Privacy Policy v5
About Marvelist
Personal information we collect
- Name, email address, and profile photo (provided by you on registration)
- Account credentials – authentication is handled via Microsoft Entra External ID; plaintext passwords are never stored or held by Marvelist directly.
- Authentication tokens and sign-in session data generated by Microsoft Entra External ID during the login flow.
- Device model, operating system, and app or browser version
- Unique device identifier used for session and authentication management
- Whether the development (TestFlight beta) version is installed
- Session tokens issued on sign-in, stored securely and used for authentication
- Device push token (APNs token), shared with OneSignal to deliver notifications
- Notification preferences and targeting tags (for example, beta vs. production user status)
- Lists, tasks, and items you create or share within the app
- Sharing relationships between users where list sharing is used
- Pages or screens viewed and feature-usage events (for example, that a list was created), identified only by opaque internal identifiers — never the names or contents of your lists, tasks, or events
- Approximate location (country, region, or city) derived from your IP address; we do not retain your full IP address
- Device and browser type, and a cookie-based analytics identifier
- Your account identifier (an opaque UUID) used to recognise the same account across devices; we never send your name or email address to Google
How we get your information and why
We use your information to:
- Create and manage your account
- Provide personalisation within the app
- Enable list sharing with other users you choose to share with
- Authenticate your identity securely across devices
- Send push notifications for reminders and app updates (where you have consented)
- Support Apple Watch and Siri/Shortcuts integrations
- Understand how the web app is used and improve it (web app only, and only where you consent to analytics cookies)
- Maintain service security and detect abuse
Lawful basis under UK GDPR
- Your consent — for push notifications, optional personalisation, and analytics cookies on the web app. You can withdraw consent at any time: for notifications via your device or app settings; for web analytics via the Cookie settings control on the web app; or by contacting help@marvelist.co.uk.
- Contract performance — to provide the core app functionality you have signed up for, including account management, list storage, and sharing.
- Legitimate interests — to maintain the security of the service, prevent abuse, and improve reliability, where these interests are not overridden by your rights.
Sharing with third parties
How we store your information
Your account and content data is stored securely on servers hosted within the United Kingdom and/or European Union. Data is encrypted in transit (TLS) and at rest.
International transfers
Some processors operate outside the UK and EU. Push notification data is processed by OneSignal, and web analytics data by Google, in the United States. Authentication data processed by Microsoft Entra External ID may be processed within the EU or globally depending on Microsoft's regional infrastructure. These transfers are protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework, Microsoft's Data Processing Addendum, and/or Standard Contractual Clauses.
Retention
We retain your personal information for as long as your account remains active. Upon receiving a deletion request, we will remove your personal data within 30 days. Some audit records may be retained for a longer period where required to comply with security or legal obligations. Web analytics data is retained by Google Analytics for a limited period in line with our configured retention settings.
Account deletion
You can delete your account directly from the User Profile section of the app, or by contacting help@marvelist.co.uk. Deletion removes all personal information associated with your account, including your lists, tasks, profile data, protected lists and their keys.
Marvelist Vault (optional extra encryption)
Marvelist Vault is an optional feature that adds an extra layer of encryption to the contents of lists you choose to protect. When you protect a list, its tasks, notes, checklist items and comments are encrypted with keys unique to your account before they are written to our database, so those contents cannot be read directly from the database, a backup, or an export.
This is additional, application-layer encryption on top of the storage-level encryption already applied to all data. It is not end-to-end encryption. The keys are held by Marvelist in a key store kept separate from the database, which means Marvelist can still process your protected content where necessary to provide the service — for example to sync it across your devices or share it with people you choose.
Protected lists are excluded from the Marvelist assistant and AI features, and notifications about them are genericised so their contents do not appear in alerts. A list's name and description, and operational details such as due dates and completion status, are not encrypted by Vault and remain usable across the app. When you first set up Vault you are given a one-time recovery code. We do not store this code; it is your responsibility to keep it safe. Your protected content is included, in readable form, in any data export you request of your own account.
Third-party processors
We use a small number of third-party service providers (sub-processors) to operate Marvelist. These processors act only on our instructions and are contractually bound to protect your data.OneSignal, Inc.
Microsoft Entra External ID (Microsoft Corporation)
Google LLC (Google Analytics)
Backend Infrastructure (Azure and Cloudflare)
Apple, Inc.
Cookies and analytics (web app)
Push notifications
Apple platform features
Apple Watch
Siri and Shortcuts
Beta testing (TestFlight)
- Apple collects crash logs, usage data, and feedback submitted through TestFlight, in accordance with the Apple Privacy Policy.
- Beta builds may include additional diagnostic logging to help us identify and resolve issues. This logging is limited to technical diagnostic data (such as errors and feature usage counts) and does not include the content of your lists or personal data.
- We may use crash and diagnostic data from TestFlight to identify and fix issues before production release.
Your data protection rights
Under UK data protection law, you have the following rights. You are not required to pay any charge to exercise them, and we will respond within one month of receiving your request.- Right of access: Ask us for copies of your personal information.
- Right to rectification: Ask us to correct inaccurate or incomplete information.
- Right to erasure: Ask us to erase your personal information in certain circumstances.
- Right to restriction: Ask us to restrict processing of your personal information.
- Right to object: Object to our processing of your personal information.
- Right to portability: Ask us to transfer your data to another organisation or directly to you.
Children's privacy
Marvelist is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at help@marvelist.co.uk and we will take steps to remove that information promptly.Changes to this policy
How to complain
Have a question about this policy?
Reach out to Tophhie Cloud if you have any questions, concerns, or requests relating to this policy. We'll get back to you as soon as we can.