Privacy Policy

Version 1.0.0 · 2 September 2026

Introduction

With this privacy policy we would like to inform you about how we process personal data for Tikku (hereinafter: "the app").

The protection of your privacy is of the utmost importance to us, so it goes without saying that we comply with the legal stipulations on data protection, in particular the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the French Loi Informatique et Libertés.

Tikku is designed so that the most sensitive things it touches, namely which apps you block and how much time you spend on your phone, never leave your device. The section "What stays on your device" below explains this in detail.

Name and Contact Details of the Responsible Party

Skander MHADHBI EI (MILESTONE ONE)
Entrepreneur individuel registered in France
16 rue Emile Baudot, 91120 Palaiseau, France
SIREN: 831 144 886
contact@milestone-one.com

Skander MHADHBI EI is the data controller for the personal data processed through the app.

Data Protection Officer

We have not appointed a Data Protection Officer because our processing activities do not meet the thresholds set out in Article 37 GDPR. If you have any questions about our data protection measures, the processing of your data or the protection of your rights as a data subject, you can contact us at contact@milestone-one.com.

Please note that when communicating by email via the Internet, the confidentiality of the transmitted data cannot be guaranteed. We therefore ask you not to send confidential information by email if possible. Otherwise, we recommend contacting us by post at the above address.

Terms used

All data protection terms have the same meaning as defined in the General Data Protection Regulation (EU) 2016/679 ("GDPR").

What stays on your device

Before listing every category of data in detail, here is what Tikku deliberately never sends to us or to anyone else:

  • The apps, categories and websites you choose to block. Your selection is handled by the operating system, which does not reveal to Tikku the names of the apps you picked. It is stored only on the device where you made it.
  • Your screen time data (how long you used which app, and when). It is read and displayed by the operating system itself, in a part of the app that Apple prevents from accessing the network. Tikku never receives this data and never uploads it.
  • Your blocking activity, such as when a shield was shown or which blocked app you tried to open. This is processed on your device to display the shield and to apply the pause and exception limits you chose, and is not sent to us.
  • Your tasks, focus sessions and progress, as long as you do not sign in. They are stored in a local database on your device. They are sent to our servers only if you choose to sign in, in order to back them up and sync them across your devices.

No account is required to use Tikku. All features, including blocking, work without signing in.

Processed data categories

Personal data is all information about an identified or identifiable person. The following categories of personal data are processed through the app:

Account data

If you choose to sign in with Apple or Google, we collect and process the following data to create and operate your personal account:

  • email address (provided by Sign in with Apple or Sign in with Google; with Apple this may be a private relay address that you control)
  • an indicator that the email address has been verified by the identity provider
  • display name (provided by Sign in with Apple or Sign in with Google, if you choose to share it)
  • an indicator of whether your subscription is currently active
  • the identifier of the authentication provider (Apple or Google) you signed in with, together with the tokens returned by that provider, which we store solely to maintain your session
  • a Tikku user identifier (UUID generated server-side at account creation)

Use of an account is optional. You can use all features of the app without signing in.

Planning and progress data

This is the content you create in the app. It is stored in a local database on your device. If you sign in, it is also stored on our servers so that it can be backed up and synced across your devices:

  • tasks: title, optional notes, scheduled date and time or the "anytime" or "later" status, planned duration, repeat rule, completion status and sub-tasks
  • routines you added from the quick-add list and any changes you made to them
  • for each task or session, the blocking settings you chose: the scope (nothing, everything, everything except a list, or only some apps), the firmness (Flexible or Strict) and the name of a blocking preset. The apps themselves are not included; see "Screen Time and blocking data" below
  • focus sessions: start time, end time, duration and whether the session was completed
  • streaks, badges earned and the dates on which they were earned
  • the data needed for your weekly report, such as the number of tasks completed and the total focused time per day
  • settings, such as reminder preferences, the first day of your week and your display preferences

The titles and notes of your tasks are yours. We do not analyse their content and we do not use them for any purpose other than storing and syncing them for you.

Screen Time and blocking data (processed on your device only)

If you grant Tikku Screen Time authorization, the following data is processed by the app and its extensions on your device. None of it is transmitted to us or to any third party:

  • the status of the Screen Time authorization you granted
  • your selection of apps, categories and websites for each task, session or preset, in the form provided by the operating system, which does not include the app names
  • the schedules during which a block is active, derived from the times of your tasks and sessions
  • the counters that enforce the pause, early-end and weekly-exception limits of Flexible and Strict mode
  • the interactions with the shield, such as a request to pause or to end a run early
  • your screen time reports (usage per app, per day, week and month), which are displayed by the operating system

This data is stored on your device only and is deleted when you delete the app. You can revoke the Screen Time authorization at any time in the Settings of your device.

Tikku requests individual Screen Time authorization for your own device only. It does not use Family Controls to manage or monitor other people's devices and does not receive any data about them.

Billing data

If you purchase a subscription, the payment is processed by Apple or Google, depending on the store where you made the purchase. We do not receive or process your payment card details. We process the following billing-related data:

  • payment receipts from Apple or Google (which do not contain your payment card details)
  • a RevenueCat anonymous customer identifier that links your device to your purchase
  • the date on which your current subscription period expires
  • the identifier of the latest subscription event we received from RevenueCat (used to keep your subscription status in sync)

If you make a purchase without an account, the data above is still stored on our servers (linked to the RevenueCat anonymous identifier) so that we can verify your subscription on this and any other device on which you later sign in.

Technical data

This data describes technical information about the installed app and the connection to our servers. It is processed only when the app communicates with our servers, that is when you sign in, sync or verify a subscription:

  • session log entries (timestamps, IP address, user-agent string) created when you sign in
  • app version
  • session token (stored on your device, in the iOS Keychain)

Device data

This data tells us which hardware and software is being used to access the app. It is collected automatically by our product analytics provider, PostHog (see "Recipients of Personal Data" below):

  • mobile platform and operating system version
  • device model
  • app version
  • app language and locale
  • time zone
  • approximate location (city and country) derived from your IP address by PostHog at the moment your events are received
  • a randomly generated, pseudonymous analytics identifier created by the PostHog SDK on your device, which allows us to recognize the same device across sessions for analytics purposes

We do not collect the operating system's advertising identifier (IDFA on iOS, AAID on Android) or the iOS Identifier for Vendor (IDFV). The app does not request the App Tracking Transparency permission. We do not collect your precise location. We do not access your microphone, camera, contacts, photos or calendar. We do not read data from Apple Health.

App usage data

This data tells us how and how often the app is used. It is processed by our product analytics provider (see "Recipients of Personal Data" below):

  • screen views and navigation events
  • taps on calls to action
  • subscription events (paywall views, purchase, restore, dismiss)
  • feature events, such as: task created, routine added, focus session started or completed, blocking enabled for a task (with its scope and firmness, but never the apps concerned), preset created, badge earned, weekly report opened, Screen Time authorization granted or declined
  • error and crash diagnostics

Analytics events never include the titles or notes of your tasks, the apps, categories or websites you block, your screen time, or the content of your weekly report.

Notifications, widgets and Live Activities

Tikku schedules notifications locally on your device, for example to remind you that a task is starting, to tell you that a focus session has ended, or to let you know that your weekly report is ready. The notification that offers you a way back into a blocked app after a pause request is marked as time-sensitive so that a Focus mode on your device does not hide it. The content of these notifications is generated on your device.

Widgets and Live Activities show your tasks for the day and your running focus session on your home screen, lock screen and in the Dynamic Island. The data they display comes from your device and is not transmitted anywhere.

We process the categories of data listed above for the following purposes.

Provision and operation of the app

We process account data, planning and progress data, technical data and device data in order to provide the app for its intended use, to fulfill the user contract and to enable account creation, backup and sync across your devices, and the operation of the planner, blocking, focus, progress and report features. If you use fee-based services, we also process the billing data listed above for this purpose.

Screen Time and blocking data is processed only on your device, by the app and its extensions, in order to enforce the blocks you configured and to show you your screen time. This processing does not involve our servers.

Technical data and device data are processed to establish and secure the connection between the app and the server as well as to troubleshoot and detect errors.

The legal basis for this data processing is the fulfillment of the user contract in accordance with Article 6(1)(b) GDPR. Where a feature requires an operating system permission (Screen Time, notifications), the feature is only activated after you have granted that permission, which you can withdraw at any time in the Settings of your device.

Security and abuse prevention

We process account data, technical data and session log entries in order to keep the service secure, prevent unauthorized access to your account, detect and mitigate abuse, and protect the app's infrastructure.

The legal basis for this data processing is our legitimate interest in operating a secure service, in accordance with Article 6(1)(f) GDPR.

Product analytics and improvement

We process app usage data, technical data and device data in order to understand how the app is used, identify problems, prioritize features and improve the product. The analytics data used for this purpose does not include the content of your tasks, the apps you block or your screen time.

The legal basis for this data processing is our legitimate interest in improving and maintaining the app, in accordance with Article 6(1)(f) GDPR. You have the right to object to processing based on legitimate interests at any time.

Fulfillment of our legal obligations

We process the data listed above to fulfill our legal obligations, in particular our obligations under French accounting and tax law in connection with subscription transactions, and to respond to lawful requests from public authorities.

The legal basis for this data processing is Article 6(1)(c) GDPR.

Recipients of Personal Data

As part of the data processing for the purposes listed above, your personal data may be processed by or transmitted to the following service providers, as described below.

PostHog (product analytics and error tracking)

We use PostHog to collect app usage data and error diagnostics so that we can understand how the app is used and improve it.

PostHog is provided to us by PostHog Inc., based in San Francisco, California, USA. We have configured the app to use PostHog's EU instance, hosted in the European Union at https://eu.i.posthog.com. We do not pass the content of your tasks, your blocking selections or your screen time to PostHog.

PostHog processes this data in accordance with its applicable service terms and data processing terms. Where required by applicable data protection law, we rely on appropriate safeguards made available by PostHog, such as the European Commission's Standard Contractual Clauses.

RevenueCat (subscription management)

We use RevenueCat to verify subscription status, reconcile purchases made through the Apple App Store or Google Play with your account, and handle restores across devices.

RevenueCat is provided to us by RevenueCat, Inc., based in San Francisco, California, USA. RevenueCat receives subscription event identifiers and the RevenueCat anonymous customer identifier for your device. After you sign in, your email address is also shared with RevenueCat so that we can map purchases to your account. RevenueCat does not have access to the content you create inside the app.

RevenueCat processes this data in accordance with its applicable service terms and data processing terms. Where required by applicable data protection law, we rely on appropriate safeguards made available by RevenueCat, such as the European Commission's Standard Contractual Clauses.

Neon (database hosting)

We use Neon to host our PostgreSQL database, which stores account data and synced planning and progress data for users who choose to create an account, as well as subscription records for users who have made a purchase.

Neon is provided to us by Neon, Inc., based in the United States. Our database is hosted in the AWS Europe Central 1 region (Frankfurt, Germany).

Cloudflare (API hosting)

We use Cloudflare Workers to host our backend API, which sits between the app and the database. Network requests from the app to our backend transit through Cloudflare's global edge network.

Cloudflare Workers is provided to us by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare processes IP addresses and request metadata for the purpose of routing, security and abuse prevention.

Cloudflare processes this data in accordance with its applicable service terms and data processing terms. Where required by applicable data protection law, we rely on appropriate safeguards made available by Cloudflare, such as the European Commission's Standard Contractual Clauses.

Apple Inc. (Sign in with Apple, App Store, Screen Time, notifications, widgets)

If you choose to sign in with Apple, your authentication is handled by Apple. We receive your email address (which may be a private relay address you control) and, if you choose to share it, your name. We do not receive your Apple ID password.

The App Store handles distribution of the app and processing of in-app purchases. Blocking and the screen time report are provided by the Screen Time frameworks of the operating system, which process the corresponding data on your device under Apple's control; Apple's Screen Time features are described in Apple's own privacy documentation. Notifications, widgets and Live Activities are displayed by the operating system.

These services are provided to users in the European Union by Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. To users outside the European Union, these services are provided by Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. Apple acts as an independent data controller for these services. Its processing is governed by Apple's privacy policy, available at https://www.apple.com/legal/privacy/.

Google LLC (Sign in with Google, Google Play)

If you choose to sign in with Google, your authentication is handled by Google. We receive your email address and, if you choose to share it, your name. We do not receive your Google account password.

If you obtained the app through Google Play, Google Play handles distribution of the app and processing of in-app purchases. Sign in with Google and Google Play are provided to users in the European Union by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and to users outside the European Union by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google acts as an independent data controller for these services. Its processing is governed by Google's privacy policy, available at https://policies.google.com/privacy.

Transfer to Third Countries

In the event that we process personal data in a third country (i.e. outside the European Union or the European Economic Area) or have it processed (see also the third-party services described above), this is done in compliance with the respective legal specifications.

We ensure that EU Standard Contractual Clauses are concluded with the recipients based in third countries to ensure an adequate level of data protection, supplemented where necessary by additional safeguards required by the European Data Protection Board's recommendations after the Schrems II decision. If you wish to receive a copy of the standard contractual clauses in force, feel free to contact us using our contact details.

Profiling and Automated Decision Making

Automated decision-making within the meaning of Article 22 GDPR does not take place. Streaks, badges and the weekly report are computed from your own tasks and focus sessions in order to show you your progress; they have no legal or similarly significant effect on you. We do not use your content to train artificial intelligence models. We do not send your content to third-party large language model providers.

Your Rights

In accordance with the GDPR, you are entitled to the following data protection rights in accordance with the legal requirements:

  • Right of access by the data subject under Article 15 GDPR: To request information about the processing of your data, as well as to receive a copy of your personal data. Among other things you may request information on the purposes of the processing, the categories of personal data processed, the recipients of the data (if a transfer is made), the duration of the storage or the criteria for determining the duration.
  • Right to rectification under Article 16 GDPR: To correct your data. If your personal data is incomplete, you have the right to complete the data, taking into account the purposes of the processing.
  • Right to erasure under Article 17 GDPR: To have your data deleted.
  • Right to restriction of processing under Article 18 GDPR: To have the processing restricted.
  • Right to data portability under Article 20 GDPR: To receive personal data relating to you in a structured, common and machine-readable format or to transfer it to another controller.
  • Right to object under Article 21 GDPR: To object to the processing of your data based on legitimate interests.
  • Right to withdraw consent under Article 7(3) GDPR: To revoke any consent you have given for the future.
  • Right to lodge a complaint under Article 77 GDPR: You have the right to complain to the competent supervisory authority at any time if you believe that your data is not being processed lawfully.

How to exercise your rights

To exercise your right of access, your right to rectification, your right to restriction of processing or your right to data portability, contact us at contact@milestone-one.com.

To exercise your right to erasure, delete your account from the in-app Settings. This deletes your account and all associated synced content from our servers. Alternatively, you can write to us at contact@milestone-one.com. Please note that uninstalling the app will not delete your account automatically. Data that only exists on your device (blocking selections, screen time data and, if you are not signed in, your tasks) is deleted when you delete the app.

The supervisory authority responsible for Tikku is the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, https://www.cnil.fr.

Technical safety precautions

We take a range of measures to protect your personal data.

  • The most sensitive data (blocking selections and screen time) is processed exclusively on your device, using operating system frameworks that are designed to prevent apps from exporting it.
  • All communication between the app and our servers uses TLS encryption (HTTPS), which prevents third parties from reading data while it is being sent.
  • Session tokens are stored on your device in the iOS Keychain through Expo SecureStore, never in plaintext on disk.
  • Local data on your device is protected by the operating system's data protection and by the passcode, Face ID or Touch ID you have configured on your device.
  • Database access is restricted to authorized personnel and protected by unique credentials.
  • Our infrastructure providers (Neon, Cloudflare) operate ISO 27001 certified data centers and encrypt data at rest in accordance with the AES-256 standard.

No security measure is perfect. If we ever experience a personal data breach that is likely to result in a risk to your rights, we will notify the CNIL within 72 hours and inform you without undue delay, as required by Articles 33 and 34 GDPR.

Storage and Data Deletion

We store your personal data for as long as it is necessary for the purposes for which it was collected.

  • Account data and synced planning and progress data: kept while your account exists. Deleted when you delete your account from the in-app Settings. If you use the app without signing in, no planning or progress data is stored on our servers; that content lives only on your device until you uninstall the app or delete it from inside the app.
  • Screen Time and blocking data: stored only on your device. Deleted when you delete the app. Revoking the Screen Time authorization in the Settings of your device immediately stops all blocking.
  • Subscription records: kept for the duration of the subscription and afterwards for as long as we are legally required to keep accounting records, typically 10 years in France in accordance with Article L123-22 of the French Code de commerce. Subscription records are kept even if you used the app without an account.
  • Session tokens and session metadata (IP address, user-agent, expiration timestamp): 30 days from creation. Sessions that have expired are deleted by our authentication provider.
  • App usage data and error diagnostics processed by PostHog: retained for 12 months. We periodically review this period and may shorten it.
  • Support correspondence: up to 3 years from the date of last contact.

Regardless of the right to erasure pursuant to Article 17 GDPR, you can delete your account directly in the app at any time in the Settings. Before this, you can request an export of your data by contacting us at contact@milestone-one.com.

Requirement or obligation to provide data

Unless expressly stated at the time of collection, the provision of data is not required or obligatory. You can use all features of the app without creating an account. If you choose not to provide certain data (for example, by not signing in), some features that depend on that data (for example, backup and sync across devices) will not be available.

Granting the Screen Time authorization is optional. Without it, blocking, the shield and the screen time report are not available; everything else works normally. Granting the notification permission is optional; without it, reminders and session notifications are not shown.

Children

You must be at least 13 years old to create an account or to purchase a subscription. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and you believe your child has provided us with personal data, please contact us at contact@milestone-one.com and we will delete it.

Tikku is a self-control tool for the person using the device. It is not a parental control tool and cannot be used by a parent to block apps on, or read the screen time of, a child's device.

Use of the app in a potentially unsafe environment

Security risks may arise when using the app in unsafe situations, such as open and unencrypted wireless networks, unattended public devices, rooted or jailbroken devices, or an external attack.

We recommend using the app only in secure environments on your own device with appropriate security settings. Even with the exhaustion of as many technical and organizational security precautions as possible, 100% security cannot be guaranteed. We recommend that you pay close attention to the following tips:

  • Secure access: enable an access restriction (passcode, fingerprint, facial recognition) for unlocking your device. This also protects the data Tikku stores locally.
  • Stay up to date: regularly install the latest updates for your operating system and the app.
  • Be careful with public networks: avoid using public Wi-Fi without a password or a VPN.
  • Mind your widgets: the Today widget and the Live Activity show your task titles on your lock screen. If you would rather not display them there, you can remove the widget or turn off lock screen widgets in the Settings of your device.

Version of this Privacy Policy

We reserve the right to change this privacy policy if this becomes necessary due to updates in regulations or in the app. If fundamental changes are made to this privacy policy, we will inform you inside the app. You can call up the privacy policy at any time in the in-app Settings.

Contact Us

If you have questions about this Privacy Policy, please contact:
contact@milestone-one.com