage, performance, abuse preventionLegitimate interests (Art. 6(1)(f)); we have weighed this against your privacy
Cookieless analyticsAggregate usage and performanceLegitimate interests (Art. 6(1)(f)); aggregated and not used to identify you
Optional non-essential cookies (if ever added)None todayConsent (Art. 6(1)(a)) and ePrivacy/PECR, asked before any are set

Account and profile information

  • What:your email address and authentication details; and any profile details you choose to add: first and last name, phone number, date of birth, country, city, a profile photo, your timezone, and pacing preferences (free time, weekly hours, weekly budget). If you turn on a passkey or two-factor authentication, we store the associated security credentials so we can verify it is you (we never see your biometrics, and a passkey’s private key never leaves your device).
  • Why: to create and secure your account, sign you in, personalize your plan, and contact you about your account.
  • Legal basis: performance of our contract with you (delivering the service you signed up for). Some optional profile fields rely on your consent, since you choose whether to add them.
  • Note on date of birth:we ask for it to confirm you are old enough to use Tackie (see “Children and teens” below) and so the experience fits you. It is not used for advertising.

Your content (goals, plans, tasks, progress)

  • What:the goals you describe in your own words, your “why” / motivation, the clarifying answers you give, the sharpened goals and weekly plans the app builds, your tasks, hints, schedules, streaks, focus time, weekly check-ins (“reckons”), AI-written reports, cosmetic unlocks, and completion certificates.
  • Why: this is the heart of the product. We store it so your climb persists across sessions, adapts week to week, and shows you honest progress.
  • Legal basis: performance of our contract with you.
  • Photos and graphics you upload. If you add a profile photo or a completion photo, or generate a shareable summit graphic, we store those images so they appear where you put them. Images are kept in your own folder so other users cannot reach them. Please do not upload photos of other people without their permission, or anything you do not have the right to share.
  • Heads up:because you write goals in your own words, your text can sometimes reveal sensitive things (for example, a health, fitness, or weight goal). Please read “Consumer health data” and “Sensitive data” below for exactly how we handle that.

Location (only if you allow it)

  • What:if you opt in through your browser, your device’s approximate coordinates are sent once to a third-party mapping service to look up your city. We store only the resulting city and country. We do not store the raw coordinates; they are validated and immediately discarded.
  • Why: to suggest relevant, nearby resources for your goals (for example, a local library, class, or shop category) and to show local weather where useful.
  • Legal basis:your consent (the browser permission prompt). You can decline, and Tackie still works with more general suggestions. See “Location, in detail” below.

Reminder, notification, and push preferences

  • What: the nudges, cadence, and notification settings you choose. If you opt in to browser or PWA push notifications, your browser creates a push subscription and we store its technical details (the push endpoint URL and the two keys your browser generates) so we can deliver a notification to that specific browser.
  • Why: to send only the reminders you ask for, to the device you enabled.
  • How push works.Push notifications are delivered through your browser’s own push service (operated by Google, Apple, Mozilla, or Microsoft depending on your browser). We send the message to that service, which delivers it to your device; we never send your push details anywhere else. You can turn push off any time, which deletes the stored subscription, and revoking the browser permission also stops it.
  • Legal basis: performance of our contract with you, and your consent for the reminders and push you switch on (withdraw any time).

Service email

  • What: the email address you use to receive service email. This includes account email (sign-up confirmation, password reset, email-change, and deletion confirmations), a one-time welcome email, and an optional weekly recap that nudges you with a short progress note (your current goal title and streak).
  • Why: to operate your account securely and, for the weekly recap, to help you keep momentum. These are service messages, not advertising, and we do not send marketing email or share your email with advertisers.
  • You control the recap. The weekly recap is on by default and you can switch it off any time in your settings. Account and security email cannot be turned off while you have an account, because it keeps your account safe.
  • Legal basis: performance of our contract with you and our legal obligation to confirm and secure accounts; the weekly recap rests on our legitimate interest in your progress, and you can opt out.

Product analytics and usage data

We use two layers of analytics, both privacy-minded and neither used for advertising:

  • First-party usage events. Our own servers record a small set of product milestones and engagement signals (for example, that a goal was created, a weekly check-in was done, a goal was summited, or which app tab you viewed and for how long). These events carry your account ID and short labels or counts, but never the free text of your goals, answers, or notes. We use them to understand the activation funnel and improve the product. They are visible only to our admins, and they are removed when you delete your account.
  • Cookieless analytics. Separately, we use aggregate, cookieless analytics and performance metrics (which features are used, page-load speed). Our analytics provider does not use advertising cookies or cross-site identifiers, and this data is aggregated and not used to identify you.
  • Why: to understand which features help and to keep the app fast.
  • Legal basis: our legitimate interest in improving and securing the service, balanced against your privacy.

Diagnostics and error monitoring

  • What: when something goes wrong, we record a technical error report (the error type and message, a trimmed stack trace, and which route it happened on) so we can fix it. Repeated errors are grouped and counted rather than stored over and over. These reports are designed to carry technical detail, not your goal text, and no request bodies or cookies are included. We may also forward a brief alert to an internal channel (for example, a team chat or monitoring tool) when one is configured.
  • Why: to find and fix bugs and keep Tackie reliable and secure.
  • Legal basis: our legitimate interest in a stable, secure service.

Ratings, testimonials, and feedback

  • What: if you choose to rate Tackie or write a testimonial, we store your rating (1 to 5), the testimonial text, and a display name you provide. If you send in-app feedback, a feature request, or a bug report, we store that message tied to your account so we can follow up.
  • Moderation and publishing. Before a testimonial can appear on our public landing page, it passes a moderation step that combines fixed rules with an AI sentiment and profanity check (using our AI provider). A published testimonial, with the display name you chose, is visible to anyone who visits the site. You can change or ask us to remove your testimonial at any time.
  • Why: to share genuine feedback and to improve the product. We do not use feedback for advertising.
  • Legal basis: your consent when you choose to submit, and our legitimate interest in improving Tackie.

Support and the Ranger chatbot

  • What: if you raise a support ticket (including through our Ranger guide), we collect the email address and the message you send so a human can follow up, and we email that to our support inbox. When you type a question to Ranger, the text is sent to our AI provider to generate a product answer; Ranger is scoped to questions about Tackie and does not plan your personal goal or give professional advice.
  • Why: to answer your question and provide support.
  • Legal basis: performance of our contract with you and our legitimate interest in supporting you.

Integration activity log

  • What: when an integration you turned on does something (a calendar sync, a webhook send, a push, or a service email), we log a short record of the event so you can see your integration activity and we can troubleshoot. These records hold the event type, a target label, and a status, not the content sent or any secret.
  • Legal basis: performance of our contract with you and our legitimate interest in a reliable, debuggable service.

Anonymous deletion feedback

  • What: if, when you ask us to delete your account, you choose to tell us why you are leaving, we may keep your reasons and an optional note with no link to your identity (the record carries no user ID and no contact details).
  • Why: to learn and improve. Because it carries no user ID, it is anonymous and is not tied back to you.
  • Legal basis: our legitimate interest in improving the service, using genuinely anonymized input.

Sensitive data and data minimization

Some US state laws (and GDPR / UK GDPR Art. 9) treat certain data as especially sensitive. Our stance is to collect as little of it as possible:

  • We do not ask for sensitive categories.We have no field for race, religion, sexual orientation, precise geolocation, biometric or genetic data, immigration status, or union membership. If any sensitive detail appears, it is only because you chose to write it into a free-text goal or “why”.
  • Location is city-level only, never precise geolocation. Coordinates are used once for a city lookup and then discarded, so we do not hold “precise geolocation” as defined under California and other state laws.
  • We process sensitive data only when reasonably necessary to provide the product you asked for, and we keep sensitive categories to what is strictly necessary. This reflects Maryland’s stricter data-minimization standard (Maryland Online Data Privacy Act), and we apply that minimization for everyone.
  • We do not sell sensitive data, ever, and we do not use it for targeted advertising or for profiling with legal or similarly significant effects.

Consumer health data (Washington My Health My Data Act, Nevada SB370, and similar)

This section deserves its own spotlight, because Tackie lets you write goals in your own words and some of those goals touch on health. We want to be completely straight with you about it.

  • Tackie is a general goal-planning tool, not a health, medical, fitness, or wellness service. We do not diagnose, treat, or monitor any condition, and the app is not designed to collect health information.
  • How health-implicating data can arise here: (1) you might describe a health, fitness, sleep, or weight goal in free text, and (2) our safety system reads your goal and answers to detect signals of self-harm or disordered eating, so it can respond with crisis resources instead of building a plan. That safety check is the one place where Tackie intentionally looks for a health-related state, and it exists to protect you, not to profile you.
  • Our legal basis for any health-implicating data: it is strictly necessary to provide the product and the safety protections you requested when you chose to submit a goal. We do not collect this data on our own initiative; it only reaches us because you wrote a goal in your own words and asked the app to act on it. We pair this with strict data minimization (below) and the safety guardrail so the data is used only to give you what you asked for and to keep you safe.
  • We never sell or share consumer health data.We do not sell it, we do not share it for advertising, and offering a “valid authorization” to sell it is not something we do.
  • No geofencing. We never use geofences around any health facility or anywhere else.
  • Data minimization for health signals.The safety result is used in the moment to decide whether to show supportive resources instead of a plan. We do not build, derive, or persist a lasting “health profile” or health inferences about you beyond what the safety guardrail needs to do its job.
  • Your rights over consumer health data: you can ask us to confirm what consumer health data we have, request its deletion, and withdraw any consent. Email privacy@tackie.io.

If you would rather not have health-related content processed at all, simply do not enter health-related goals; Tackie works fine for everything else.

How we use your information

We use your information strictly to run Tackie:

  • sharpen your vague goal into a clear one and build and adapt your weekly plan;
  • show your climb, progress metrics, streaks, and AI-written reviews;
  • send the reminders and account emails you need;
  • run safety checks that keep the experience supportive (see “A note on sensitive topics”);
  • keep your account secure and prevent abuse;
  • understand aggregate usage to improve the product.

We do not use your goals, plans, or content to build advertising profiles, and we do not use your personal content to train AI models. See “AI processing” next.

AI processing (how the plan gets built)

AI facts at a glance

What it is
Tackie uses AI (Anthropic's Claude) to sharpen goals, build weekly plans, write insights, and answer questions.
It can be wrong
AI can make mistakes, miss things, or confidently make up details that sound right but are not (hallucinations). Always use your own judgment.
Not professional advice
Nothing Tackie generates is medical, mental-health, legal, financial, or other professional advice, or a substitute for a qualified professional.
Not a crisis service
Tackie is not a crisis or emergency service. If you are in danger or in crisis, contact emergency services or a crisis line right away.
Your data
Your goals and answers are sent to our AI provider to generate responses. They are not used to train AI models. See the data sections below.
You stay in control
AI output is a starting point, not an instruction. You decide what to do, and you can edit or ignore anything it produces.

When you ask Tackie to sharpen a goal or build a plan, the relevant text you write (your goal, your “why,” and your answers) is sent to our AI provider, Anthropic (the Claude API), which generates the suggested questions, sharpened goal, tasks, and reports. A separate, lightweight AI safety classifier also reads your goal and answers to check for crisis signals. Anthropic acts as our processor for these calls.

A few honest specifics:

  • Your inputs and outputs are not used to train AI models. Per Anthropic’s commercial / API terms, Anthropic does not train its models on API inputs or outputs.
  • Short retention. Anthropic retains API data only briefly (on the order of about 7 days under its commercial / API terms as of late 2025), and longer only where required to comply with law or enforce policy.
  • Server-side only. Your API requests are made from our servers, never directly from your browser, so the AI key stays protected and your content is not exposed client-side.
  • AI output is a helpful suggestion, not professional advice. Plans are AI-generated and may be incomplete or imperfect. They are not medical, mental-health, or other professional advice. See our Terms of Service for the full disclaimer.

You are interacting with AI (EU AI Act, Art. 50)

Tackie’s questions, sharpened goals, plans, tasks, hints, and reports are generated by artificial intelligence, and we tell you so clearly in the app. AI-generated content in Tackie is produced by an automated system, and we label it as such. (These transparency obligations under the EU AI Act take effect through 2026; we are aligning to them now.)

Automated processing and your role in decisions

  • The AI produces suggestions only. You decide what to do with them, what to keep, and what to act on.
  • Tackie makes no solely automated decisions that produce legal effects or similarly significant effects about you. There is no automated denial of service, pricing, credit, employment, or any comparable decision. Because of this, the profiling and automated-decision-making (ADMT) regimes under GDPR Art. 22 and US state laws (for example, California, Colorado, and Connecticut) do not apply to how Tackie works.

A note on sensitive topics

Tackie includes safety guardrails. If your input suggests self-harm or disordered eating, the app responds with a supportive message and crisis resources (for example, in the US you can call or text 988) instead of building a plan. We designed this to protect wellbeing. Please note Tackie is not a crisis service or a substitute for professional help.

Location, in detail

To suggest resources or weather near you, Tackie can ask your browser for your location. If you allow it:

  • your device’s approximate coordinates are read in your browser and sent once to our server, which calls BigDataCloud (a reverse-geocoding service) to translate the coordinates into a city. We store only the resulting city and country in your profile;
  • the raw coordinates are validated and then immediately discarded on our server, never written to the database;
  • if you already have a city saved, we do not overwrite it;
  • where local weather is shown, an approximate location is sent to Open-Meteo, which states it collects no personal data.

You can decline the browser prompt at any time, and Tackie keeps working with more general suggestions. Because we keep location at the city level (not precise coordinates), it is not treated as “precise geolocation” under California or other state laws.

Integrations and connected services (all opt-in)

Tackie can connect to a few outside services to make your plan easier to live with. Every one of these is opt-in. They stay off until you turn them on, and you can turn them off again whenever you like. Here is exactly what each one does with your data.

Google Calendar (optional sync)

  • What it does:if you connect Google Calendar, Tackie creates and manages a single dedicated calendar named “Tackie” in your Google account and writes your goal’s current-week tasks into it as all-day events. Each event holds the task title, its date, an optional hint, and the title of the goal it belongs to.
  • The minimal access we ask for.We use Google’s narrow calendar.app.created scope, which lets Tackie create and manage only the calendar it made. Tackie cannot see, read, or change your other calendars, meetings, or events. We also read your Google account email (through standard sign-in scopes) only to show you which account is linked.
  • What we store. So we can keep the calendar in sync without asking you to sign in every time, we store a Google refresh token for your account. It is encrypted at rest (AES-256-GCM), so our database only ever holds ciphertext, and we mint short-lived access tokens from it on demand, on our server. We also store the linked account email, the id of the Tackie calendar, and when it last synced.
  • Disconnecting. You can disconnect Google Calendar anytime from Tackie. When you do, we make a best-effort call to revoke the token at Google and delete the Tackie calendar (which removes the events it held), and we delete the stored connection on our side regardless.
  • Governed by Google’s terms.Google LLC processes this calendar data as a sub-processor, and your Google account is governed by Google’s own privacy policy. Tackie’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. We use this access only to provide the calendar-sync feature you turned on, we do not sell it, we do not use it for advertising, and we do not use it to train AI models.

Calendar subscription feed (a secret link)

  • What it does: instead of Google sync, you can turn on a calendar subscription feed. Tackie gives you a private URL containing a long, unguessable token. Any calendar app you point at that URL gets a live, read-only .ics feed of your task titles, their dates, your goal titles, and whether each task is done.
  • Keep the link private. The feed has no password. Anyone who has the URL can read that task and goal info, so treat it like a secret and only put it into calendar apps you trust.
  • You stay in control. You can rotate the token at any time, which instantly breaks any link you shared before, or turn the feed off entirely, after which the URL stops returning your data. The feed exposes only the task and goal details above, never your account, profile, or anything sensitive.

Automation webhooks (IFTTT, Zapier, Make)

  • What it does: you can connect an automation webhook so that when you summit a goal, Tackie sends a small notification to an automation service you choose. Tackie POSTs a short payload (the event name, your goal title, a public summit-certificate URL, and a timestamp) to a webhook URL you set up at IFTTT, Zapier, or Make. This is outbound only: Tackie sends to your automation, it never receives data back through it.
  • You pick the destination, so you own what happens next. Once Tackie sends that payload to the URL you configured, the data is in the hands of that third party (IFTTT, Zapier, or Make) and whatever applet you built, and it is governed by that third party’s terms and privacy policy, not ours. Because you choose where it goes and what it triggers, this routing is your responsibility. You can remove a webhook anytime, which stops any future sends.

Payments (Stripe)

Tackie offers paid plans. When you buy one, the payment is handled by our payment processor, Stripe, Inc.

  • Stripe handles your card, not us. Your card or other payment details are entered into and processed by Stripe (on Stripe-hosted fields). Tackie does not receive or store your full card number, CVC, or similar full payment credentials.
  • What we do receive. To manage your subscription, Stripe shares limited billing metadata with us, for example your subscription status, plan, card brand and last four digits, expiry, and billing country. We use this only to run your plan (start it, renew it, handle failed payments, and let you cancel).
  • Security and PCI-DSS. Card-data security and PCI-DSS compliance are handled by Stripe, a certified payment processor. Your payment information is governed by Stripe’s own privacy policy in addition to this one.
  • How we use it. We do not sell your billing information, we do not use it for advertising, and we do not use it to train AI models.

Cookies and similar technologies (ePrivacy / PECR)

  • Essential cookies: we use the cookies strictly necessary to keep you signed in and your session secure (authentication and security). These do not require consent, but we disclose them here.
  • Baseline analytics: our default usage and performance analytics are cookieless and aggregated; they do not set advertising cookies or cross-site identifiers, and they store nothing on your device for tracking.
  • Analytics cookies (consent-based): if you accept, we use Microsoft Clarity to understand how the app is used through aggregated product analytics, heatmaps, and session replay. Session replay records interactions like clicks, scrolls, and navigation. The text you type into fields is masked(your goal, your answers, your reckon notes, and your password), so what you write is hidden from these recordings and never captured by Clarity. Clarity sets cookies and is loaded only after you opt in via our cookie banner. It is governed by Microsoft’s privacy statement. We do not use it to identify you personally or for advertising.
  • No advertising trackers. We do not use third-party ad-tech, retargeting pixels, or cross-site advertising trackers.

When analytics cookies are in use, we show a cookie consent bannerand load Microsoft Clarity only if you choose “Accept all.” Choosing “Essential only” means no analytics cookies are set and Clarity never loads. Essential authentication cookies are always required for the app to work. You can change your choice by clearing this site’s data in your browser, and in the EU and UK we obtain your consent (ePrivacy/PECR) before setting any non-essential cookies.

Universal opt-out and Global Privacy Control

Some browsers and extensions send a Global Privacy Control (GPC) or other Universal Opt-Out Mechanism (UOOM) signal that asks businesses not to sell or share your personal information or use it for targeted advertising. California requires honoring GPC, and roughly a dozen states require recognizing universal opt-out signals.

  • We honor these signals. When we detect a GPC or comparable opt-out signal, we treat it as a valid request to opt out of sale, sharing, and targeted advertising.
  • In practice this is largely a no-op for Tackie, because we already do not sell your personal information, do not share it for cross-context behavioral advertising, and do not run targeted advertising at all. We honor the signal anyway so your preference is respected.

Who we share data with (service providers)

We do not sell or rent your data. We rely on a short list of trusted providers that process data on our behalf, only to run Tackie, under data processing agreements (GDPR Art. 28) that restrict their use of your data:

ProviderWhat it does for usRoleTransfer mechanism (for EU/UK data)
SupabaseSecure database and authentication (stores your account, goals, and content; row-level security isolates each account).ProcessorStandard Contractual Clauses via DPA (plus UK Addendum). We are evaluating an EU region.
Anthropic (Claude API)The AI that sharpens goals and builds plans from the text you submit, plus the safety classifier. Does not train on your inputs/outputs; ~7-day retention.ProcessorStandard Contractual Clauses via DPA (plus UK Addendum)
VercelHosting, plus cookieless Web Analytics and Speed Insights.ProcessorEU-US Data Privacy Framework (certified), with SCCs as backup
Cloudflare (Turnstile)Bot protection on our sign-in and demo forms. Turnstile processes client signals (IP address, User-Agent, TLS fingerprint, and our site key) only to tell humans from bots and block bot traffic. Per Cloudflare it cannot identify you and does not profile or target individuals. Governed by Cloudflare's Turnstile Privacy Addendum.Processor (protecting our site); Cloudflare is an independent controller when improving TurnstileEU-US Data Privacy Framework (certified), with SCCs as backup
ResendSends our service email (account confirmations, password reset, email-change, the welcome email, and the optional weekly recap) reliably from our domain.ProcessorStandard Contractual Clauses via DPA (plus UK Addendum)
Browser push services (Google, Apple, Mozilla, Microsoft)If you opt in to push notifications, your browser's own push service delivers the notification to your device. We send only to a verified push endpoint on these services. We do not choose your push service; your browser does.Independent service (your browser vendor)Operated by the relevant vendor under its own terms; only the notification content is sent
GoogleIf you choose “Sign in with Google,” Google authenticates you and shares your name, email, and basic profile with us. We do not receive your Google password.Independent service / sub-processorEU-US Data Privacy Framework (certified)
Google LLCGoogle Calendar API (only if you connect it). Tackie writes your task titles, dates, and goal titles into a dedicated “Tackie” calendar using the narrow calendar.app.created scope; it cannot access your other calendars. Our use follows Google’s Limited Use requirements.Sub-processor (calendar sync)EU-US Data Privacy Framework (certified)
Stripe, Inc.Payment processing for paid plans. Stripe handles your card details directly (Stripe-hosted); we never receive or store full card numbers. We receive only limited billing metadata to manage your subscription. PCI-DSS is handled by Stripe.Processor (payments)Standard Contractual Clauses via DPA (plus UK Addendum)
Microsoft ClarityProduct analytics, heatmaps, and session replay, ONLY if you accept analytics cookies. Helps us see how the app is used (clicks, scrolls, time) to improve it; not used to identify you or for advertising.Processor (analytics, consent-based)Standard Contractual Clauses / Microsoft DPA
BigDataCloudTurns coordinates into a city name when you allow location. Called from our server; states it stores no user data.Third-party service / processorCoordinates are not retained by us
Open-MeteoProvides local weather when shown, from approximate location. States it collects no personal data.Third-party serviceNot personal data per provider

We hold data processing agreements with our processors and maintain an internal Record of Processing Activities (GDPR Art. 30) as a matter of practice.

We may also disclose information if required by law (for example, a valid legal request), or to protect the rights, safety, and security of users, the public, or Tackie. If Tackie is ever involved in a merger or acquisition, your data may transfer as part of that transaction, and we will tell you and honor this policy.

What we do not do

  • We do not sell your personal information.
  • We do not share it for cross-context behavioral or targeted advertising.
  • We do not rent, trade, or hand your goals to advertisers.
  • We do not use your personal content to train AI models.
  • We do not profile you to make automated decisions that have legal or similarly significant effects.
  • We do not use minors’ data for targeted advertising, do not sell minors’ data, and do not profile minors for significant decisions.

Your goals are not a product. They are yours.

We are not a data broker

Every Tackie user has a direct relationship with us (you signed up and use the app). We do not buy or sell personal information about people we have no direct relationship with, so we are not a “data broker.” The California Delete Act (DROP) registry does not apply to us.

How your data is protected

  • Data is encrypted in transit and at rest.
  • Every account’s data is isolated at the database level with row-level security, so one person can never reach another’s climb. Your uploaded photos live in your own storage folder, isolated the same way.
  • AI calls run server-side so secrets never reach the browser.
  • You can strengthen sign-in with a passkey (WebAuthn) or two-factor authentication. A passkey’s private key stays on your device and is never shared with us.
  • We keep a write-only security audit trail of sensitive account actions (for example, deletion requests) so we can show that they happened.
  • Sensitive tokens we must store, like a Google Calendar refresh token, are encrypted at rest with strong encryption so our database only holds ciphertext.
  • We use bot protection, rate limiting, and per-user usage caps to defend the service against abuse.
  • Our core providers maintain recognized security standards (for example, SOC 2 and ISO 27001).

If we ever experience a personal-data breach that is likely to put your rights at risk, we will notify the relevant supervisory authority and affected users without undue delay, as required by the law that applies to you (for example, GDPR / UK GDPR and US state breach-notification laws).

No system is perfectly unbreakable, but we treat your trust as load-bearing and design accordingly.

International data transfers

Tackie is operated from the United States, and our providers may process data in the US and other countries. If you are in the EU, UK, or another region with data-transfer rules, we rely on lawful transfer mechanisms so your data stays protected when it crosses borders, named per provider in the table above:

  • EU-US Data Privacy Framework (DPF): where a provider is certified (for example, Vercel and Google).
  • Standard Contractual Clauses (SCCs): in the data processing agreement, where DPF does not apply (for example, Anthropic, Supabase, and Stripe).
  • UK transfers: the SCCs are paired with the UK International Data Transfer Addendum (or IDTA) so the UK leg is covered.

Copies of the relevant safeguards are available on request at privacy@tackie.io. We are also evaluating an EU data region for our database to reduce transfers.

How long we keep your data (retention)

We keep each category only as long as we need it for the purposes above, then delete it. Specific periods:

CategoryRetention period
Account and profile informationFor the life of your account; deleted on the deletion timeline below after you close it
Your content (goals, plans, tasks, progress, reports, certificates)For the life of your account; deleted on the deletion timeline below
Location (city/country)For the life of your account; raw coordinates never retained
Consumer health data / sensitive signalsUsed in the moment for safety; not derived or persisted beyond the safety guardrail
Integration connections (Google Calendar encrypted refresh token, calendar feed token, saved webhook URLs)Only while you keep that integration connected; deleted when you disconnect it or close your account
Push subscriptions (push endpoint and browser-generated keys)Only while push is on for that browser; deleted when you turn it off, unsubscribe, or close your account
Photos and graphics you upload (avatar, completion photos, share graphics)For the life of your account; deleted on the deletion timeline below
Ratings and testimonialsUntil you change or remove them, or we remove them; deleted on account deletion
Feedback and support/chatbot messagesFor the life of your account, plus a short period needed to handle and document the request
First-party usage events (account ID plus labels/counts, never goal text)Tied to your account until deletion, then removed; cookieless analytics stays aggregate only
Error and diagnostic reportsKept in deduplicated, grouped form for triage, then cleared once resolved and stale
Integration activity logA short period for your activity view and troubleshooting; tied to your account and removed on deletion
Security audit trail (sensitive-action records)Retained as a write-only record that an action occurred, intentionally kept even after a purge as proof
Billing metadata (subscription status, card brand/last4, billing country from Stripe)For the life of your paid plan, plus a period needed for tax, accounting, and legal records; full card details are never stored by us
Transactional email recordsFor the life of your account, plus a short period as needed for security and legal records
Cookieless analyticsAggregate, non-identifying form only; not tied to you
Anonymous deletion feedbackKept only in anonymous form, because it carries no identity

We follow data-minimization: we do not retain identifiable personal data longer than we need it for the purposes above or as the law requires.

Deleting your account and data

You can have your Tackie account and the data attached to it deleted whenever you want, right from inside the app. Here is how it works today:

  • Delete it yourself, anytime.Open your profile from the avatar menu, choose “We hate to see you go,” and tap Delete account. You can also email privacy@tackie.io if you prefer we handle it (we will confirm it is really you before acting).
  • You get a 30-day recovery window. Once you delete, your account enters a 30-day grace period during which you can change your mind and recover everything. After 30 days, your personal data is permanently removed from our active systems, which clears your goals, plans, tasks, progress, profile, uploaded photos and graphics, push subscriptions, integration connections, testimonials, and account.
  • Backups roll off on their normal cycle, after which deleted data is overwritten and gone from backups too.
  • A content-free record (no goals, no content, just the fact that a deletion happened and when) may be kept to show we honored your request.
  • Anonymous deletion feedback you chose to give, if any, stays, because it has no link to you.

Prefer a break instead of a goodbye? Use Take a break to pause your climb and pick up right where you left off later, with nothing deleted. Whenever you are ready to delete for good, the self-serve control is always there, or email privacy@tackie.io and we will handle it.

Your rights and choices

Depending on where you live, you have some or all of these rights. We honor them for everyone where we reasonably can.

  • Access / know: get a copy of the personal data we hold about you, and information about how we use it.
  • Correct / update: fix inaccurate data (much of it is editable directly in the app).
  • Delete: delete your account and the data attached to it (see the deletion section above).
  • Portability: receive a copy of your data in a portable, machine-readable format. We provide this on request (email privacy@tackie.io); we fulfill export requests manually rather than through a self-serve in-app download.
  • Object / restrict: object to or restrict certain processing.
  • Withdraw consent: where we rely on consent (such as location or reminders), you can withdraw it at any time without affecting prior processing.
  • Opt out of sale/share/targeted advertising and profiling: not applicable, because we do not do any of these; we state this affirmatively and we honor universal opt-out signals anyway.
  • Non-discrimination: we will not treat you worse for exercising these rights.

How to exercise your rights

Use the controls in the app, or email privacy@tackie.io.

  • Verification: we will verify your request, usually through your existing sign-in or by confirming control of your account email, so we only release data to you.
  • Authorized agents: you may use an authorized agent to submit a request on your behalf. We will ask the agent for proof of your written permission (and may still ask you to verify your own identity and confirm the agent is authorized).
  • Response time: we aim to respond within 45 days for US state-law requests, and we may extend by an additional 45 days when reasonably necessary for complex requests (we will tell you if we need the extra time). For GDPR / UK GDPR, we respond within one month, extendable by up to two further months for complex or numerous requests.
  • Appeals (US): if we deny your request, you may appealby replying to our decision email or writing to privacy@tackie.io with “Privacy Appeal” in the subject. We will review and respond within the time your state allows (generally 45 to 60 days) and explain our reasoning. If you are still unsatisfied, you may contact your state Attorney General(for example, the California Privacy Protection Agency or your state AG’s office).
  • Complain to a regulator (EU / UK): you also have the right to lodge a complaint with a supervisory authority, the ICO in the UK, or your national Data Protection Authority in the EU.

California residents

We do not sell or share your personal information, and we have not in the preceding 12 months. You have the rights to know, access, delete, correct, opt out (a no-op here, as above), limit use of sensitive data, and to non-discrimination described above. We do not collect “precise geolocation” (we keep location at city level). We honor Global Privacy Control. See the “California notice at collection” table near the top for categories, purposes, and retention. To exercise your rights, use the in-app controls or email privacy@tackie.io; to appeal a denial, reply with “Privacy Appeal.” You may also contact the California Privacy Protection Agency or the California Attorney General.

Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Indiana, Tennessee, Minnesota, Maryland, Kentucky, Rhode Island (and other states)

You have the rights to confirm and access, correct, delete, obtain a portable copy, and opt out of sale, targeted advertising, and profiling with legal or significant effects (all no-ops here, as we do none of these). We honor universal opt-out signals. We provide an appealprocess for any denied request (see “How to exercise your rights”), and you may contact your state Attorney General if your appeal is unsuccessful. For Minnesota, Maryland, and California, see the per-category retention table; for Maryland, we apply heightened data minimization (sensitive data only when strictly necessary, and we do not sell sensitive data).

EU / UK residents

We process your data on the lawful bases listed in the table above (mostly contract, with consent for optional features and legitimate interests for security and improvement). For any special category data (Art. 9) that your goals may reveal, see “Consumer health data” for our basis. You have the full set of GDPR / UK GDPR rights listed above, including data portability and the right to complain to a supervisory authority (ICO in the UK; your national DPA in the EU).

Children and teens

Tackie is for users 13 and older and presents a neutral age gate. We ask for date of birth at sign-up to enforce this. How we handle younger and teen users:

  • Under 13 (COPPA):Tackie is not directed to children, and we do not knowingly collect personal information from anyone under 13, so COPPA’s verifiable-parental-consent regime does not apply to us. If we gain actual knowledge that an account belongs to someone under 13, we will delete it promptly. A parent or guardian who believes their under-13 child gave us information can email privacy@tackie.io and we will remove it.
  • Teens 13 to 17: we do notuse minors’ personal data for targeted advertising, we do not sell minors’ data, and we do not profile minors to make decisions with legal or similarly significant effects. (This reflects rules in California and a growing number of states, and the UK Age-Appropriate Design Code.)
  • EU/UK note:the EU’s “digital consent” age for some consent-based processing varies from 13 to 16 by member state, while Tackie’s gate is 13+. Because our core processing relies on contract rather than consent, and Tackie is not child-directed, we believe this is appropriate; we will adjust if a specific member state requires it.

Governing law

This Privacy Policy and our handling of your personal information are governed by the laws of the State of Wyoming, United States, where our operating entity is organized, except where a privacy or data-protection law that applies to you provides you with rights or protections under your own jurisdiction. Nothing here limits rights you have under the laws of your state or country.

Changes to this policy

If this policy changes in a meaningful way, we will update the “Last updated” date at the top and, where appropriate, let you know in the app. Significant changes that affect your rights will be highlighted.

Contact us

Questions, concerns, or a friendly hello? Reach us at privacy@tackie.io. You can also write to us at Pinn.Media LLC, 30 N Gould St #43324, Sheridan, Wyoming 82801, United States. Tackie is proudly built in the USA.

Cloudflare Turnstile Policy

We use Cloudflare Turnstile to tell humans from bots on our forms (see the sub-processors table above). The following is Cloudflare’s Turnstile Privacy Addendum, reproduced here for your convenience. The authoritative version is published and maintained by Cloudflare.

Turnstile Privacy Addendum, last updated June 18, 2025.

1. Introduction

Turnstile, developed by Cloudflare, Inc. (“Cloudflare”), is a pro-privacy website security tool that processes minimal Signals (as defined below) solely to protect web properties against malicious activity by distinguishing human users from bots and blocking bot traffic. Cloudflare does not control whether a website chooses to use Turnstile; instead, it makes Turnstile available to any website that is looking for a way to detect and block bot traffic.

2. Scope of this Addendum

This Turnstile Addendum is supplemental to Cloudflare’s main Privacy Policy. It provides additional information specific to your use and interaction with Turnstile, and also applies to personal data processed using Cloudflare’s Challenge Platform. The Cloudflare Privacy Policy continues to apply except where this Addendum provides more specific information, in which case the more specific information applies instead.

3. Information We Collect

Cloudflare Turnstile processes a variety of client-side signals (“Signals”) such as client IP address, TLS fingerprint, User-Agent header, and Sitekey and associated origin. Cloudflare does not have the ability to directly identify any individuals from any of the Signals Turnstile collects, including IP addresses.

4. How We Use Information We Collect

Bot detection and blocking. Turnstile protects web properties by distinguishing human users from bots and blocking detected bot traffic. It evaluates the Signals above, specific to both the visitor and the website visited. The purpose is not to identify, profile, or target individuals but solely to detect and block bots, and the Signals are strictly necessary for that purpose. Cloudflare is a data processor of these Signals, processing them on behalf of and pursuant to the instructions of its website-operator customers (the controllers). For questions, or to exercise data-protection rights regarding this processing, please contact the relevant website operator.

Improving Turnstile. Cloudflare also processes these Signals to refine and improve its bot-detection algorithms in response to evolving bot threats and to maintain the security of the web properties visitors choose to visit. For this purpose Cloudflare is a data controller, governed by its Turnstile Privacy Notice together with its main Privacy Policy.

5. Notice to EU and UK Residents

To the extent the data described qualifies as personal data: when processing it as a processor to protect customers’ websites, Cloudflare’s customers, as controllers, determine the lawful basis, and Cloudflare processes the data under their instruction and on their behalf; and when processing it as a controller, Cloudflare relies on its legitimate interests in improving the effectiveness of Turnstile’s bot-detection capabilities.

6. Cookies

The Signals collected by Turnstile are strictly necessary for detecting and blocking bots so visitors can enjoy a safe and secure experience on websites that have implemented Turnstile. For more information about the cookies used by Cloudflare, see Cloudflare’s Cookie Policy and the Turnstile Developer Docs.

Contact for privacy concerns

If you have questions or concerns about the Turnstile Privacy Notice or your personal data processed through Turnstile, please contact Cloudflare’s Data Protection Officer at dpo@cloudflare.com.

Questions, concerns, or a friendly hello? Reach us at hello@tackie.io or support@tackie.io. Tackie is proudly developed in the USA .