Privacy
Last updated: October 2026
The short version
This website sets no cookies for us, runs no scripts and asks you for nothing. It counts its visits without recording who made them. The Spinther app has no account and no sign-in, and it collects nothing about you unless you turn usage data on. Your tasks live on your iPhone and sync through your own iCloud, end-to-end encrypted. We cannot see any of it.
The rest of this page explains that in the detail the GDPR asks for.
Who is responsible
The data controller is Spinther, at:
Tegnérgatan 36113 59 Stockholm
Sweden
For any privacy question or request, email hello@spinther.app.
We have not appointed a Data Protection Officer under Art. 37 GDPR: we are not a public authority, and our core activities involve neither large-scale systematic monitoring nor large-scale processing of special categories of data. We are established in Sweden, and therefore in the European Union, so no Art. 27 representative is required.
This website
spinther.app is a set of pages served by a Cloudflare Worker. It
sets no cookies of ours and stores nothing of ours in your
browser. On this website there is no analytics script, no session recording,
no tag manager and no advertising technology of any kind, so there is no
consent banner.
The site does count its visits, on the server, as each page is served. A
count records which page was opened, the name of the site that linked to it
if your browser passed one on (the domain only, such as
reddit.com), and whether you arrived from somewhere else or
moved between our pages. That is all. It records nothing about you: not your
IP address, not your browser or device, and no identifier, so one page view
cannot be connected to another or to a person. Automated requests and link
previews are left out. Once a week the totals (visits, page views and the
most common referring domains) are added to our records in PostHog, next to
the app’s usage counts.
No page loads a script, and nothing is fetched from any other domain. The site has no forms: to reach us, you write to hello@spinther.app from your own email.
Serving the site necessarily involves your IP address and request metadata reaching Cloudflare, who host it. That is ordinary web delivery, described under processors and retention below.
The app: what it stores, and where
Spinther’s App Store privacy label declares two items, both belonging to the optional usage data described below: Product Interaction (the usage counts) and Device ID (the random installation identifier that comes with them). Both are marked as not linked to you and not used to track you, and every other category is Data Not Collected. Concretely:
| What | Where it lives |
|---|---|
| Tasks, projects, notes, ideas and reminders | On your iPhone, and mirrored to your own private iCloud database. Every field holding your content is end-to-end encrypted. |
| Dictation audio | Transcribed on the device as you speak. The audio is never written to a file and never uploaded. The text it becomes is kept with your tasks and ideas, like anything you type. |
| Calendar events and Apple Reminders | Read on your device only, with your permission, and only to display or import them. Never copied to us. |
| Your preferences | On your iPhone, with some synced through your own iCloud so your devices agree. |
| Diagnostic logs | Apple’s on-device logging only, with your content marked private so it is redacted. Nothing is sent anywhere. There is no crash or performance SDK. |
Two sort timestamps are stored unencrypted, because iCloud cannot order encrypted columns and the default lists sort on them. They are timestamps, not content. Everything you actually type is encrypted.
Because this data sits in your iCloud account rather than on our servers, we have no access to it, no ability to recover it for you, and no way to produce it in response to a request — from you or from anyone else. Deleting the app and its iCloud data removes it.
Usage data, if you turn it on
Usage data is off until you turn it on. Spinther can send basic usage counts: things like how often you capture a task or idea and which features get used. No personal information, and never the content of your tasks, notes or ideas. Nothing is sent unless you say yes, and you can change your mind in Settings any time.
The counts go to PostHog, an analytics service, on its European servers in Frankfurt, Germany. Spinther talks to it directly rather than through PostHog’s own software kit, so a count contains what is listed here and nothing that a kit would add:
- What happened, as a name from a fixed list (a task was captured, an import finished), with details that are choices from fixed lists, numbers, durations or yes/no answers: whether it was a task or an idea, whether it was typed, dictated, shared in or came through Siri or a shortcut, which part of the app it came from, which sitting it was saved in — a running number for each time you open a capture sheet or dictate and save something, add a task or idea with the share sheet’s quick buttons, create one through Siri or a shortcut, or speak into the Dictate control, so several things saved in one go can be told from several separate visits — and how many items an import brought in. There is no free text in a count, so nothing you type or say can be in one.
- Your major iOS version, the kind of iPhone and the build of Spinther: standard, Pro or foldable, or “unknown” for a model Spinther does not recognise, but not the model itself; and the build number of the copy of Spinther that sent the count, so a count can be read against the version of the app that made it.
- On two of the counts, a short summary of how the app is set up: whether you have imported from another app and which one, and how many projects you have created. A number and an app name, not the names of your projects.
- A random identifier for your installation, so one installation’s counts can be told apart from another’s. It is made up at random on your iPhone after you say yes, it is derived from nothing about you or your device, and it is scrambled (SHA-256) before it leaves. Spinther also tells PostHog not to build any profile behind that identifier, so there is no record there that gathers up one installation’s counts into a person. This identifier is why we say “no personal information” rather than “anonymous”.
What happens to the time before you agree. A new installation of Spinther keeps a small tally on your iPhone of how its first week went: how many things you captured in your first session — the first seven minutes after you first open Spinther — and how quickly the first three came, whether any of those captures came from outside the app (Siri or a shortcut, the share sheet, a widget, a control or the app icon’s quick actions), whether any of them was dictated, and whether you captured something on three of your first seven days. Not tied to that first week, it also notes which way of capturing you reach for first, whenever that is, and whether Spinther has full access to your calendars at the moment you say yes. Spinther also keeps a second, smaller tally from your first capture on: how many capture sessions you have had — each time you open a capture sheet or dictate and save something, add a task or idea with the share sheet’s quick buttons, create one through Siri or a shortcut, or speak into the Dictate control counts once — which sitting is in progress, and when you last saved something. That is how Spinther knows when to ask you the question, which it does after the fifth session. Separately, Spinther notes which app you first imported from, if any. While usage data is off, all of that stays on your iPhone. If you turn usage data on, the first-week tally goes with your yes, once, as a summary, along with how long it had been since you first opened the app, whether you had already reached the first of the two milestones below, and — where a time for it was recorded — how long that took; and the import note becomes part of the short summary described above. The session tally is never sent as such; from then on each count of a capture carries the number of the sitting it belongs to, and that numbering carries on from the sittings before you agreed rather than starting again at one. If either tally shows you had already captured something earlier that same day, one more count goes with your yes, saying that day was a day you captured on — unless that day has already been counted. Those two milestones draw on the first-week tally if you reach them after saying yes: three captures in the first session with at least one dictated or made from outside the app, and capturing on a third day in the first week. Each is sent as one count with its totals. There is no log of your individual actions waiting to be sent, and what you did before agreeing is never sent action by action. If your copy of Spinther was updated from a version that kept no first-week tally, there is none to send; the session tally starts with your first capture on the new version.
Once you have said yes, turning usage data off sends one last count, recording that it was turned off, and then nothing more. It keeps the random identifier on your iPhone, so turning it back on continues as the same installation. Erase All Data and Settings removes the identifier, your choice and everything else Spinther keeps for usage data, both tallies and the import note included, after which the installation counts as a new one. The app behaves identically whether usage data is on or off.
Your yes or no is also kept in your iPhone’s keychain, which iOS normally keeps even after an app is deleted. It holds that one answer, when it was recorded and which version of what Spinther sends it covered, and nothing else; it never reaches us, and it cannot move to a new iPhone or to your other devices. If you install Spinther again on the same iPhone, it picks up your answer: after a no, we don’t ask again; after a yes, Spinther first tells you that usage data is on and lets you turn it off there and then, and only after that starts again, under a new random identifier that is not linked to the old one. If what Spinther sends has changed since you said yes, or your yes is more than a year old, it asks you again instead, and a yes given on a version of Spinther that did not yet keep this copy is not kept at all. Erase All Data and Settings deletes the kept answer too. Deleting Spinther on its own does not: the answer is on your iPhone, not with us, so we cannot remove it. To clear it, install Spinther again and use Erase All Data and Settings, or erase your iPhone and set it up as new.
Like any request over the internet, each count reaches PostHog from your connection’s IP address. Spinther tells PostHog, with every single count, not to work out a location from that address, and the project is set so the address itself is not stored. The counts held from Spinther carry no country and no other location.
When the app connects to the internet
Spinther itself reaches the network on four occasions. iCloud sync runs by itself while you are signed in to iCloud, two are things you start, sending usage counts happens only if you have agreed to it, and none of them sends your content to us:
- iCloud sync — between your iPhone and your own Apple Account. Apple is your provider here, not ours.
-
Importing from or exporting to Todoist — only when
you start an import or an export. Spinther signs in to your Todoist
account using PKCE with no client secret, and never stores the access token.
An import reads your tasks, which travel from Todoist to your device. An
export sends the workspaces you choose — their names, their
projects’ names and their open tasks’ titles, notes,
priorities, due dates and repeats — from your device to your Todoist
account. Either way we receive none of it. One
caveat worth stating plainly: Todoist’s consent screen loads our name
and logo from
spinther.app, so at that moment your browser contacts this site, exactly as described under “This website” above. - Sharing a web link into the app — Spinther fetches that page’s title, from that page’s own site, so it can name the task sensibly. Title only, and it falls back silently if the site does not answer.
- Sending usage counts to PostHog — only if you have turned usage data on, and never including anything you have typed. It is off by default, and one switch in Settings turns it off again.
Separately, the first time you dictate, iOS may download its own speech model. That is Apple’s asset pipeline, requested by the operating system rather than by Spinther, and nothing about it reaches us.
Permissions the app may ask for
Each is optional and revocable at any time in iOS Settings: microphone (dictation), notifications (reminders), calendar (read-only, to show your events), reminders (to import them) and alarms (for escalated reminders).
Spinther asks when you first use the feature that needs it. The one exception is reinstalling the app onto a device that already holds your iCloud data, where notifications and calendar are requested up front so your existing reminders keep working.
Spinther never requests location. There is no location code anywhere in the app.
Legal bases
We process personal data only where Art. 6(1) GDPR gives us a lawful basis. There is very little to process:
| Purpose | Data | Basis |
|---|---|---|
| Answering your email, including privacy requests and beta enquiries | Your email address and whatever you write to us | Legal obligation — Art. 6(1)(c) for rights requests under Art. 12–22; legitimate interests — Art. 6(1)(f) for ordinary correspondence |
| Basic usage counts from the app | Everything listed under “Usage data, if you turn it on”: usage counts, your major iOS version, kind of iPhone and build of Spinther, the short set-up summary (imports and number of projects), the first-week tally sent with your yes, the sitting number on each capture count, and a scrambled random installation identifier; never your content | Consent — Art. 6(1)(a), off unless you turn it on, withdrawable in Settings at any time |
| Serving and securing this website | IP address, request metadata, technical logs | Legitimate interests — Art. 6(1)(f) in operating and protecting the site; strictly necessary to deliver the page you asked for |
| Counting visits to this website | Read from the request as the page is served, then discarded: the referring site, whether your browser says it is opening a page, and your browser’s name, used only to leave out automated requests. Kept: the page, the referring domain and whether it was a new visit, with nothing that identifies you | Legitimate interests — Art. 6(1)(f) in knowing whether anyone reads the site and how they found it |
Legitimate interests assessment. For site delivery and security our interest is in keeping the site available and protected from abuse. No less intrusive means achieves this, the data involved is limited to connection metadata, it is never used for advertising or profiling, it is kept briefly, and it does not override your rights. For counting visits, our interest is in knowing whether the site is read at all; the count is taken from the request we already have to answer, nothing is read from your device, and what is kept cannot be traced back to you. You may object at any time under Art. 21 by writing to us.
Nothing here relies on consent except the one thing that asks for it in so many words: usage data in the app. It is opt-in, it can be withdrawn at any time, and withdrawing costs you nothing.
Processors
We use three processors. Cloudflare and PostHog each act under a data processing agreement and only on our documented instructions. Apple holds our email under its standard iCloud terms, and we have no separate data processing agreement with Apple.
| Processor | Purpose | Transfer safeguard |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN and TLS for this website, and storing its visit counts | Global edge including the US. EU–US Data Privacy Framework; EU Standard Contractual Clauses and the UK IDTA where the Framework does not apply |
| PostHog, Inc. | Receiving and storing the app’s usage counts, only from people who have turned usage data on, and this website’s weekly visit totals. PostHog uses its own suppliers to run the service, listed at posthog.com/subprocessors; the storage itself is in Germany | The counts are held on PostHog’s European servers in Frankfurt, Germany. PostHog is established in the United States, so where it needs access from outside Europe we rely on the EU Standard Contractual Clauses in its data processing agreement, which we signed on 21 September 2026 |
| Apple | Receiving and storing our email correspondence with you at
spinther.app, in an iCloud Mail mailbox |
Apple says it generally stores personal data with Apple Inc. in the United States, and relies on the EU Standard Contractual Clauses for transfers out of the European Economic Area, the United Kingdom and Switzerland. These are Apple’s own arrangements, described in its privacy policy, not an agreement we have signed |
Apple’s other roles
Apart from holding our email, two things happen through Apple, and neither is a processor relationship, so neither belongs in the table above:
- Distributing the app, through the App Store and TestFlight. Apple acts as an independent controller for that under its own terms, not on our instructions.
- Syncing your tasks through iCloud. That happens inside your own Apple Account, under your agreement with Apple. We never see it, and we could not instruct anyone about it.
We will update this section before engaging any new processor.
International transfers
Cloudflare is established in the United States and serves this site from a global edge network, so your connection metadata may be handled outside the European Economic Area, the United Kingdom and Switzerland. For those transfers we rely on the EU–US Data Privacy Framework where the recipient is certified, and otherwise on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2), with the UK International Data Transfer Addendum for UK transfers and the Swiss addendum under the revised FADP. You can request a copy of the relevant safeguards by emailing us.
The app’s usage counts are held on PostHog’s European servers in Frankfurt. PostHog itself is established in the United States, so for any access from outside Europe we rely on the EU Standard Contractual Clauses in its data processing agreement, with the UK Addendum and the Swiss addendum where those apply. PostHog also uses its own suppliers to run the service, which it lists at posthog.com/subprocessors.
Our email correspondence with you at spinther.app is kept in an
iCloud Mail mailbox. Apple says it generally stores personal data with Apple
Inc. in the United States, and that it relies on the EU Standard Contractual
Clauses for transfers of personal data out of the European Economic Area,
the United Kingdom and Switzerland. Those are Apple’s own
arrangements, and we have no separate agreement with Apple about them. Apple
describes them in its privacy policy at
apple.com/legal/privacy.
How long we keep things
| Data | Kept for |
|---|---|
| Email correspondence, including privacy requests | Up to 24 months after the exchange ends, then deleted, unless it is needed for a legal claim |
| Cloudflare request and security logs | Retained briefly by Cloudflare under their own rotation, and never copied into any store of ours |
| Visit counts for this website | Three months, then deleted by Cloudflare. The weekly totals made from them are kept in PostHog alongside the app’s usage counts. Neither holds anything that identifies a visitor |
| Usage counts, if you turned usage data on | Kept by PostHog, which guarantees to hold them for a year on the plan we are on and names no date for deleting them after that. We would rather tell you that than promise a shorter period we cannot enforce — the period is set by the plan and cannot be shortened by us. The counts carry nothing that names or contacts you, and turning usage data off stops new ones at any time |
| Your usage-data answer, kept on your iPhone | Until you remove it with Erase All Data and Settings, or erase your iPhone and set it up as new. It never reaches us, so we cannot delete it for you |
| Your tasks and everything you write in the app | For as long as you keep them. They are in your iCloud, not ours, so only you can delete them — the app’s Erase All Data and Settings does exactly that |
Your rights
Under the GDPR and UK GDPR you may request access to your personal data (Art. 15), correction of it (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and portability (Art. 20), and you may object to processing based on legitimate interests (Art. 21).
Where we rely on consent — usage data in the app — you may withdraw it at any time under Art. 7(3), with the switch in Settings. Withdrawing is as easy as giving it and costs you nothing. Deleting the app does not withdraw a yes by itself; the switch in Settings, or Erase All Data and Settings, does.
In practice the personal data we hold is the correspondence you have sent us. Email hello@spinther.app and we will respond within one month, as Art. 12(3) requires.
Usage counts are the exception, and the reason is structural. They arrive under a scrambled random identifier and with nothing else that points to a person, and Spinther tells PostHog not to build any profile behind that identifier — so there is no record there to look anything up by. We cannot tell which counts came from your installation, and cannot look them up, correct them or delete them for one person (Art. 11). What you control is on your iPhone: the switch in Settings stops the counts, and Erase All Data and Settings discards the identifier.
Children
Spinther is intended for adults. We do not knowingly process personal data from children under 16. If you believe a child has sent us personal data, write to us and we will delete it.
Automated decision-making
There is none. We carry out no automated decision-making, and no profiling, producing legal or similarly significant effects (Art. 22). Usage counts are read in aggregate, to see how the app is used; nothing in the app or for you changes because of them. The app contains no AI or machine-learning model that evaluates you in any way.
Security
Everything is served over HTTPS. Your content in the app is end-to-end encrypted in iCloud. The app has no server of ours to breach, no account database and no third-party SDK, which removes most of the surface a notice like this usually has to account for. The one store of app data outside your iPhone and your iCloud is the usage counts held by PostHog, and only for people who turned usage data on. Access to the little we do hold is limited and multi-factor protected.
No system is perfectly secure. If you believe you have found a security issue, please email hello@spinther.app.
In the unlikely event of a personal data breach likely to risk your rights and freedoms, we will notify the supervisory authority without undue delay and within 72 hours where feasible (Art. 33), and notify you directly where the risk to you is high (Art. 34).
Changes
We may update this notice as the product changes. The date at the top always shows when the current version took effect. If a change materially affects how we handle your data, we will say so prominently here before it takes effect.
Complaints
If you think our processing infringes the GDPR you may lodge a complaint with a supervisory authority (Art. 77) — in the EU or EEA state where you live, where you work, or where the issue arose. Our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY); in the UK it is the Information Commissioner’s Office. We would genuinely rather hear from you first, if you are willing.