Privacy Policy
Tical is built so that there is very little about you to hold. The app keeps your time entries on your own disk and never sends them anywhere. This site and the licence server behind it hold your email address and a fingerprint of the machine your licence is bound to - and, if you asked to be told when Tical launches, the address you gave us for that. That is close to the whole story.
Last updated 20 August 2026. Effective from the same date.
What changed: the launch waitlist. It is the first thing on this site that keeps an email
address you were not obliged to give, so it has its own entry in every section below -
including section 6, which until now had no consent in it to withdraw.
1. Who is responsible
The controller of the personal data described here, within the meaning of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), is:
- Dawid Woźnica, trading as Tical Software
- Email: contact@tical.io
We are a one-person operation and have not appointed a Data Protection Officer, which the GDPR does not require of us. Write to the address above and you reach the person who wrote the software.
2. The short version
| What | Why | How long |
|---|---|---|
| Your email address | To identify your purchase and re-issue your licence if you ask | Life of the licence, then the statutory tax period |
| A fingerprint of your computer | To bind one licence to one machine | Same as above |
| Stripe payment references | To match a payment to a licence, and to honour refunds | Same as above |
| Your email address, if you joined the launch waitlist | To send you one email when Tical ships, and to honour the launch price | Until that email goes out, or until you unsubscribe - whichever is first |
| Your IP address | Rate limiting and abuse prevention | In memory only, or a few days in server logs |
| Your time entries | Never collected - they stay on your computer | - |
There is no advertising, no tracking pixel and no session recording. We do not profile you and we make no automated decisions about you. The only measurement of any kind is a plain daily total - how many downloads went out, how many discount codes were revealed, how many people joined the waitlist - with nothing attached to it that could point at a person, yours or anyone's (section 4.3). We have never sold personal data and will not.
There is one mailing list, and it is the launch waitlist: one email, when Tical ships, to people who asked for it. It is not a newsletter, there is no second message planned, and nothing you do on this site adds you to it except typing your address into one of those forms (section 4.5).
3. The desktop app sends nothing
This is the part most people care about, so it comes first. The Tical application that runs on your computer:
- stores everything - projects, entries, tags, settings - in a single SQLite file on your own disk;
- contains no telemetry, no usage analytics and no crash reporting;
- verifies your licence key offline, against a signature it checks locally. It does not contact this server to confirm that you are allowed to run it, and it will keep working if this server disappears entirely;
- records only the entries you start and stop yourself. It does not watch your screen, read window titles or log which applications you use. While a timer is running it notices that the machine has gone idle, purely so it can ask what to do with the gap when you stop - that check happens on your machine and is never transmitted to us.
If you turn on cloud sync, Tical writes an encrypted copy of your database to your own Google Drive, using credentials you grant to your own account. That data goes from your computer to your Drive. It does not pass through us and we cannot read it. Your use of Google Drive is governed by Google's privacy policy, not this one.
Plugins and exporters you install - including the Jira, ClickUp, Toggl and Clockify integrations - talk directly to whichever service you configure them for, under your own credentials. Those transfers are between you and that provider.
4. What the licence server stores
This website and the licence server behind it are the only places where we hold data about you. Concretely:
4.1 When you buy Tical
Checkout happens on Stripe's own pages. Card numbers never reach our server and we could not store them if we wanted to - this server holds no Stripe secret key at all. After a successful payment Stripe notifies us, and we record:
- your email address, exactly as you gave it to Stripe;
- the Stripe checkout session and payment intent
identifiers (strings such as
cs_live_…andpi_…); - the edition you bought, the highest major version your licence covers, and the time of purchase;
- a random redemption token, which is what the link in your receipt points at.
We do not receive your card details, your billing address or your name from Stripe, and we do not ask for them.
4.2 When you activate your licence
On the activation page you paste a hardware code that the app generates on your computer. When we issue your key we record, in an append-only log:
- your email address;
- the hardware fingerprint contained in that code (see section 5);
- the licence identifier, edition, issue date and version ceiling;
- the signed licence key itself, so we can send it to you again if you lose it.
4.3 When you simply visit
Our server sees your IP address on every request, as any web server does. We use it for one purpose: to count requests per address so that a single visitor cannot exhaust the service for everybody else. Those counters live in memory and are discarded when the window closes.
IP addresses also appear in ordinary server logs, along with the request path, timestamp and browser user-agent string. One administrative action - an operator revealing a full licence key - is deliberately recorded together with the operator's IP address, so that access to customer keys leaves a trail.
Log entries that mention an email address show it masked (for example
cu•••@example.com). The administration screens show masked addresses too; the
full value is revealed only by an explicit, logged and rate-limited action.
Three things are counted, and only as running totals: how many downloads we served on a given day, how many times each hidden discount code was handed out, and how many people joined the waitlist from each of the three forms on the home page. A tally is a date, a name and a number - nothing is attached to it. No address, no cookie, no identifier, no record of who or which visit, and so nothing in it that could be traced back to you or matched against anything else. The waitlist tally in particular holds no address and never did; it is a count beside the list, not a copy of it, which is also why erasing your entry does not leave a hole in it. We keep all three to know whether anyone is interested in Tical, which is a question a total answers completely.
4.4 When you send feedback
The feedback form stores exactly what you type into it: whether it is a feature request or a bug report, your summary, your description, and the date. There is no account behind it and nothing is collected in the background.
The email field on that form is optional and exists for one reason - so that we can reply to you about what you sent. Leave it blank and your submission carries no identifier at all. If you do fill it in, it is shown masked in our administration screens like every other address, and it is not added to the waitlist. The two are separate lists kept for separate reasons, and the only way onto the waitlist is to ask (section 4.5).
Please do not paste licence keys, passwords or anything else confidential into the form. If you do, tell us and we will delete the entry.
4.5 When you join the launch waitlist
Tical is not on sale yet. The three forms on the home page exist so that we can tell you when it is, and so that you get the launch price when we do. Joining one stores your email address, which of the three forms you used, the date, and nothing else about you - no IP address kept with it, no cookie, no profile.
We use it for one email: the one that says Tical has shipped. There is no newsletter behind it and no second message planned. If we ever want to send you something else, we will ask first.
Signing up twice does not create a second entry - the second attempt is treated as a no-op, and the answer you get back is the same either way, on purpose: we do not want this form to be a way for a stranger to find out whether an address is on the list.
You can leave at any moment, without giving a reason and without writing to anyone. Two ways, both of which mark the entry so nothing further is sent to it: the confirmation page carries a one-click unsubscribe link, and /unsubscribe takes the address you signed up with, for when that link is long gone. That form answers identically whether or not the address was ever on the list - for the same reason the signup form does, and with the same consequence, which is that it cannot confirm to you that it found you. Prefer to be erased outright rather than marked? Ask, and the row goes (section 10).
If you also answered the optional question on that page - what would make you buy - the answer is stored with your entry, so that we can tell what people asked for and, if it is something we build, tell you. It is free text you chose to write; please keep confidential things out of it, as with the feedback form.
5. About the hardware fingerprint
A Tical licence is tied to one computer, which means we need something stable to tie it to. The app reads four identifiers from your machine - the Windows machine GUID, and the serial numbers of the motherboard, the BIOS and the system drive - and, for each one separately, computes a SHA-256 hash and keeps only the first sixteen hexadecimal characters.
What that means in practice:
- We never see your actual serial numbers. We see four short hashes.
- The hashes cannot be reversed into the serials, though they are stable, so they work as a persistent identifier for that specific machine. Under the GDPR that makes them personal data, and we treat them as such.
- Values that cannot be read, or that are known manufacturer placeholders, are simply omitted.
- We index this fingerprint in order to enforce one licence per machine. We do not use it to recognise you anywhere else, and it tells us nothing about what is on your computer.
6. Why we are allowed to hold it
- Performance of a contract (Art. 6(1)(b) GDPR) - issuing your licence, binding it to your machine, re-issuing it when you get a new computer and handling refunds are all steps in the contract you entered when you bought Tical. Without your email address and hardware code there is no licence to issue.
- Legal obligation (Art. 6(1)(c) GDPR) - Polish tax and accounting law requires us to keep records of completed sales.
- Legitimate interests (Art. 6(1)(f) GDPR) - keeping the service available and preventing abuse of the activation and download endpoints, which is why we count requests per IP address and log administrative access to keys. We consider this a mild intrusion, plainly expected of any online service, and it is balanced against the very real harm of the service being knocked over or licences being harvested.
- Consent (Art. 6(1)(a) GDPR) - the launch waitlist, and only that. Typing your address into one of those forms and submitting it is the consent; nothing else on this site asks for any, and nothing else relies on it.
You can withdraw that consent whenever you like, and it is deliberately no harder than giving it: the one-click link on the confirmation page, or a message to us. It takes effect immediately, costs you nothing, and does not affect anything else - a licence you bought is contract, not consent, and keeps working either way. Withdrawing does not undo the fact that we held the address up to that point, which is what the GDPR means by consent being withdrawable "without affecting the lawfulness of processing based on consent before its withdrawal".
For everything else on this page there is no consent for you to withdraw - but you can object to the processing based on legitimate interests, as described in section 10.
7. Who else sees it
We use as few outside services as we can. The complete list:
| Who | What they receive | Role |
|---|---|---|
| Stripe Stripe Payments Europe, Ltd. |
Everything you enter at checkout: card details, email address, billing country, and the payment record itself | An independent controller for the payment. Their privacy policy applies to it |
| GitHub GitHub, Inc. / Microsoft |
Your IP address and browser user-agent, when you download the app | Release hosting. See below |
| [HOSTING PROVIDER] | Whatever passes through the server, as its operator | Processor, under a data processing agreement |
The GitHub case is worth spelling out. The application binaries live in a private repository, so when you click a download link our server asks GitHub for a short-lived signed URL and then redirects your browser to it. Your browser fetches the file directly from GitHub's content delivery network, which means GitHub - not us - sees your IP address and user-agent for that request. The bytes never pass through our server, and no account or identifier of yours is attached to the URL.
Beyond that: TLS certificates come from Let's Encrypt, and nothing else on this site is loaded from a third party. There are no fonts, scripts, frames or images fetched from anyone else's servers, so no other company learns that you visited. That is also true of the waitlist form - it posts to this server, not to a mailing provider, which is the reason there is no fourth row in the table above.
One addition is coming, and only one. This server cannot send email, so the single launch message will be sent through an email delivery provider, and the list will be exported to it for that purpose. We have not chosen one yet. When we do it will be named here, with the same three columns as the rows above, before the mail is sent - a processor added quietly after the fact would make this section untrue for the period that mattered most.
We may also disclose data where the law requires it - for instance to a tax authority or in response to a valid court order.
8. Transfers outside the EEA
Stripe and GitHub are able to process data in the United States. Those transfers rest on the European Commission's Standard Contractual Clauses and, where applicable, on the providers' certification under the EU-US Data Privacy Framework. You can ask us for details of the safeguards in place.
Our own server and its backups are located in [SERVER LOCATION / COUNTRY].
9. How long we keep it
- Licence and purchase records - for as long as your licence is valid, which for a perpetual licence means indefinitely, because we need to be able to prove it is yours and re-issue it when your hardware changes. Once a licence is no longer in use, the records attached to a completed sale are still kept until the end of the statutory Polish accounting retention period, which is five years counted from the end of the tax year of the transaction.
- Feedback submissions - until the request or bug is dealt with and we no longer need the context, after which the entry is deleted. Unlike the issuance log, this one does have a delete button, and asking us to remove yours is enough.
- Waitlist entries - until the launch email has been sent, or until you unsubscribe, whichever comes first. Unsubscribing marks the entry rather than deleting it, for one reason: a mark is what stops a later export mailing you again, and a deleted row cannot do that. Ask and it is deleted outright instead - that one is a button, not a hand-edited database. Once the launch mail has gone out the list has served its only purpose and is removed.
- Server logs - rotated automatically. We keep roughly the last 50 MB of output, which in normal traffic is a matter of days, and we do not archive it.
- Database backups - taken nightly and kept off the server. Old backups age out on a rolling schedule, so a record you ask us to delete may persist in a backup for a short time after we remove it from the live database. We do not restore backups in order to recover deleted data.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify it if it is wrong - a mistyped email address, for example;
- erase it, where we have no overriding reason to keep it;
- restrict processing while a dispute about accuracy is resolved;
- port it to another provider in a structured, machine-readable form;
- object to processing we base on legitimate interests;
- withdraw consent for the launch waitlist at any time - the one-click link on the confirmation page and the form at /unsubscribe are that right, exercised without asking anyone (section 6).
To exercise any of these, email contact@tical.io. We reply within one month, and normally much sooner. We may ask you to confirm control of the email address on the purchase, because that address is essentially the only thing linking the record to a person - we will not ask you for identity documents.
On erasure specifically. If you ask us to delete your data we will do it, with two honest caveats. First, records of a completed sale must be retained for the tax period described above; the GDPR permits us to refuse erasure on that ground (Art. 17(3)(b)), so what we can do in the meantime is restrict the record from any other use. Second, deleting a licence record means we can no longer prove the licence is yours or re-issue it if your computer changes - your existing installation will keep working, because it verifies offline, but you would be buying again rather than asking for a replacement. We will say so before acting. Neither caveat applies to a waitlist entry: there is no sale behind it and nothing depends on it, so that one is simply deleted when you ask.
If you think we have handled your data badly, please tell us first - but you are entitled to go straight to a supervisory authority. Ours is the Polish Urząd Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. You may also complain to the authority where you live or work.
11. Cookies and tracking
This site sets no cookies for visitors. Not one. There is no consent banner because there is nothing to consent to.
A single cookie, tical_admin, exists on the administration pages, which only the
operator can reach. It holds a sealed session token, is marked HttpOnly,
Secure and SameSite=Strict, expires after twelve hours, and is
strictly necessary for the operator to stay logged in.
Nor is there any substitute for cookies. We do not use local storage or browser fingerprinting, and nothing here recognises a returning visitor. The activation page carries your redemption token in the address bar of the link from your receipt, and keeps no copy of it.
One exception, and it is worth describing precisely. When you join the
waitlist, your browser holds the signup's token in sessionStorage for the length
of that tab - it is what lets the next page attach your answer to your signup, and what puts
the token into the unsubscribe link. It is not an identifier for you, it is not read on any
later visit, your browser discards it when the tab closes, and the page clears it as soon as it
is used. It is in sessionStorage rather than in the address bar so that it does
not end up in your history or in a link you paste to somebody.
The same goes for the launch-price bar at the bottom of the home page and the SDK page. If you
dismiss it, your browser remembers that in sessionStorage so it does not come back
at you while you keep reading. It holds one true-or-false value, it says nothing about you, it
never reaches us, and it goes when the tab does.
12. Security
Proportionate to a small service holding a small amount of data:
- everything is served over HTTPS;
- the application runs in a hardened, read-only container with dropped privileges, reachable only through a reverse proxy on the host;
- signing keys and secrets are mounted as files, never committed to source control and never exposed by the application;
- administration is protected by a long random key and a sealed session cookie, and its endpoints are rate-limited;
- email addresses are masked by default in logs and in the administration screens;
- backups are stored off the server.
No system is perfect. If a breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and tell you directly where the risk is high. If you have found a vulnerability, please write to contact@tical.io - we would much rather hear it from you.
13. Children
Tical is a tool for working adults and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has purchased a licence, contact us and we will unwind it.
14. Changes to this policy
If we change what we collect or who receives it, we will update this page and move the date at the top. Where the change is significant and we hold your email address because you bought a licence, we will email you about it. Previous versions are available on request.
Questions about any of this: contact@tical.io. See also our Terms of Service.