Privacy

What TidyCards knows about you, why, and what happens to it.

Last updated on September 9, 2026

In short

TidyCards keeps what it needs to run an account and show lists, and nothing it does not. We run no advertising, we sell nothing about you and hand nothing to anyone, and no tracker follows you anywhere else. We do measure how the service is used, and we are told when something breaks — through PostHog, on servers in the European Union, without a cookie; the section on what is measured says exactly what that involves.

What you write — your lists, your items, the searches that find something — is never sent to anyone. There is one exception, described below: the words of a search that came back empty.

What we keep

Four kinds of things. We ask for nothing the service does not use.

Your account

The address you sign in with, your name, your username, and your password — stored hashed with scrypt, a deliberately slow algorithm, so that not even we can read it back.

What you choose to add to your profile: a bio, pronouns, links, a profile picture, a cover image, and whether the profile is public. All of it is optional, and a profile starts private.

Your preferences: language, theme, time zone, which emails you want, and whether your use of the service may be measured.

The date you last used TidyCards, and nothing more: not the pages you opened, not the device you were on. It is what lets us write to you once if you stop coming, and it is the only thing of its kind that outlives your sessions.

If you sign in with Google: the identifier, the address and the name Google hands us, so we can recognise you next time. We get no password, and no access to anything else in your Google account. Your Google profile picture is copied once into our own storage rather than loaded from Google every time a page shows it.

What you make

Your lists and what is in them, the lists you like and save, who works on which list with you, and the invitations sent — including the address an invitation was sent to, which is stored encrypted with a separate fingerprint beside it so that it can be found again without being read.

For each link you save, what the page said about itself when you saved it: its title, its description, a picture, sometimes the name of its author. We do not fetch it again unless you ask us to.

Pictures you upload

A profile picture, a cover, an image on an item. Each is re-encoded on arrival into three sizes, and we do not keep the file you sent, so what cameras and phones write into a photograph, including where it was taken, never reaches our storage.

What we do not keep

No payment details, because nothing is payable. No postal address, no telephone number, no date of birth. No record, anywhere, of what you do on other sites.

Where you are signed in

Each device you sign in on is a session, and for each session we keep the address it connects from, what its browser calls itself, when it was opened and when it was last seen. That is what lets the security settings list your devices and let you sign out any of them, and what lets us end every session at once when a password changes or an account is suspended.

The city shown next to a device is worked out on our own server from its address, with a database we download once a month; the address is sent to nobody. A session ends thirty days after its last activity, or when you sign it out. A visitor who never signs in is forgotten after a day.

Cookies

TidyCards sets cookies of its own, and no one else’s until you allow it. One carries the identifier of your session — nothing more: whether you are signed in, the token that protects forms, the message shown after an action and the mark that keeps your visit to a list from being counted twice are kept on our server, in the session the identifier points at, not in the cookie. Three others remember your language, theme and time zone for a year, so a page arrives already in them. A fourth, described below, remembers which players you have allowed. None of them follows you anywhere else, and we use none of them to measure or advertise.

A card can hold a player the site it came from draws itself — a page of theirs inside this one, which can set cookies of its own. It stays turned off until you press the button that allows it, and that button names the site. Each site is allowed on its own, and the answer is kept on this device for a year.

Pictures on the cards

A card shows the picture the linked site published for it, and that picture does not come from them: TidyCards takes a copy the first time a card asks for it, keeps it on its own storage and serves it from there. Opening a list of twenty links therefore does not tell twenty sites that you are reading it, and none of them learns your IP address, the time, or which page you are on.

What is left is video. A video file is still played from the server that hosts it, because taking a copy would mean every minute watched passing through here — so that server does see the cards carrying a video. A third-party player stays turned off until you allow it, as “Cookies” above says.

Emails

We write to you when an account needs it: to confirm an address, to reset a password, to tell the old address when the sign-in address changes, to carry an invitation, to say somebody added you to a list. The last of these can be switched off in the notification settings; the others cannot, because without them an account cannot be operated. We send nothing else — no newsletter, no promotion.

Technical logs

Our server keeps no record, in its own logs, of the pages you visit — what is measured is described in the next section. It writes a line when something goes wrong — a fault, a request that should not have been possible — with the time, an identifier of the request and what happened, so that the fault can be understood; your address is not part of it. These lines are capped rather than kept: the server holds the last thirty megabytes of them and drops the oldest, which at our scale is a matter of weeks, and they are read only when a fault is being looked into.

What is measured

One service does this, PostHog, on its servers in the European Union. Everything below goes there and nowhere else.

What is sent

The pages you open and what you do on them — opening a list, adding an item, running a search — with the time, the kind of browser and the size of the screen. An item added also says how its card is drawn and, where its link points at a site we know how to draw a player from, which one: “YouTube”, “Spotify” — the site’s name and never the address. When you are signed in they are tied to your account’s identifier, so that a question like “how many of the people who create a list add something to it” can be answered.

They are never tied to your name or your address, and none of it is used for advertising or handed to anyone. We have PostHog discard the address your browser connects from rather than keep it — but an approximate location is worked out from that address before it goes, and stays with the event: a country, a region, a city and the coordinates of its centre. The country lets us answer a regulator asking how many people in the Union use this service.

Searches that find nothing

When a search comes back with no results, the words you typed are sent with it, so that we know what people are looking for here and not finding, and can do something about it. A search that finds something sends the number of results and never the words.

This is the only place where something you wrote leaves the service.

When something breaks

The error goes to the same service with the page it happened on, the kind of browser and, if you are signed in, your account’s identifier, so that the fault can be found and fixed. A fault is reported whether or not you have turned the measurement off — what breaks still has to be repaired — but then without your identifier on it.

Nothing is written to your browser

No cookie, nothing in its storage. That is why no banner asks for your consent: there is nothing on your device to ask about. It also means that until you sign in, each visit counts as a new visitor, and we live with the imprecision.

Turning it off

A switch in your preferences stops it for your account. With it off, the page is not even given the address to send to, so nothing leaves your browser, and the server refuses to name you in anything it sends. It takes effect on the next page you open, and nothing that was already counted is unwound.

How many people read a list or a profile

When you open a list’s page, or somebody’s profile, we add one to that page’s counter. The counter keeps nothing about you: a page, an hour, a number, and nothing that tells you apart from anyone else. It stays on our servers and goes to no one.

A visit, not a refresh

So that the same visit is not counted twice, your session remembers which pages you have already been counted on, for half an hour. That is kept on our server, inside the session, and erased with it. Coming back to a page after half an hour of quiet counts again.

Where you arrive from

Every visit is filed under a category: from the service itself, from a search engine, from a social network, from another site, or directly. We keep the category and never the address of the page you came from.

Who sees them

Whoever holds the list, whoever the profile belongs to, and the people who run the service. They see numbers and curves, never people — because nothing ever named them. The only distinction drawn is between visits from signed-in accounts and visits from people without one.

How long

The hour-by-hour detail is erased after ninety days. The daily totals stay, because they no longer say anything about anyone.

The preferences switch does not stop it

As with faults, and for the same reason: this counter does not carry your name, so there is nothing to take off it. What the switch does cut stays cut — none of these numbers goes to PostHog, and nothing there ties them to your account.

Who sees what

A public profile and a published list are visible to anyone, account or not, and a published list may be shown on Discover. An unlisted list is visible to whoever has its address. A private list is visible to you and to the people you invited onto it. Somebody you invite sees your name and the title of the list in the invitation.

Nobody else does. We do not share what we keep with anyone, except the companies that help run the service, named below, and except where the law obliges us to.

When the law asks

A court or an authority can require us to hand over what we hold about an account. We answer such a request, we hand over what exists, and we say what does not.

French law makes a service like this one keep, for a year, whatever it collects that would identify who created a piece of content. We do not collect it: no address is recorded beside a list, an item or a comment, so there is nothing of that kind to produce. The decree obliges keeping what is collected; it does not oblige collecting it.

What exists is the account as it stands — its address, its declared name, its username, when it was created, what it published and when — the sessions of the last thirty days with the address they connect from, and the record of decisions taken about the account. Nothing is verified here: the name on an account is whatever somebody typed.

Who helps run it

Three companies handle data for us, each for one task, each under a contract that forbids using it for anything else. We use no fourth, and none of them is paid in data.

  • The hosting provider, which rents us the server: everything stored is on it — the database, the pictures you upload, the lists. In the European Union.
  • PostHog, for measuring use and receiving faults, on its servers in the European Union.
  • The service that delivers our emails, which sees the address a message goes to and what it says.
  • Google, only if you choose to sign in with Google — and not for us: it acts on its own account, under its own terms, and what comes back to us is an identifier, an address and a name.

Where it is

In the European Union, and we send nothing outside it. Our hosting provider uses suppliers of its own, some outside the Union, under the standard contractual clauses the Commission publishes for that; that is its arrangement rather than a transfer we decided.

The database that turns an address into a city is a file on our own server, from DB-IP, downloaded once a month. Nothing is sent to DB-IP, and the About page credits it as its licence asks.

How it is kept

The measures below are the ones worth naming, because they are the ones that would matter if something went wrong.

  • Passwords are stored hashed with scrypt and never in a readable form; a password reset does not reveal the old one because nobody can.
  • The address an invitation was sent to is stored encrypted, with a separate fingerprint used to find it again.
  • Sessions live on our server and can be ended one at a time or all at once — changing a password ends every one of them.
  • Everything travels over HTTPS, and the browser is told to refuse anything else.
  • The pages carry a policy that lets no third party run code on them.
  • Uploaded pictures are re-encoded, and what a camera wrote into the file does not survive it.

If something goes wrong anyway

We have a written procedure for it, and it commits us to the two things the law asks: telling the data protection authority within seventy-two hours where the breach is likely to be a risk, and telling you directly where it is likely to be a high risk to you. No procedure makes a breach impossible. Having one written down is what lets us act at once.

How long

Your account and what you made stay as long as the account is open. Everything else has a term, and a job on our server applies it every night.

If you stop using TidyCards for two years, we write to tell you, and unless you sign in within thirty days we close the account — then erase it thirty days after that, like any closed account. Signing in is all it takes to stop it, and the two years start again. We do it because personal data is kept for as long as it is needed and no longer.

  • An account nobody has used for two years: closed thirty days after we write to you, then erased thirty days later.
  • A closed account: thirty days, then everything on it that names you is erased.
  • A session: thirty days after its last activity, or as soon as you sign it out.
  • The date you last used the service: as long as the account is open.
  • A visitor who never signs in: forgotten after a day.
  • An invitation nobody accepted: it stops working after seven days, and the record of it is deleted ninety days later.
  • A password-reset link: one hour. A confirmation link: one day.
  • What is measured: one year, at PostHog.
  • Technical logs: the last thirty megabytes, which at our scale is a matter of weeks.
  • A moderation decision and who took it: kept without term, which the law allows for establishing and defending legal claims.

When you close your account

Your lists go out of circulation, every device is signed out, and the account is marked closed. Thirty days later everything on it that names you is erased: your address, your username, your name, what your profile said and the pictures on it.

Ask us sooner and we do it sooner — write to us and we erase it rather than waiting the thirty days out.

The erasure empties the account of everything that names you, which is what the right to erasure is for, and leaves its row in place so the lists and items other people work on stay where they are, without an author. It also frees your username for somebody else to take.

Children

You must be at least 15 to open an account, the age French law sets for deciding about your own data online. Both sign-up pages say so before you finish.

We do not ask for proof of age and we do not keep an answer: there is no column here saying how old anybody is, and verifying it would mean collecting far more about everybody than the question is worth.

That means we act on what we are told. If somebody reports an account as a child’s, or a moderator sees it while reading a list, the account is suspended while we look and closed if the doubt holds. A parent or guardian can report it the same way anybody else does, and can write to the address at the foot of this page.

On what grounds

The law asks us to say by what right we keep any of this, purpose by purpose. There are three answers here, and no fourth.

Most of it is the agreement between you and this service: you asked for an account and for lists, and there is no way to give you those without keeping them. Some of it the law requires — answering a report of illegal content, telling both sides what was decided, and keeping a record of it. The rest rests on our own legitimate interest, a ground that only holds where what we gain is real, where there is no gentler way to get it, and where it does not override what you could reasonably expect. Where we rely on it, you can object; the section on your rights says how.

We ask for your consent for one thing only: a player from another site does not load until you press the button that allows it.

  • Your account, your profile, your lists and what is in them, the transactional emails that keep them working, and signing in with Google — the agreement between you and this service.
  • Receiving a report about a list or an item, deciding it, and writing to the person who reported it and the person who made it — a legal obligation under the Digital Services Act.
  • Keeping a record of who decided what, and when — a legal obligation for the moderation part, and our own interest in being able to answer for the rest.
  • Sending an invitation to an address somebody gave us — our interest in letting people work on a list together. It is sent once, never followed up, and the record of it is deleted ninety days later.
  • Sessions, rate limits and technical logs — our interest in keeping accounts and the service safe from someone trying passwords in bulk or from a fault nobody reported.
  • Measuring what is used and being told when something breaks — our interest in knowing whether the service works. Nothing is written to your browser for it, and the section on what is measured says exactly what is sent.

Your rights

All of them, and where each one is answered. Three of them you can exercise yourself, right now, without asking anybody.

See and correct

Everything your account holds is in your settings, and every part of it can be changed there — your name, your username, your bio, your links, your preferences, and your address with a confirmation to both the old one and the new. If something is wrong and you cannot change it yourself, write to us.

Get a copy

The download in your settings gives you everything at once, as a JSON file: your account, your profile, your lists and their items, your likes and saves, the lists you are on, the invitations you sent and received, your sessions, and what has been decided about your account.

It answers two rights at the same time — the copy the law lets you ask for, and the machine-readable form you can take to another service. It leaves out only what belongs to somebody else: which administrator took a decision, items on a shared list that you did not write, and reports somebody filed about you.

Be erased

Closing your account starts it, and thirty days later we have finished; ask and we finish sooner. What survives is what no longer names you, and the record of decisions taken about the account, which the law lets us keep for establishing and defending legal claims.

Object

Where we rely on our own legitimate interest, you can object. For the measurement that is a switch in your preferences. For anything else on that ground — the sessions, the rate limits, the logs — write to us and say which, and we will weigh it rather than answer with a form.

Restrict, and be told

You can ask us to hold off using something while a disagreement is settled. There is no button for that: write to us and we suspend the account for as long as it takes. Nothing is deleted in the meantime.

Whatever you ask, we answer within a month. If we cannot, we say so and why before the month is out.

Complain

If you think we have handled your data badly you can complain to the data protection authority where you live — in France, the CNIL — and you can do that without writing to us first.

Changes to this page

This page changes when what TidyCards does changes. The date at the top says when it last did, and a change that widens what we keep or who sees it will be announced on the service before it applies.

Contact

For anything about your data — a question, a request, an erasure — write to legal@tidy.cards.

See also