Privacy Policy
Privacy Policy
Contents
- Overview
- Data Controller & Scope
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing
- Data Sharing & Disclosure
- Groups, Lists & Shared Content
- Data Storage, Security & Retention
- International Data Transfers
- Your Privacy Rights
- Account Deletion
- US State Privacy Disclosures
- App Store Privacy Labels
- Tracking, Ads & Device Permissions
- Children's Privacy
- Third-Party Services
- Security Incidents
- Changes to This Policy
- Contact Us
Overview
DoIt ("we", "our", or "us") is a collaborative list application that helps you create groups, share lists, check off items in real time, and keep everyday tasks organized with the people you live and work with.
This Privacy Policy explains what personal information we collect when you use DoIt, why we collect it, and how we use and protect it. By using DoIt, you acknowledge the data practices described in this policy.
Data Controller & Scope
For the purposes of applicable data protection laws, Vertek Solutions LLC is the data controller for personal information processed through DoIt. DoIt is operated from Atlanta, Georgia, United States.
This policy applies to information collected through the mobile app, related backend services, and support communications. It does not apply to third-party websites or services that have their own privacy policies.
Information We Collect
We collect the following categories of information:
Account Information
- Email address (used to create and identify your account)
- Display name (if you provide one or if it is supplied by a sign-in provider)
- Profile photo URL (if supplied by a sign-in provider such as Google or Apple)
- Authentication data (managed securely via Supabase Auth)
Group & List Data
- Groups you create or join, including group name, icon, color, and invite code
- Your role in a group (for example, admin or member)
- Lists and list items you create, including names, optional notes, completion status, and who added them
- Activity history used to show recent changes across your groups
Device & Usage Data
- Device identifiers used for advertising (Google AdMob) and app diagnostics
- Theme preference (light or dark) stored on your device
- Error and diagnostic data that helps us keep the app stable
Location Data
- DoIt does not collect precise GPS location data.
How We Use Your Information
We use your information to:
- Provide, maintain, and improve the DoIt app and its features
- Authenticate your account and keep it secure
- Sync groups, lists, and item updates with other members in real time
- Show recent activity across the groups you belong to
- Send account emails such as password reset codes
- Display banner ads that help keep DoIt free
- Enforce our Terms of Service and comply with legal obligations
Legal Bases for Processing
If you are in a jurisdiction that requires a legal basis for processing (such as the EEA, UK, or Switzerland), we process personal data under one or more of the following bases:
- Performance of a contract: to provide app functionality you request (account creation, shared lists, group invites)
- Legitimate interests: to improve security, reliability, and product performance
- Consent: for optional advertising-related tracking where required by law. You may withdraw consent at any time.
- Legal obligations: where required to comply with applicable law
Data Sharing & Disclosure
We do not sell, trade, or rent your personal data. We may share your information only in these limited cases:
- Supabase: We use Supabase for authentication, the Postgres database that stores groups and lists, and realtime updates. Supabase processes data on our behalf to operate the app.
- Google and Apple: If you sign in with Google or Apple, those providers authenticate you and may share your email, name, and profile photo with DoIt.
- Google AdMob: Banner ads may collect device identifiers and usage signals for ad serving, subject to your tracking consent on iOS.
- Other group members: Content you add to a group — including your display name, list items, and notes — is visible to other members of that group.
- Legal obligations: We may disclose data if required by law, subpoena, court order, or to protect the rights and safety of DoIt and its users.
- Business transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction. We will provide notice via the app or email before such a transfer occurs.
Groups, Lists & Shared Content
DoIt is built around shared groups. Here is what you should know:
- Groups are joined with an invite code. Anyone with the code can join the group until an admin changes or stops sharing that code.
- List items, notes, and completion status are visible to all current members of the group.
- Your display name (and avatar, if provided by your sign-in provider) is shown to other members on items you add.
- Admins can remove members from a group. Removed members lose access to that group's lists.
- Do not put sensitive personal information (such as passwords, financial details, or medical information) into list items or notes.
- You can delete items and lists you control. Group-level deletion is handled by group admins according to the tools available in the app.
Data Storage, Security & Retention
Your data is stored using Supabase infrastructure, which includes:
- Encryption in transit (TLS)
- Secure authentication tokens managed by Supabase Auth
- Access controls that restrict group and list data to members of that group
While we take reasonable precautions to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
Retention: We keep personal data only as long as needed for the purposes described in this policy, including legal, accounting, and security obligations. If you delete your account, we aim to delete or de-identify associated personal data from active systems within 30 days, subject to limited retention required by law or technical backup cycles. Content you added to shared groups may remain visible to other members if it is still part of an active list.
International Data Transfers
DoIt is operated from Atlanta, Georgia, United States. Because we use cloud providers with global infrastructure (primarily Supabase and Google), your information may be processed outside your country of residence, including in the United States.
Where required by law (for example, for users in the EEA or UK), we rely on appropriate transfer safeguards, including Standard Contractual Clauses and our providers' compliance frameworks, to protect your data during cross-border transfers.
Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data. You can also update your display name in the app.
- Deletion: Request deletion of your account and associated data. See Account Deletion.
- Portability: Request a portable copy of certain data where applicable.
- Objection / Restriction: Object to or request restriction of certain processing where legally available.
- Withdraw consent: Withdraw consent for optional processing (such as ad tracking) at any time.
- Lodge a complaint: If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority.
To exercise your rights, contact us at dev.saif17@gmail.com. We may need to verify your identity before fulfilling a request. We will respond within 30 days, or within any shorter period required by applicable law.
Account Deletion
If you create a DoIt account, you can also delete it. Apple requires this for apps that support account creation.
- In the app, open Profile and choose Delete Account (when available), or
- Email dev.saif17@gmail.com from the address on your account with the subject “Delete DoIt account”
After we verify the request, we delete or de-identify your account data from active systems within 30 days, subject to limited backup and legal retention. Content you added to shared groups (such as list items) may remain visible to other members if it is still part of an active list. See also our Support page.
US State Privacy Disclosures
If you are a resident of California (CCPA/CPRA) or another US state with applicable privacy laws, you may have additional rights, including the right to know, delete, correct, and opt out of certain data uses.
DoIt does not sell personal information for monetary or other valuable consideration. Categories of personal information we collect and their business purposes are described in Sections 3 and 4 of this policy.
You may exercise your applicable rights by contacting us at dev.saif17@gmail.com. We will not discriminate against you for exercising your privacy rights.
App Store Privacy Labels
Apple requires apps to declare data types in App Store Connect. DoIt may collect the following, used to provide the app and (for ads) to display advertisements. We do not sell this data.
- Contact Info: email address (account sign-in)
- Identifiers: user ID; device identifiers used by Google AdMob
- User Content: group names, lists, item names, notes, and display name
- Usage Data: feature interactions that may be used for ads and diagnostics
- Diagnostics: crash and performance data from the ads SDK and app runtime
Data linked to your identity is used to run your account and shared groups. Ad-related identifiers may be used for tracking only if you consent on iOS (App Tracking Transparency).
Tracking, Ads & Device Permissions
- Ads: DoIt may show banner ads served through Google AdMob. These ads help keep the app free.
- iOS App Tracking Transparency: On iOS, we request your permission before enabling tracking-dependent ad features in accordance with Apple's App Tracking Transparency (ATT) framework. If you decline, you may still see ads but they will not be personalized based on cross-app tracking.
- Do Not Track: Because mobile apps do not consistently support browser-based DNT signals, we do not respond to DNT signals in a standardized way. You can control ad-related tracking through your device settings instead.
- Device permissions: You can control app permissions in your device settings at any time.
Children's Privacy
DoIt is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you are in a jurisdiction where the minimum age for digital services is higher (for example, 16 in certain EU member states), users below that age should not use DoIt without verifiable parental or guardian consent.
If we become aware that a child under the applicable minimum age has provided us with personal data, we will take steps to delete it promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at dev.saif17@gmail.com.
Third-Party Services
DoIt integrates with the following third-party services, each governed by their own privacy policies:
- Supabase: Authentication, database, and realtime sync — supabase.com/privacy
- Google Sign-In: Optional sign-in — policies.google.com/privacy
- Sign in with Apple: Optional sign-in — apple.com/legal/privacy
- Google AdMob: Banner advertising — policies.google.com/privacy
- Apple App Store and Google Play: Marketplace distribution — apple.com/legal/privacy / policies.google.com/privacy
We are not responsible for the privacy practices of these third parties. We encourage you to review their policies.
Security Incidents
If we become aware of a data breach or security incident affecting your personal information, we will take steps required by applicable law, including investigation, mitigation, and notification. Where required by law, we will notify the relevant supervisory authority. Affected users will be notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will provide prominent notice via the app or by email, and where required by law, seek your consent before the changes take effect.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
Email us at
dev.saif17@gmail.com