Privacy policy
1. The short version
Five things worth knowing before the detail:
- You can use String without an account. Reminders are written to a database on your device. If you never sign in, they are never uploaded.
- Signing in is what turns on sync. Once you do, your reminders are stored in Google Cloud Firestore so your devices agree.
- Voice notes never leave your device. Recordings are saved to local storage. They are not uploaded, not synced, and not transcribed.
- There is no usage tracking and there are no ads. No analytics product, no advertising SDK, no advertising identifier. The only thing the app sends about itself is a crash report when it breaks.
- This website collects nothing at all. No analytics, no cookies, no third-party fonts, and access logging is switched off.
What we do not collect
To be explicit, because most apps in this category do collect all of it:
- No analytics product of any kind — no PostHog, no Google Analytics, no Firebase Analytics, no Mixpanel, no Amplitude, no Segment
- No advertising SDK and no ads, rewarded or otherwise
- No advertising identifier
- No location, coarse or precise
- No contacts, calendar, photos or files
- No behavioural profiling, and no automated decision-making
2. Who we are
String is made by Do It And Be Done, a business established in the United States. For privacy law purposes we are the data controller for the personal data described here.
- Contact for privacy matters and data requests: string-support@doitandbedone.com
3. What we collect
3.1 The things you create
Reminder titles and notes, dates and repeat rules, todo lists, sub-items and their order, completion state, and any voice notes you record.
This content is free text — whatever you type is what gets stored. If you are not signed in, all of it stays in the local database on that device and we never see it. If you are signed in, everything except voice notes is mirrored to Firestore so it can reach your other devices.
Voice notes are the exception and stay local on every platform. They are written to your device's storage and are not part of sync.
3.2 Account data
If you create an account, Firebase Authentication stores your email address, a unique user ID, and — if you sign in with Google — the basic profile that Google returns. We use this to know which reminders are yours and to let you sign in on another device. We do not have access to your Google password.
3.3 Shared reminders
If you share a reminder or a collection with someone, that content becomes visible to the people you shared it with, along with the fact that it came from you. Sharing is always an explicit action on a specific item. Nothing is shared in the background, and there is no public directory of users.
3.4 Crash reports
The Android app uses Firebase Crashlytics. This is the only diagnostic data the app sends, and it is sent only when something goes wrong.
When String crashes or freezes, Crashlytics sends a stack trace, the device model and operating system version, the app version, the state of the app at the time, and a Crashlytics installation identifier. That identifier lets us tell whether one person hit the same crash five times or five people hit it once; it is not used to build a profile of you and it is not combined with anything else.
Crash reports are not intended to contain your reminder text, and we do not attach it.
We keep Crashlytics because a reminders app that silently fails to fire a reminder is a broken product, and crash reports are how we find out. It is the one piece of telemetry we decided was worth keeping, and it only fires when the app has already failed you.
3.5 Purchases
If you buy a subscription, the transaction runs through Google Play Billing and is managed by RevenueCat. They receive a purchase token, product ID, country, and your String account ID so entitlements follow you between devices. We never see or store your card details — payment is handled entirely by Google Play.
3.6 This website
This site sets no cookies, runs no analytics, and loads no third-party resources — no CDN, no hosted fonts, no tag manager. That is why you were never shown a consent banner: there is nothing to consent to. We have also switched off access logging at our web host, so visits to this site are not recorded. See the cookie policy.
4. Who else receives data
Each of these is a processor or independent controller acting on the data described above.
| Who | What they get | Their policy |
|---|---|---|
| Google Firebase Authentication, Firestore, Crashlytics |
Account email and user ID; your synced reminders; crash diagnostics and the device data attached to them. | firebase.google.com/support/privacy |
| RevenueCat Subscriptions |
Purchase tokens, product IDs, country, your String account ID. | revenuecat.com/privacy |
| Google Play Billing and distribution |
Payment details, which we never receive. | policies.google.com/privacy |
| DreamHost Website hosting |
Requests to this website. Access logging is disabled, so request logs are not retained. | dreamhost.com/legal/privacy-policy |
We do not sell your personal information. We do not share it for advertising of any kind. We do not disclose it to data brokers. There is no advertising SDK in the app, so there is nothing to share even if we wanted to.
5. Legal bases (GDPR)
If you are in the EU, EEA, UK or Switzerland, we rely on these grounds:
- Performance of a contract (Art. 6(1)(b)) — holding your account, syncing your reminders, delivering sharing, and providing subscriptions you paid for.
- Legitimate interests (Art. 6(1)(f)) — crash reporting, so that we can keep the app working. We have weighed this against your interests: the data is limited to diagnostics, it is only sent when the app actually fails, it is not used to profile you, and you can object at any time and we will act on it. This is the only processing we base on legitimate interests.
- Legal obligation (Art. 6(1)(c)) — keeping transaction records where tax or accounting law requires it.
We do not rely on consent for anything, because we no longer do anything that would need it.
String is a general productivity app and is not designed to collect special-category data under Article 9. Reminders are free text, so please avoid putting health, religious or similarly sensitive details into them if you would rather they were not synced.
6. Your rights and how to use them
Wherever you live, you can ask us to:
- Access — get a copy of what we hold about you
- Rectify — correct anything wrong
- Erase — delete your account and its data
- Port — receive your reminders in a machine-readable format
- Restrict — have us pause processing while a dispute is resolved
- Object — to processing based on legitimate interests, which here means crash reporting
How to make a request
Email string-support@doitandbedone.com with what you want and the email address on your account. We respond within 30 days. If a request is complex we may extend by a further 60 days and will tell you why within the first 30.
We will ask you to confirm you control the account email. We will not ask you for identity documents for a routine request.
You also have the right to complain to your data protection authority. In the EU that is your national regulator; in the UK it is the Information Commissioner's Office.
7. US state privacy rights (CCPA/CPRA)
If you are a California resident — and, in substance, if you are in another US state with a comparable law — this section is for you.
Categories we collect
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Email, account ID, Crashlytics installation ID | Yes |
| Commercial information | Subscription purchases | Yes |
| App diagnostics | Crash traces, device model, OS version | Yes, on crash only |
| Your content | Reminder text, lists, sub-items | Only if you sign in and sync |
| Audio | Voice notes | Recorded, but kept on your device — we never receive them |
| Internet or network activity | Browsing or app-usage history | No. There is no analytics SDK in the app. |
| Advertising identifiers | — | No. There is no advertising SDK in the app. |
| Geolocation | — | No, neither precise nor coarse. |
| Biometric information | — | No |
| Sensitive personal information | — | We do not seek any. See section 5. |
Do we sell or share your personal information?
No. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we never have. There is no advertising SDK in the app and no advertising identifier is collected, so there is no mechanism by which this could happen.
Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" link to provide. Global Privacy Control signals sent by your browser are honoured by this website regardless.
Other California rights
- Right to know — the categories and specific pieces we hold, the sources, and the purposes
- Right to delete — subject to legal retention exceptions
- Right to correct — inaccurate personal information
- Right to limit use of sensitive personal information — we do not collect any, so there is nothing to limit
- Right to non-discrimination — exercising a right will never get you worse service, a higher price, or a degraded app
Exercise any of these at string-support@doitandbedone.com. You may use an authorised agent; we will ask for written proof of authorisation.
8. How long we keep things
| Data | Kept for |
|---|---|
| Reminders on your device | Until you delete them or uninstall the app. Entirely under your control. |
| Synced reminders in Firestore | Until you delete them. Account deletion is handled on request — email us and we remove your synced data within 30 days. |
| Voice notes | On your device only, until you delete the reminder. |
| Account record | Deleted within 30 days of you asking us to close your account. |
| Crash reports | Crashlytics keeps these for 90 days. |
| Purchase records | As long as tax and accounting law requires, typically 7 years. |
| Website server logs | Not retained — access logging is switched off on our web host. |
Deleting your account removes your synced data. It does not reach back into copies that other people already have of reminders you shared with them.
9. Security
Data travelling between the app and our services is encrypted in transit with TLS. Data at rest in Firestore is encrypted by Google. Firestore security rules restrict each account's documents to that account. Access to production systems is limited to people who need it.
Data stored on your own device is protected by your device's encryption and lock screen — so a device passcode is worth having.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data we will notify you and the relevant regulator within the timeframes the law sets — 72 hours for GDPR.
10. Children
String is not directed at children. You must be at least 13 to use it, or 16 where your country sets a higher age for digital consent. We do not knowingly collect personal data from children below that age. If you believe a child has given us data, email us and we will delete it promptly.
11. International transfers
We are established in the United States, and our service providers process data there as well. Firebase Authentication, Firestore, Crashlytics and our API gateway all run in US regions. If you are in the EU, EEA or UK, that means your data is transferred to the United States.
These transfers rely on the European Commission's Standard Contractual Clauses, the UK Addendum where applicable, and — for providers that are certified — the EU-US Data Privacy Framework.
12. Changes to this policy
When we change this policy we update the version number and effective date at the top. For anything that materially affects your rights or expands what we collect, we will tell you in the app before it takes effect, and where the law requires it we will ask for your consent rather than assume it.
Previous versions are available on request.
Change history
- Version 2.0 (27 August 2026) — removed PostHog, Google Analytics for Firebase and Google AdMob from the app. String no longer collects usage analytics, no longer serves advertising of any kind, and no longer collects an advertising identifier. Crash reporting is unchanged.
- Version 1.0 (26 August 2026) — first published.
13. Contact
- Privacy, data requests, support, bugs and feature requests: string-support@doitandbedone.com