Privacy Policy

Your data, without the fog

nowish needs account, group, and task data to run a shared todo list. Task text is normally encrypted before it leaves your device. Reports and beta screenshots are deliberate readable exceptions explained below.

Effective: July 17, 2026 · Applies to: the nowish Android app and nowish.ca

Closed-beta transparency notice

nowish is in an invite-only closed beta. This page describes the current implementation honestly, including its unfinished parts: a complete published retention schedule and a firm off-site backup lifecycle are still being finalized, and the sections below say so where it matters.

Who operates nowish

nowish is owned and operated by Caleb Binder, an independent developer doing business as a sole proprietor from Alberta, Canada. This is the same legal name used on the Google Play developer listing.

For privacy questions or requests, email privacy@nowish.ca. For general questions and support, email contact@nowish.ca. Both inboxes are monitored. Beta testers can also use the feedback button in the app. Do not reply to automated messages from noreply@nowish.ca; that address only sends account emails and is not read.

What nowish collects

Account and security data

Your email address, display name, account identifier, timezone, a salted one-way password verifier, login-session tokens, records of which Terms version you accepted, and temporary hashed verification or recovery records. For encrypted accounts, nowish also stores public keys, encrypted private-key envelopes, password-derivation parameters, group-key wraps, and encrypted recovery material.

Data kept on your device

The app keeps its server address, session token, account identifier, display name, tutorial progress, and an encrypted convenience copy of the account’s private identity key in private app storage. The key copy is protected with a non-exportable Android Keystore key. Android cloud backup is disabled for nowish. Signing out clears the session and key cache; clearing app storage or uninstalling clears the local copy, but does not by itself delete the server account.

Shared task data

Group membership and roles; invitation, mute, block, and removal state; task schedules, recurrence rules, priority and assignment settings; due, seen, completion, snooze and undo history; and records needed to send reminders and keep devices synchronized. The current Android client encrypts group names, task names, and task-step text on the device before upload. The server stores the ciphertext plus structural metadata and authenticated authorship/revision metadata.

Push notifications

If Firebase messaging is available and your device registers for it, nowish stores a Firebase Cloud Messaging device token. Push messages contain a content-free “sync” signal rather than task, group, or member names. Android notification permission controls whether notifications are shown, but the current beta does not yet offer an in-app control that deletes a registered token on demand.

Moderation reports and safety records

When you select an item to report, nowish temporarily reserves a readable text snapshot of that group, task, step, or member plus enough group context to verify it. This prevents an edit, deletion, or group removal from erasing the evidence while you complete the form. Submission erases the duplicate reservation copy immediately. An unsubmitted reservation becomes unusable after 15 minutes, and the next routine cleanup erases its readable evidence (normally within one minute while the service is running, or on the next startup/request cleanup). A content-free rate-limit marker—account and target identifiers, timestamps, and a one-way token hash—may remain for up to one hour. If you submit, nowish also receives the report category, your optional explanation, your account and display-name snapshot, and app version. A report does not include an encryption key or screenshot. nowish stores review status and an audit trail of moderator actions. Personal blocks and enforced group-removal bans are also stored.

Closed-beta feedback

If you send beta feedback, nowish receives the type of feedback, your message, app version and version code, and your account identifier when you are signed in. Opening the feedback sheet creates a screenshot preview on your device. The preview is uploaded as a PNG only if you explicitly select “Include screenshot” before sending. A screenshot can contain any account, group, task, member, or other information visible on screen, so review the preview before choosing to include it.

Technical and operational data

The server processes network addresses and request metadata to establish encrypted connections and route requests. Application and container logs may contain timestamps, requested paths, response status, and error details. nowish also keeps operational records such as notification deliveries and missed task occurrences. There is no advertising SDK and no third-party product-analytics or profiling SDK in the current app.

What the app does not request

The current Android app does not ask for location, camera, microphone, contacts, phone, or photo-library permission, and it does not use an advertising identifier. A beta feedback screenshot is made from pixels already visible inside nowish; it does not read your photo library.

Why the data is used

nowish does not sell personal information, show ads, build advertising profiles, or use your task text for advertising.

Encryption and the honest limits

Traffic between the app and nowish.ca uses TLS. The current app encrypts group, task, and step text with group keys on the device. Passwords are not stored in plaintext.

Password recovery is designed to restore an encrypted account after an email-code check. To make that possible, the service operates recovery key material separately from the account database. That means nowish should not claim that operator access to encrypted content is mathematically impossible. The recovery path is intended only to restore user access, and ordinary moderation does not use it: reporting sends the selected readable snapshot directly from the reporting member’s device.

Encryption does not hide content from people in the group who have a group key, from someone who can unlock your device, from a screenshot you choose to send, or from a moderation report you choose to file.

Administrative and moderation interfaces require separate operator tokens. The production moderation process is deliberately separated from the service recovery key, and moderator actions are recorded in an append-only audit trail.

Who receives data

These providers process data to supply their service; nowish does not give them data for their own advertising. The nowish server itself is hosted in British Columbia, Canada. Firebase and Resend may process data outside Canada under their own infrastructure and contractual arrangements.

Retention and deletion

Live account and task records remain while the account or relevant group exists, unless a user or authorized group member deletes an item through an available app control. Reset and deletion codes expire quickly. Purpose-separated HMAC records for deletion codes and their rate-limit counters are purged after one hour; password-reset code records do not yet have an equivalent documented purge schedule. Feedback, reports, moderation audit records, operational records, and server logs likewise do not yet have a complete published retention schedule. Defining and enforcing one is a pre-launch requirement.

Deleting your account permanently disables the original email and credentials, removes account sessions, recovery material, device tokens and personal preferences, and replaces the remaining account identity with a pseudonymous former-member record. Groups in which you are the only member are deleted. A group shared with other people remains for them; your key access and membership are removed and your attribution is stripped. Moderation evidence, audit history, and historical group-ban records may remain for safety, abuse prevention, and record integrity. A retained ban record stays attached only to the deleted account ID; it does not automatically restrict a new account later registered with the former email. Structured account-email and profile-name fields are removed from retained safety records. Free-text report reasons, moderator notes or escalation records, and reported group, task, or step text may remain as evidence and could independently mention identifying context. See the exact process at Delete your account.

The repository’s default local-backup retention is 14 days. An off-site backup, if configured, requires a separate storage lifecycle and a firm maximum has not yet been documented. Deletion from live systems therefore does not currently carry a promised maximum time for disappearance from every backup. This must be resolved before a public release.

Your choices

A portable data export and a self-service verified privacy-inquiry workflow are not implemented yet; the My data page accurately tracks what is and is not currently available. In the meantime, a privacy request emailed to privacy@nowish.ca is handled manually, with reasonable identity verification before any account data is discussed or changed.

Children

nowish is not directed to children under 13 and does not knowingly invite them to create accounts. Child-safety reports are treated as urgent. A parent or guardian can make a privacy request without installing the app by emailing privacy@nowish.ca.

Changes

This page will change as the beta fills the gaps identified above. Material changes to the Terms or Community Rules use a new version and may require acceptance in the app. The effective date at the top will be updated when this Privacy Policy changes.