Privacy Policy
Last updated: 2026-10-01. This is a plain-language policy for a small, single-developer, single-account app — it has not been reviewed by a lawyer. Sections that would need that review before this app is used by more than its one account are marked ⚠️ LEGAL REVIEW.
What this covers
ProjectPilot (the web app at this domain and its iOS companion app) is a personal project-tracking tool. Today it is built and used by one person. This policy describes what data the app collects and what happens to it, in case that ever changes or in case the App Store review process needs it.
Information we collect
- Account data: your email address, an optional display name, and a password (stored only as a salted PBKDF2 hash, never in plain text).
- The content you enter: project names, summaries, next steps, tasks, notes, ideas, and subscription details (name, cost, renewal date) — all the data the app exists to hold for you.
- Sign-in & security logs: IP address, user agent, and timestamp for login attempts (to detect and lock out brute-force attempts), and for public page views (a lightweight visit log, no third-party analytics or ad tracking).
- iOS device data: a per-device API token (so the phone doesn't need your password after the first sign-in) and, once push notifications are enabled, an Apple Push Notification (APNs) device token.
How information is used
Strictly to run the app: authenticating you, displaying and updating your projects, calculating renewal reminders and "stale project" nudges, and — once enabled — sending you push notifications or reminder emails you've opted into from Settings.
Who it's shared with
Nobody, except the infrastructure providers that run the app:
- Cloudflare — hosting, the database, and key-value storage (Workers, D1, KV).
- SMTP2GO — sends renewal-reminder and stale-project emails, if you've turned email reminders on.
- Apple — delivers push notifications to the iOS app via APNs.
Your data is never sold, rented, or used for advertising, and there is no third-party analytics or ad-tracking script on this site.
Data retention ⚠️ LEGAL REVIEW
Project, idea, and subscription data is kept until you delete it or delete your account. Login-attempt records are purged after 24 hours. Page-view logs are trimmed to the most recent 90 days by a daily cleanup job. You can delete your account and all of its data yourself in the iOS app (Settings → Delete account); this is permanent and happens immediately. There is currently no self-service data export — ask whoever administers the app to do that manually.
Your rights ⚠️ LEGAL REVIEW
You can review and edit most of your data directly in the app. For anything else (a full export, full account deletion, or questions about this policy), contact the app's owner. This section would need real legal review (GDPR/CCPA-style rights language) before this app is opened up to users beyond its current single account.
Security
Passwords are hashed with PBKDF2 (never stored in plain text). Sessions use a signed, revocable cookie. Login attempts are rate-limited by IP and email. All traffic is served over HTTPS. As with any system, no method of storage or transmission is 100% secure.
Children's privacy
ProjectPilot is not directed at children and is not knowingly used by anyone under 13.
Changes to this policy
If this policy changes in a material way, the "last updated" date above will change and, while the app has user accounts beyond its current one, affected users would be notified.
Contact
Contact the app's owner for any privacy questions.