Data Retention Policy
1. The principle
We keep data only as long as it takes to do the thing you asked for, and then we delete it. Where the law requires us to keep something longer, we say so below. Most of Checkmate's data never reaches us at all — your tasks live on your device. This policy covers the data that does reach our servers.
2. Data that stays on your device (we never receive it)
| Data | Kept until |
|---|---|
| Tasks, notes, priorities, due dates, subtasks, tags | You delete them, or delete the app |
| Attachments (images and files on a task) | Same — stored on your device only, never uploaded |
| App settings, theme, streaks | Same |
| Routine suggestions learned on your device | ~90 days locally, then they age out; deleted immediately if you turn routine suggestions off |
We have no copy of any of this and cannot recover it for you. Settings → Delete all tasks removes it; so does deleting the app.
3. Data on our servers
3.1 Account and session
| Data | Retention |
|---|---|
| Session token | Until you disconnect or delete your account |
| Display name (optional) | Until you delete your account |
| Device identifier, IP address, device type | ~90 days, then deleted; kept for authentication, security, and rate-limiting |
3.2 Shared lists and groups
| Data | Retention |
|---|---|
| Task content in a shared list (titles, notes, subtasks, priority, order, completion) | While the list exists |
| List membership | While you're a member |
| Content in a list you own | Deleted when you delete the list or your account |
| Content in a list you joined | Removed from your view when you leave; the list continues for other members |
Attachments are not shared to our server, so there is nothing here to retain for them.
3.3 Connected calendar (Google)
| Data | Retention |
|---|---|
| OAuth access & refresh token (encrypted at rest) | While the calendar stays connected; deleted on disconnect or account deletion, and revocation is requested from Google |
| Google account email | Same |
| Synced task fields (title, notes, date/time, all-day, priority, completion) | Same |
| Task ↔ calendar event mapping | Same |
| Deletion tombstone for a synced event | ~30 days, so a deleted event doesn't reappear |
| Events read back from Google | Used to update your synced tasks; we retain the synced task fields and mapping above, not a separate copy of your calendar |
3.4 Routine and scheduling suggestions
Routine suggestions are computed entirely on your device — nothing about them is kept on our servers. Learned patterns live locally for about 90 days (Section 2). Turning routine suggestions off deletes what's been learned on your device.
3.5 Safety, moderation, and copyright records
| Data | Retention | Why |
|---|---|---|
| Content reports and a snapshot of the reported content | ~2 years | Pattern evidence across repeat reports |
| Blocks | While the block is in place | Function |
| Copyright (DMCA) notices, counter-notices, case records | Account life + 3 years | Litigation window |
| Removed-content snapshots (copyright) | Same | Required to restore content after a valid counter-notice |
| Enforcement strikes | Matches the 12-month strike window | Enforcement |
| Child-safety incident records and any preserved material | At least 90 days from the report, longer if law enforcement requires | 18 U.S.C. § 2258A |
| Audit log of enforcement actions | Indefinite — contains no personal content, only references | Accountability |
| Deletion records | Indefinite — contains no personal content, only a one-way hash and a date | Proof we deleted |
3.6 Third parties
| Provider | What they hold | Retention |
|---|---|---|
| Apple / RevenueCat | Purchase and subscription records | Per their policies; required for billing and tax |
| Sentry | Anonymous crash and error reports (no task content) | ~90 days |
| Your calendar and account, if connected | Per Google's own policies | |
| Cloudflare | Hosts our server, database, and key-value store | Per our windows above |
| Expo (EAS) | Build and update delivery | Per their policies |
4. When retention rules conflict
Some obligations override others. In order of precedence:
- Child-safety preservation and law-enforcement holds — override everything, including your deletion request
- Copyright preservation during an active notice or counter-notice window
- Your deletion request
- Normal retention expiry
If you request deletion and something above sits at a higher precedence, we delete everything else and keep only what we're legally required to keep.
5. Deleting your data
| What | How |
|---|---|
| Tasks on your device | Settings → Delete all tasks, or delete the app |
| Your account and server data | Settings → Delete account |
| A connected calendar | Calendar sync → Disconnect (also asks Google to revoke access) |
| Routine suggestions | Turn off routine suggestions in Settings — this deletes what's been learned |
| Everything, by request | Email privacy@checkmatepriorities.com |
6. Changes
Material changes get an updated effective date and, where appropriate, a note in the app.
7. Contact
privacy@checkmatepriorities.com