CheckMate · Legal

Privacy Policy

Effective date: July 27, 2026
App: Checkmate ("CheckMate: Priority-Planner") — iOS
Provider / contact: John Halaka — privacy@checkmatepriorities.com

Plain-English summary: Your tasks live on your device. We don't run ads, we don't track you across apps, and we never sell your data. The smart features — scanning a list, voice-to-task, AI subtask suggestions, and routine suggestions — run entirely on your phone. Data leaves your device only when you choose to: when you share a list with other people; if you connect a calendar for two-way sync (then the tasks you sync — their title, time, and notes — go to that calendar and to our sync server); and anonymous crash reports that help us fix bugs. You can disconnect or delete everything at any time.


1. What the app stores on your device

  • Your tasks — titles, notes, priority, due dates, reminder times, recurrence, subtasks, tags, and completion state — are stored in a local database (SQLite) on your device.
  • Attachments — any image or file you attach to a task is stored on your device only. Attachments are not uploaded to us, and are not shared with other members of a shared group, even if the task itself is in a shared list.
  • App settings — theme, premium/trial status, streaks, routine suggestions, and similar preferences — are stored locally on your device.
  • None of this is sent to us or to any third party unless a specific feature below says so.
  • This data is removed when you delete the app, or via Settings → Delete all tasks.

2. On-device processing — nothing is sent to us

Several features that might look like "cloud" features actually run entirely on your phone:

  • Scan to Add (camera). When you scan a handwritten or printed list, the photo is processed on your device using on-device text recognition. The image is not uploaded anywhere and is removed after the text is read.
  • Voice to Task (iOS). Speech recognition runs on your device. Your audio is not sent to us, and Checkmate requests on-device recognition so your speech is not sent to Apple's servers either.
  • AI suggestions. Subtask and task-breakdown suggestions are generated on your device — using Apple's on-device model where available, or a built-in rules engine otherwise. Your task text is not sent to us, to any AI provider, or to any external server. There is no account, API key, or cloud model involved.
  • Routine suggestions. If you turn on routine suggestions, Checkmate looks for patterns in your own task history and, if you allow calendar access, in the events already on your device's calendar, to suggest tasks you tend to repeat. This analysis runs entirely on your device; the results (suggested routines) are stored locally and are not sent to us or to any third party. Routine suggestions are opt-in, you can turn them off at any time, and the derived suggestions are kept only about 90 days before aging out.

3. Data that leaves your device — only if you choose to

Checkmate works fully offline with no account. The following are the only ways your content can leave your device, and each is something you choose to do.

a) Optional account & shared lists. To connect an account or use shared lists, the app talks to a server we operate (a Cloudflare Worker). When you do this we store a randomly-generated session token, an optional display name, and the device identifier, IP address and device type used to create the session (for authentication, security, and rate-limiting); these last technical details are kept for about 90 days. If you create or join a shared list (a group of up to 7 people — you plus up to 6 others), the tasks in that list (titles, priorities, notes, subtasks, order, and completion state) and the display name you choose for the group are stored on our server so the people you share with can see them. Anything you put in a shared list is visible to the other members of that group — treat it like anything else you share with a group of people. Tasks that aren't in a shared list never leave your device. (Attachments are never uploaded — see Section 1.)

b) Adding events to your device calendar. If you add a task to your device's calendar, the event (title, notes, time) is written to your device's Calendar app. If your device is set to sync that calendar to iCloud, Google, or Outlook, the event will appear there through your device's own sync. Reading from your calendar (to import events, or to suggest routines — Section 2) happens locally on your device.

c) Two-way calendar sync — optional, and only if you connect an account. If you connect a calendar account (currently Google Calendar) to keep your tasks and your calendar in sync automatically, the following applies for as long as that account stays connected:

  • What you authorize. You sign in with Google and grant Checkmate permission to view and edit events on your Google Calendar (Google's calendar.events scope), and to see your basic Google profile — your name and email address — so we can identify the connected account.
  • What leaves your device (to our sync server). For each task you choose to sync, we send its title, notes, date and time, all-day setting, priority, and completion/deletion status to a server we operate (a Cloudflare Worker) so it can be kept in sync. Tasks you don't sync never leave your device.
  • What we send to Google. From that server we create and update an event on your primary Google Calendar containing the task's title, notes, and start/end time. (Your priority and completion status are not sent to Google.)
  • What we read from Google. We read events on your primary Google Calendar (their titles, notes, and times, within roughly the last 30 days to the next 12 months) so that changes you make in Google Calendar flow back to your tasks.
  • The connection token is stored on our server. So that sync can run in the background, Google gives our server a token that lets Checkmate access your calendar. This token is stored on our server (Cloudflare), encrypted at rest, and is never sent to or stored on your device. We also store your Google account email, the task fields listed above, and a private mapping between each task and its calendar event.
  • You stay in control. You can disconnect at any time in the app (calendar sync → Disconnect). Disconnecting deletes the stored connection and the synced task data from our server and asks Google to revoke the token. You can also remove Checkmate's access directly, at any time, from your Google Account's "Third-party apps & services" settings.

If we ever add another calendar provider, we will describe how that provider's data is handled and, where required, ask for your consent before you connect it.

d) Quick links. If you tap "Add to Google Calendar" or "Send to Teams," your device opens that service with the task title included in the link. That happens only when you tap.

Google API Limited Use. Checkmate's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to provide and improve the calendar-sync features you see in the app. We do not use it for advertising; we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models; we do not sell or transfer it to third parties, other than our hosting provider (Cloudflare) to operate the feature or where the law requires; and we do not allow humans to read it except with your consent, for security or abuse investigations, or where the law requires.

Except for the Google account name and email you provide by connecting Google Calendar, we do not collect your name, email, contacts, location, photo library, or device identifiers for advertising.

4. Crash reporting, purchases & infrastructure

  • Sentry — receives anonymous crash and error reports from production builds so we can fix bugs. These contain technical details (device model, OS version, error information) but not your tasks, and no advertising identifiers. Crash reports are retained for about 90 days. See sentry.io/privacy.
  • Apple / RevenueCat — process in-app purchases and subscriptions and manage your premium entitlement. We never see your payment details.
  • Google — if you connect Google Calendar, Google processes your sign-in and calendar data through Google Sign-In and the Google Calendar API to provide that feature. See policies.google.com/privacy.
  • Cloudflare — hosts the server (the Worker, its database, and key-value store) used for the optional account, shared-list, and calendar-sync features — including the encrypted calendar connection tokens and the synced task data described in Section 3.
  • Expo (EAS) — build and over-the-air-update infrastructure; receives basic device and app-version information to deliver updates.

We don't control these companies' practices; this policy covers what we do with your data.

5. What we don't do

  • No ads.
  • No advertising SDKs and no cross-app tracking. We don't build advertising profiles and we don't track you across apps or websites. We use crash reporting (Sentry) only to fix bugs.
  • No selling or renting of personal data — ever.
  • No "engagement" manipulation — no guilt notifications.

6. Permissions we ask for

Each permission is used only for the feature it names, and only when you use that feature:

  • Camera — to scan a printed or handwritten list (Scan to Add).
  • Microphone & Speech Recognition — to turn what you say into a task (Voice to Task).
  • Calendar — to add task events to your device calendar, import events from it, and (if you enable routine suggestions) look for repeating patterns in it — all on your device.
  • Photos — so you can attach an image to a task (stored on your device only).

Connecting a calendar account for two-way sync (Section 3c) is done through the provider's own sign-in (for example, Google Sign-In) and is separate from your device's Calendar permission.

7. Age requirement & children

Checkmate is intended for people 13 and older, and the App Store age rating reflects this. When you set up an account or a shared list, we ask for your age in a neutral way; if you tell us you are under 13, we do not let you create an account. We do not knowingly collect personal information from children under 13. If we learn that we have collected such information, we will delete it. (You can still use the app's offline, on-device features without an account.)

8. Shared lists & reporting

Shared lists let a small group (up to 7 people) see and edit the same tasks. You are responsible for the content you add to a shared list, and our Community Guidelines and Terms of Service apply. If someone shares content that violates them, you can report the content or block the person from within the app; reports come to us at support@checkmatepriorities.com and we review and act on them. See also our Copyright / DMCA Policy for infringement notices.

9. Security

Data sent to our server travels over HTTPS. The access tokens for a connected calendar account are encrypted at rest on our server. Session tokens are stored on your device in the OS secure storage (Keychain / Keystore). No method of storage or transmission is 100% secure, but we keep the amount of data we hold to the minimum needed for the optional features above.

10. How long we keep data

  • Tasks & settings stay on your device until you delete them or delete the app.
  • Account, shared-list, and technical-session data (session token, display name, and — for about 90 days — device identifier/IP/device type) is kept on our server until you delete your account, or leave or delete the shared list.
  • Connected-calendar data — the encrypted token, the synced task fields, and the task-to-event mappings — is kept only while the account stays connected, and is deleted from our server when you disconnect the calendar or delete your account. A brief record that a synced event was deleted may be kept for about 30 days to keep it from reappearing.
  • Routine suggestions derived on your device are kept locally for about 90 days.
  • Crash reports are retained for about 90 days.
  • Reports/abuse records we receive are kept as long as needed to enforce our policies.

A fuller breakdown is in our Data Retention Policy.

11. Your privacy rights & deleting your data

  • Tasks: Settings → Delete all tasks, or delete the app.
  • Account & shared lists: Settings → Disconnect (forgets the session on this device) or Delete account (revokes your access code and removes shared lists you own from the server).
  • Connected calendars: disconnect in the app (deletes the connection and synced data from our server and asks the provider to revoke access), or remove Checkmate's access directly in your Google Account settings.
  • Access or deletion requests: email privacy@checkmatepriorities.com and we'll help with any data we hold about you.

Our servers, and Google's, are located in the United States; if you use Checkmate from the EEA or the UK, your personal information will be processed in the US. Depending on where you live — for example California (CCPA/CPRA) or the EEA/UK (GDPR) — you may have additional rights to access, correct, delete, or port your personal information, and to object to certain processing. We do not sell or share your personal information for advertising. To exercise any right, email privacy@checkmatepriorities.com; we won't discriminate against you for doing so.

12. Changes to this policy

If we make material changes we'll update the effective date above and, where appropriate, note it in the app. If we materially change how we handle data from a connected account (such as a connected calendar), we will notify you and, where required, ask you to agree before that change takes effect. Continued use after an update means you accept the revised policy.

13. Contact

Questions or requests: privacy@checkmatepriorities.com