Privacy policy
Last updated 8 September 2026
The short version. Your notes live on your devices and in your own iCloud account. We don't have a copy of them, and there's no account to sign up for. The only things that reach a server are the ones you ask for: a note you share, an integration you connect, and your email address if you join the beta.
01 — The app
What the app stores
Stiicky writes your notes as Markdown files inside its iCloud folder. We can't read it. The app sends no analytics, no usage telemetry, and no crash reports with note content in them.
02 — The server
If you use a hosted server
A hosted Stiicky server does the things a phone in your pocket can't: hold a shared note at a link that keeps working, and poll integrations while your devices are asleep. It's built so that most of your data never reaches it at all.
| Data | On the server | How long |
|---|---|---|
| Notes you haven't shared | never sent | — |
| Boards, pins, tags, archive | never sent | — |
| Notes in an active share | stored | Deleted when you revoke the share, or move the note out of it |
| Integration cards in transit | passing through | Deleted once your device confirms it has them |
| OAuth tokens for services you connected | stored | Until you disconnect that account |
| Sync cursors and item IDs | stored | Until you disconnect. IDs only, never content |
| A workspace you opted in to MCP | stored | Deleted when you switch that workspace's opt-in off |
| Link previews | in memory | 10 minutes, and never written to disk |
03 — Google
Google account data
Connecting a Google account is optional, and off until you do it. When you connect one, Stiicky asks for a single Google scope beyond your basic profile:
https://www.googleapis.com/auth/tasks
It's there for one feature: mirroring your Google Tasks lists into Stiicky as cards you can edit. Ticking a box completes the task in Google, renaming a line renames it, adding a line creates it. That's why the access has to be read and write.
The server stores the auth token for the account, and the task and list IDs needed to keep each card pointed at the right task. Task text travels to your device and isn't kept on the server afterwards. Disconnect the account and the token is revoked with Google and its cards are deleted.
Limited Use. Stiicky's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising, we don't sell it, and nobody reads it unless you've asked us for help with a support problem.
04 — The beta list
Your email address
If you join the beta list, we store the address you typed and the date you sent it. Nothing else: not your IP address, not what browser you used.
We use it to send TestFlight invitations and the occasional note about the beta. That's all. It isn't sold, rented or shared, and it isn't used to build a profile of you. Send a request to support and we'll delete it.
Accepting an invitation means handing your address to Apple so TestFlight can mail you. From that point, Apple's privacy policy covers their copy.
05 — Everything else
What we never do
- No advertising, and nothing sold or rented to anyone.
- No third-party analytics or tracking scripts, on this site or in the app.
- No profile built out of your notes, tasks or messages.
- No access to your notes. The architecture above is what makes that a fact instead of a promise.
06 — Contact
Reaching a person
For privacy questions, deletion requests, or anything else about how Stiicky handles your data, write to [email protected].