Legal
Privacy Policy
Last updated: July 26, 2026
This Privacy Policy explains how Tratto (“we”, “us”, or “our”) collects, uses, and shares information when you use the Tratto mobile application and related websites and services (the “Service”). By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Information we collect
Account and authentication
When you sign in, we collect information needed to create and secure your account. Depending on how you sign in, this may include your email address, display name, and authentication identifiers provided by Firebase Authentication and, if you use it, Google Sign-In.
Content you create
We store the content you create in the Service so it can sync across your devices. This may include projects, sections, tasks, typed and handwritten text, notes, tags, dates, attachments you add, and related settings.
Purchases and subscriptions
If you buy a subscription or in-app purchase, payment is processed by Apple, Google, and/or our subscription provider (RevenueCat). We receive purchase and entitlement status (for example, whether Pro is active), not your full payment card details.
Device and usage information
We may collect technical and usage data to operate and improve the Service, such as device type, operating system, app version, language, crash or error reports, and how features are used. We use analytics tools including Microsoft Clarity and PostHog for this purpose.
Notifications
If you enable due-date reminders, the app schedules local notifications on your device. Reminder content is generated from your tasks and is processed on-device for delivery; you can disable notifications in system settings.
2. How we use information
We use the information above to:
- Provide, sync, and maintain the Service
- Authenticate you and secure your account
- Process subscriptions and unlock paid features
- Send optional task reminders you configure
- Diagnose bugs, improve performance, and understand product usage
- Comply with legal obligations and enforce our Terms
3. How we share information
We do not sell your personal information. We share information with service providers that help us run the Service, including:
- Google Firebase — authentication, cloud database, and related infrastructure
- Google Sign-In — if you choose to sign in with Google
- RevenueCat — subscription and entitlement management
- Apple App Store / Google Play — purchase processing
- Microsoft Clarity and PostHog — analytics and product insights
These providers process data under their own privacy policies and only as needed to provide their services to us. We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset sale.
4. Data storage and international transfers
Your account and content are stored using cloud providers (including Firebase). Data may be processed in the United States or other countries where we or our providers operate. Where required, we rely on appropriate safeguards for cross-border transfers.
5. Retention
We retain account and content data while your account is active. If you delete your account through the in-app option, we delete or anonymize associated personal data within a reasonable period, except where we must retain information for legal, security, or accounting reasons. Analytics and logs may be retained for shorter operational periods.
6. Your choices and rights
Depending on where you live, you may have rights to:
- Access, correct, or delete personal information
- Export or receive a copy of your data
- Object to or restrict certain processing
- Withdraw consent where processing is based on consent
You can update much of your content directly in the app, manage notification permissions in device settings, and delete your account where that option is offered. To make a privacy request, contact us using the details below. You may also have the right to lodge a complaint with a local supervisory authority.
7. Security
We use industry-standard measures appropriate to the nature of the Service (including encrypted transport and authenticated cloud access) to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Children’s privacy
The Service is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
9. Third-party links and stores
The Service may link to third-party sites or app stores. Their privacy practices are not covered by this Policy. Review their policies before providing information to them.
10. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised Policy on this page and update the “Last updated” date. Continued use of the Service after changes become effective constitutes acceptance of the updated Policy, except where applicable law requires additional consent.
11. Contact
Privacy questions or requests can be sent to [email protected]. If that address is not yet active, use the support contact method listed on the App Store or Google Play product page for Tratto.
See also our Terms of Service.