Privacy policy

Last updated 8 September 2026

The short version. Your notes live on your devices and in your own iCloud account. We don't have a copy of them, and there's no account to sign up for. The only things that reach a server are the ones you ask for: a note you share, an integration you connect, and your email address if you join the beta.

01 — The app

What the app stores

Stiicky writes your notes as Markdown files inside its iCloud folder. We can't read it. The app sends no analytics, no usage telemetry, and no crash reports with note content in them.

02 — The server

If you use a hosted server

A hosted Stiicky server does the things a phone in your pocket can't: hold a shared note at a link that keeps working, and poll integrations while your devices are asleep. It's built so that most of your data never reaches it at all.

DataOn the serverHow long
Notes you haven't shared never sent
Boards, pins, tags, archive never sent
Notes in an active share stored Deleted when you revoke the share, or move the note out of it
Integration cards in transit passing through Deleted once your device confirms it has them
OAuth tokens for services you connected stored Until you disconnect that account
Sync cursors and item IDs stored Until you disconnect. IDs only, never content
A workspace you opted in to MCP stored Deleted when you switch that workspace's opt-in off
Link previews in memory 10 minutes, and never written to disk

03 — Google

Google account data

Connecting a Google account is optional, and off until you do it. When you connect one, Stiicky asks for a single Google scope beyond your basic profile:

https://www.googleapis.com/auth/tasks

It's there for one feature: mirroring your Google Tasks lists into Stiicky as cards you can edit. Ticking a box completes the task in Google, renaming a line renames it, adding a line creates it. That's why the access has to be read and write.

The server stores the auth token for the account, and the task and list IDs needed to keep each card pointed at the right task. Task text travels to your device and isn't kept on the server afterwards. Disconnect the account and the token is revoked with Google and its cards are deleted.

Limited Use. Stiicky's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, we don't sell it, and nobody reads it unless you've asked us for help with a support problem.

04 — The beta list

Your email address

If you join the beta list, we store the address you typed and the date you sent it. Nothing else: not your IP address, not what browser you used.

We use it to send TestFlight invitations and the occasional note about the beta. That's all. It isn't sold, rented or shared, and it isn't used to build a profile of you. Send a request to support and we'll delete it.

Accepting an invitation means handing your address to Apple so TestFlight can mail you. From that point, Apple's privacy policy covers their copy.

05 — Everything else

What we never do

  • No advertising, and nothing sold or rented to anyone.
  • No third-party analytics or tracking scripts, on this site or in the app.
  • No profile built out of your notes, tasks or messages.
  • No access to your notes. The architecture above is what makes that a fact instead of a promise.

06 — Contact

Reaching a person

For privacy questions, deletion requests, or anything else about how Stiicky handles your data, write to [email protected].