legal

privacy
policy.

Effective date: March 24, 2026  ·  Last updated: March 24, 2026

Plain language first. This policy is written to be genuinely readable. check-d is a personal productivity app — your data belongs to you, lives in your own iCloud account, and is never sold. The sections below explain exactly what is collected, why, and how.
01

who we are

check-d is an independent iOS app developed by Gurumanie Singh. References to "we", "our", or "us" in this policy refer to Gurumanie Singh as the developer and data controller for check-d.

If you have any questions about this policy or how your data is handled, please use the contact details in section 13.

02

what we collect

check-d stores the following data, all of which is tied to your personal iCloud account and held in Apple's CloudKit private database — never on our own servers.

data where stored why
Display name CloudKit — UserProfile record Shown in the app and used to personalise AI responses
Preferred tone CloudKit — UserProfile record Selects the AI motivation style (encouraging / strict / playful)
Profile photo (optional) CloudKit — JPEG asset on UserProfile Avatar displayed in profile and sign-in screen
Streak & total completed tasks CloudKit — UserProfile record Stats display, AI context, streak indicator
Task titles, notes, category, effort, mood CloudKit — Task records Core done-list feature
Task completion timestamps CloudKit — Task records Streak calculation and activity heatmap
XP, level, total XP CloudKit — Pet record XP bar and level-up progress system
Daily check-in responses CloudKit — CheckIn records Journal prompts: joyful moment, lesson learned, emotional check-in
Check-in scores & date CloudKit — CheckIn records History display and editing

All records are scoped to your iCloud account via an ownerRecordName field — data from one Apple ID is never accessible to another user.

03

CloudKit & Apple iCloud

check-d uses Apple CloudKit as its sole backend. Your data lives in Apple's private CloudKit database associated with your iCloud account — not on any server we operate.

You do not create an account with us. There is no email address, password, or external login. Your Apple ID and iCloud account are the only credentials required.

Because your data is stored in your private iCloud database, Apple's own privacy policy and infrastructure govern how it is protected at rest and in transit. You can review Apple's privacy policy at apple.com/legal/privacy.

To delete your check-d data, you can delete the app and clear its CloudKit data via Settings → [your name] → iCloud → Manage Account Storage on your device.

04

AI motivation & external processing

When you log a completed task, check-d may generate a short motivational message. This requires sending a small amount of information to an external service.

what is sent to whom why
Display name (sanitised, alphanumeric only) Our Cloudflare Worker, then Google Gemini Personalise the motivational message
Task title (sanitised) Our Cloudflare Worker, then Google Gemini Generate relevant, task-specific motivation
Current streak count Our Cloudflare Worker, then Google Gemini Add streak context to the message
Preferred tone Our Cloudflare Worker, then Google Gemini Match the AI response style to your preference

How it works: The app sends an authenticated HTTPS request to a Cloudflare Worker we operate. The Worker holds the API key and forwards the request to Google Gemini. The generated response (a short sentence) is returned to the app and displayed. Your raw API key is never stored on-device.

What is not sent: Task notes, check-in journal entries, photos, and your full task history are never transmitted to the AI service.

Third parties in this flow:

Cloudflare processes the request as a processor we control. Cloudflare's privacy policy applies: cloudflare.com/privacypolicy

Google Gemini generates the AI response. Google's terms and privacy policy apply to how they handle API inputs: policies.google.com/privacy

If the AI request fails for any reason, the app continues to function normally with fallback text. AI motivation is optional enhancement — not a requirement for the core experience.
05

photos & profile picture

check-d may request access to your photo library if you choose to set a profile picture. This is entirely optional.

When you select a photo, the image is compressed to JPEG and stored as an asset on your CloudKit UserProfile record — the same private iCloud database described above. The photo is used only for your avatar within the app.

We do not access, scan, or analyse any photos beyond the single image you explicitly select. We do not request camera access.

You can remove your profile picture at any time from Profile → tap your avatar → remove photo.

06

local device preferences

The following preferences are stored locally on your device using UserDefaults and are never uploaded to any server:

accent colour choice dark / light mode onboarding completion flag last task date last task category cached CloudKit record IDs

These are purely local app preferences. Uninstalling check-d removes them from your device.

07

sharing wins

check-d includes an optional share feature that lets you share a completed task as an image. When you tap the share button, the app generates a visual card image entirely on-device — containing the task title, your streak count, and category — and opens the iOS system share sheet.

The destination of that image (Messages, social media, etc.) is entirely your choice. We do not receive, process, or store any information about what you share or where.

08

what we do not collect

check-d does not use any of the following:

not collected details
Advertising identifiers No IDFA, no ATT prompt, no ad networks
Analytics SDKs No Firebase, Mixpanel, Amplitude, or equivalent
Crash reporting services No Crashlytics or third-party crash tools
Location data No location APIs are used
Contacts No contacts access is requested
Cross-app tracking We do not track you across apps or websites
Email address or password No traditional account system exists in the app
Device identifiers No device fingerprinting or hardware ID collection

check-d products are ad-free. We do not sell your data to any third party, ever.

09

data retention & deletion

Your data persists in your CloudKit private database for as long as you have the app installed and your iCloud account active. We do not impose additional retention periods — Apple's iCloud infrastructure manages the underlying storage.

To delete your data:

Within the app, you can delete individual tasks from the home tab. You can remove your profile photo from the profile tab. Check-in entries can be reviewed and managed from the check-in history.

To delete all check-d data entirely, go to Settings → [your name] → iCloud → Manage Account Storage → check-d → Delete Data on your device. Alternatively, uninstalling the app and clearing its iCloud data removes everything.

AI requests are processed in real time. We do not intentionally retain prompt/response logs. Refer to Cloudflare and Google Gemini's respective policies for their infrastructure-level retention practices.

10

security

All communication between the app and external services uses HTTPS. Requests to the AI Worker are authenticated with a shared secret — your API key is never stored on-device.

Your task and check-in data is stored in Apple's CloudKit private database, which is protected by Apple's security infrastructure including encryption at rest and in transit.

Local app preferences are stored in standard iOS UserDefaults. No sensitive credentials are stored in UserDefaults.

While we take reasonable steps to protect your data, no system is entirely immune to risk. We encourage you to use a strong iCloud password and enable two-factor authentication on your Apple ID.

11

children

check-d is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will take steps to remove that information.

Users between 13 and 17 should use the app with parental awareness, in line with Apple's age guidelines for the App Store.

12

changes to this policy

We may update this privacy policy from time to time. When we do, we will update the "last updated" date at the top of this page. For significant changes, we will make reasonable efforts to notify you — for example via an in-app notice on the next launch after the update.

Continued use of check-d after a policy update constitutes your acceptance of the revised terms. If you do not agree with any changes, you should stop using the app and delete your data as described in section 9.

13

contact

If you have any questions, concerns, or requests related to this privacy policy or how check-d handles your data, please reach out:

privacy contact