Open navigation
Legal
Privacy Policy
Tockli is a task board with a focus timer built in. This policy explains exactly what the product stores, why it stores it, and how to get it back or get rid of it.
Last updated
Analytics is optional. Tockli asks before sending product analytics to PostHog. Declining does not change how the product works, and you can change your choice at any time using the Analytics settings button.
Who is responsible for your data
Tockli is an independent product built and operated from the United Kingdom. For the purposes of UK GDPR, Tockli is the data controller for the information described below. You can reach the operator at [email protected].
Signing in
Authentication is handled by Supabase Auth. You can create an account with an email address and password, or sign in with Google. Tockli never sees or stores your password: Supabase stores a hash of it, and Google sign-in never sends a password to us at all.
If you sign in with Google, Google shares your email address, name, and profile picture URL with Tockli so an account can be created. Nothing else is requested from your Google account, and Tockli does not read your Google Calendar, Drive, or contacts.
What Tockli stores, and why
Everything below lives in the product database so your board and your history are there when you sign back in.
- Your profile. Email address, display name, avatar URL, and which plan you are on. Used to identify your account and show you as the owner of your work.
- Projects and boards. Project names, descriptions, colours, and your board columns.
- Sharing. If you invite someone to a project, Tockli stores the email address you invited, the role you gave them, an invitation token, and whether the invitation is pending, accepted, or revoked. Invitations expire after 14 days.
- Tasks and their detail. Task titles, notes, status, priority, time estimates, time spent, due labels, plus your categories, tags, subtasks, and comments.
- Focus sessions. When you finish a session, Tockli records the length in minutes, the project and task it belonged to, when it finished, and the session note you wrote.
- Cancelled sessions. If you stop a timer early, Tockli records the planned length, how long you actually ran, a reason chosen from a fixed list (interrupted, wrong task, needed a break, or other), and an optional note. This is what makes the focus score and the interruption patterns meaningful.
- Settings. Focus and break lengths, your daily session goal, working days, strict mode, sound choice and volume, and light or dark theme.
- Marketing signups. If you sign up from the landing page, Tockli stores the email address you gave, the role and intent you selected, where you arrived from, and which landing-page variant you saw.
Session notes and task notes are free text
Session notes, task notes, comments, and cancellation notes are written by you and stored as you typed them. Tockli does not parse them, scan them, or use them to build a profile of you. Because they are free text, please do not put passwords, financial details, health information, or anything else sensitive into them.
Where your data is stored
Tockli uses Supabase for authentication and database storage. Your data sits in a Postgres database protected by row-level security policies, so a signed-in account can only read and write its own rows and the rows of projects it has been given access to.
The website and application are hosted on Netlify. Netlify processes standard server request data such as IP address and user agent in order to serve pages and protect against abuse.
Supabase, Netlify, PostHog (only if you allow analytics), and Google (only if you use Google sign-in) act as processors for Tockli. Data may be processed outside the UK by these providers under the appropriate transfer safeguards in their data processing terms.
Cookies and local storage
Tockli does not use advertising cookies and does not sell data to anyone.
- Supabase authentication. Signing in stores a session token in your browser so you stay signed in. Signing out clears it. This is strictly necessary for the product to work.
tockli.analytics.consent. Your Allow or Decline choice, held in local storage so Tockli can remember it. Analytics does not start while no choice has been made.tockli.experiments. Which sign-up experiment variant you were assigned, held in local storage so it does not change between visits.
Earlier builds used the keys flowtimer.analytics.anonymousId and flowtimer.experiments. Old anonymous analytics identifiers are deleted. Experiment assignments are moved to the current key and the old key is deleted.
Clearing your browser storage removes all of the above and signs you out. Analytics then stays off until you make a new choice.
Product analytics
If you allow analytics, Tockli sends named product actions to a PostHog project hosted in the EU. These actions include page views, sign-up and login steps, task and timer actions, Focus Score views, and calls to action. Each event can include its time, the route path without its query string, and basic browser or device information. Before sign-in, a random identifier exists only in memory. After sign-in, Tockli may use your opaque Supabase account ID so a product journey can be understood across devices.
Tockli does not send PostHog your email address, display name, task text, goals, project descriptions, project IDs, or session notes. Cookies, persistent browser identity, automatic click capture, session recordings, exception and performance capture, and precise location enrichment are disabled. Do Not Track and Global Privacy Control signals override an earlier Allow choice.
You can withdraw consent at any time through Analytics settings. Tockli then stops collection, clears the analytics identity in the current browser, and asks PostHog to opt that browser out.
Our legal bases
Tockli relies on performance of a contract to run your account, store your boards, and keep your focus history. It relies on legitimate interests to keep the service secure and to prevent abuse. Optional PostHog product analytics is based on consent, which is requested before any analytics is sent and can be withdrawn at any time.
How long data is kept
Your account data, boards, tasks, and focus history are kept for as long as your account exists, because the point of the focus history is that it accumulates.
Deleting a task or project also removes records attached to it where the database relationship is configured to cascade. Pending invitations expire after 14 days. To close your account and request deletion of the remaining account data, use the contact address below. Backup copies may remain for a limited period until the provider's normal backup cycle rolls over, or where retention is required by law.
PostHog product analytics is kept for no more than 12 months. Your consent choice remains in your browser until you change it or clear browser storage.
Your rights
Under UK GDPR you have the right to access your data, to correct it, to have it erased, to receive a portable copy, to restrict or object to processing, and to withdraw any consent you have given. You can do a lot of this yourself from within the app by editing or deleting your content.
For anything else, including a full export or a full deletion, email [email protected] from the address on your account. Requests are answered within 30 days.
If you are not happy with how a request was handled, you can complain to the Information Commissioner's Office, the UK supervisory authority, at ico.org.uk.
Children
Tockli is not intended for children under 13, and accounts should not be created for them.
Changes to this policy
When this policy changes in a way that affects what is collected or who it is shared with, the date at the top will be updated and the change will be noted on the blog. Continuing to use Tockli after an update means the updated policy applies. The terms of service cover the rest of the relationship.