Tophhie Cloud Trust Center / Policies
Marvelist Active Last updated 26 August 2026

Privacy Policy v6

Data controller: Tophhie Cloud, United Kingdom
Address: Disclosed upon request to help@marvelist.co.uk
General enquiries: help@marvelist.co.uk
Privacy requests: privacy@tophhie.cloud

About Marvelist

Marvelist is a tasks, lists, and personal organisation service available as an iOS and watchOS app and as a web application at app.marvelist.co.uk. It includes features such as list creation and management, item and event sharing, Apple Watch integration, Siri and Shortcuts support, and push notifications for reminders and updates.

This policy applies to all users of Marvelist across these platforms, including those using the production release and those participating in the beta programme via TestFlight. Some sections apply to a specific platform only; where that is the case it is indicated (for example, analytics cookies apply to the web app only).

Personal information we collect

We collect only what is necessary to provide and improve the Marvelist service.

Account and identity information

  • Name, email address, and profile photo (provided by you on registration)
  • Account credentials – authentication is handled via Microsoft Entra External ID; plaintext passwords are never stored or held by Marvelist directly.
  • Authentication tokens and sign-in session data generated by Microsoft Entra External ID during the login flow.

Device and session information

  • Device model, operating system, and app or browser version
  • Unique device identifier used for session and authentication management
  • Whether the development (TestFlight beta) version is installed
  • Session tokens issued on sign-in, stored securely and used for authentication

Push notification information

  • Device push token (APNs token), shared with OneSignal to deliver notifications
  • Notification preferences and targeting tags (for example, beta vs. production user status)

Usage and content data

  • Lists, tasks, and items you create or share within the app
  • Sharing relationships between users where list sharing is used

Analytics information (web app)

Where you consent to analytics cookies on the web app (see the Cookies and analytics section below), we collect, via Google Analytics:

  • Pages or screens viewed and feature-usage events (for example, that a list was created), identified only by opaque internal identifiers — never the names or contents of your lists, tasks, or events
  • Approximate location (country, region, or city) derived from your IP address; we do not retain your full IP address
  • Device and browser type, and a cookie-based analytics identifier
  • Your account identifier (an opaque UUID) used to recognise the same account across devices; we never send your name or email address to Google

Analytics cookies are off by default and are collected only if you accept them.

Product usage analytics (all platforms)

Separately from cookies, we collect a small set of usage analytics across the iOS app, watchOS app, and web app, and record equivalent events directly from our backend (for example, when a subscription starts or a plan limit is reached). This helps us understand which features are used and where people run into limits. Each event includes:

  • A fixed event name describing what happened (for example, that a paywall was shown) — never the name or contents of anything you created
  • The platform (iOS, watchOS, web, or our backend) and app version
  • Your account identifier, used to avoid double-counting and to apply consistent sampling per account
  • A short category label describing where in the app the event happened, and sometimes a second label with a specific detail (for example, "annual")
  • A single number where relevant (for example, a plan limit)
  • The time the event occurred

We do not collect, as part of this: the names or contents of your lists, tasks, notes, or events; search terms or any other free text you enter; your email address or display name; precise location; your IP address; advertising identifiers; or any special category data.

See the Product usage analytics section below for the lawful basis for this collection and how to object to it.

We do not collect: precise location data, advertising identifiers, financial information, or any special category data as defined under UK GDPR.

How we get your information and why

Most personal information is provided directly by you during registration or use of the app. Some information (such as device identifiers and session tokens) is generated automatically as part of normal app operation.

We use your information to:

  • Create and manage your account
  • Provide personalisation within the app
  • Enable list sharing with other users you choose to share with
  • Authenticate your identity securely across devices
  • Send push notifications for reminders and app updates (where you have consented)
  • Support Apple Watch and Siri/Shortcuts integrations
  • Understand how the web app is used and improve it (web app only, and only where you consent to analytics cookies)
  • Maintain service security and detect abuse
  • Understand how the app is used across iOS, watchOS, and the web app, and improve it (see Product usage analytics)

Lawful basis under UK GDPR

We rely on the following lawful bases, depending on the type of processing:
  • Your consent — for push notifications, optional personalisation, and analytics cookies on the web app. You can withdraw consent at any time: for notifications via your device or app settings; for web analytics via the Cookie settings control on the web app; or by contacting help@marvelist.co.uk.
  • Contract performance — to provide the core app functionality you have signed up for, including account management, list storage, and sharing.
  • Legitimate interests — to maintain the security of the service, prevent abuse, improve reliability, and understand how the product is used across platforms so we can improve it (see Product usage analytics), where these interests are not overridden by your rights.

Sharing with third parties

We will only share your personal information with law enforcement agencies where required under UK law. Law enforcement will be required to provide a justifiable reason and formal order before we release any information. See the Third-party processors section for disclosures about processors (such as OneSignal and Google) used to operate the service.

How we store your information

Your account and content data is stored securely on servers hosted within the United Kingdom and/or European Union. Data is encrypted in transit (TLS) and at rest.

International transfers

Some processors operate outside the UK and EU. Push notification data is processed by OneSignal, and web analytics data by Google, in the United States. Authentication data processed by Microsoft Entra External ID may be processed within the EU or globally depending on Microsoft's regional infrastructure. These transfers are protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework, Microsoft's Data Processing Addendum, and/or Standard Contractual Clauses. Product usage analytics data is processed using Cloudflare Analytics Engine, part of Cloudflare's global network, and may be processed in the United States. These transfers are protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework and/or Standard Contractual Clauses.

Retention

We retain your personal information for as long as your account remains active. Upon receiving a deletion request, we will remove your personal data within 30 days. Some audit records may be retained for a longer period where required to comply with security or legal obligations. Web analytics data is retained by Google Analytics for a limited period in line with our configured retention settings.

Product usage analytics data is retained in Cloudflare Analytics Engine for up to three months, after which it is automatically deleted.

Account deletion

You can delete your account directly from the User Profile section of the app, or by contacting help@marvelist.co.uk. Deletion removes all personal information associated with your account, including your lists, tasks, profile data, protected lists and their keys.

Marvelist Vault (optional extra encryption) 

Marvelist Vault is an optional feature that adds an extra layer of encryption to the contents of lists you choose to protect. When you protect a list, its tasks, notes, checklist items and comments are encrypted with keys unique to your account before they are written to our database, so those contents cannot be read directly from the database, a backup, or an export. 

This is additional, application-layer encryption on top of the storage-level encryption already applied to all data. It is not end-to-end encryption. The keys are held by Marvelist in a key store kept separate from the database, which means Marvelist can still process your protected content where necessary to provide the service — for example to sync it across your devices or share it with people you choose. 

Protected lists are excluded from the Marvelist assistant and AI features, and notifications about them are genericised so their contents do not appear in alerts. A list's name and description, and operational details such as due dates and completion status, are not encrypted by Vault and remain usable across the app. When you first set up Vault you are given a one-time recovery code. We do not store this code; it is your responsibility to keep it safe. Your protected content is included, in readable form, in any data export you request of your own account.

Third-party processors

We use a small number of third-party service providers (sub-processors) to operate Marvelist. These processors act only on our instructions and are contractually bound to protect your data.

OneSignal, Inc.

Push notification delivery. Receives your APNs device token and notification targeting tags. Data processed in the United States under appropriate safeguards. See OneSignal Privacy Policy.

Microsoft Entra External ID (Microsoft Corporation) 

User authentication and identity management. Microsoft Entra External ID handles account registration, sign-in, and identity token issuance for all Marvelist users. When you create an account or sign in, your email address, name, and authentication credentials are processed by Microsoft Entra External ID on our behalf. Data may be processed within the EU or globally on Microsoft's infrastructure under appropriate safeguards, including Microsoft's Data Processing Addendum and Standard Contractual Clauses. See Microsoft Privacy Statement.

Google LLC (Google Analytics)

Web analytics for the Marvelist web app only, used where you consent to analytics cookies. Receives usage events, an analytics cookie identifier, your account UUID (as a User-ID), and approximate location derived from your IP address. We do not send your name or email address. Data may be processed in the United States under appropriate safeguards. Google Consent Mode is configured so that no analytics cookies are set until you consent. See Google Privacy Policy.

Backend Infrastructure (Azure and Cloudflare)

Cloud hosting and managed database services used to store app data. Servers located in the United Kingdom and/or European Union.

Apple, Inc.

Apple Push Notification service (APNs) is used to deliver notifications to your device. Apple's handling of notification routing is governed by the Apple Privacy Policy.

Cloudflare, Inc. (Analytics Engine)

Product usage analytics described in the Product usage analytics section is processed and stored using Cloudflare Workers Analytics Engine, a distinct product from the general hosting infrastructure listed above. This data may be processed globally, including in the United States, under appropriate safeguards such as the UK extension to the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Data is retained for up to three months. See Cloudflare Privacy Policy.

Cookies and analytics (web app)

This section applies to the Marvelist web app at app.marvelist.co.uk only. The iOS and watchOS apps do not use cookies for analytics.

This section covers cookie-based web analytics only. For the separate, non-cookie product usage analytics collected across all Marvelist platforms, see the Product usage analytics section below.

Essential cookies

We use a small number of strictly necessary cookies to keep you signed in and to operate the service securely. These are required for the app to function and are not used for analytics or advertising.

Analytics cookies

With your consent, we use Google Analytics to understand how the web app is used so that we can improve it. Analytics cookies are off by default. We use Google Consent Mode, which means no analytics cookies are set and no analytics identifiers are stored until you accept them.

Your choice and how to withdraw it

When you first use the web app, a banner lets you accept or reject analytics cookies. You can change your decision at any time using the Cookie settings link on the sign-in screen, or the Analytics cookies control in your account's Privacy settings. Rejecting or withdrawing consent stops analytics cookies and prevents your account identifier from being associated with analytics data going forward.

Product usage analytics

This section applies across the iOS app, watchOS app, web app, and our backend, and describes the product usage analytics referenced in Personal information we collect.

What we collect and why

We collect a narrow set of feature-usage events — for example, that a paywall was shown, or that a plan limit was reached — tagged with your account identifier, platform, app version, and timestamp. We use this to understand which features are used and how the app performs across platforms, so we can prioritise improvements. We never collect the names or contents of your lists, tasks, notes, or events, search terms, free text, your email address or display name, precise location, your IP address, or advertising identifiers as part of this analytics.

Lawful basis

We rely on our legitimate interests in understanding and improving Marvelist, having considered that the data collected is limited, excludes the content of anything you create, and does not identify you beyond your existing account. You have the right to object at any time.

How to opt out

Product usage analytics is on by default. You can turn it off for your account at any time: in the web app, go to Account → Privacy and switch off Share usage analytics. This preference applies to your whole account, so turning it off in the web app also stops collection from the iOS and watchOS apps, and takes effect immediately. An equivalent control is coming to the iOS and watchOS apps in a future release; this policy will be updated when it ships. You can also object by contacting privacy@tophhie.cloud or help@marvelist.co.uk.

Retention

Product usage analytics data is retained in Cloudflare Analytics Engine for up to three months, after which it is automatically deleted.

Push notifications

Marvelist may send push notifications to your device for reminders and app updates. Push notifications require your explicit consent, which iOS will request when you first use the app.

To send notifications, your device's APNs token is shared with OneSignal (see the Third-party processors section). We may apply targeting tags to your notification profile — for example, to distinguish between production and beta users — so that we can send relevant communications to the right audience.

You are in control. You can disable push notifications at any time via iOS Settings > Notifications > Marvelist, or by managing your preferences within the app. Disabling notifications does not affect your account or any other app functionality.

Apple platform features

Apple Watch

When using Marvelist on Apple Watch, your list and task data is synchronised between your iPhone and Apple Watch via WatchConnectivity. No additional personal data is collected solely by virtue of using the Apple Watch app. Data transferred to the watch is stored on-device and subject to Apple's own security model.

Siri and Shortcuts

Marvelist supports Siri and Apple Shortcuts to allow you to interact with your lists using voice commands or automations. When you use Siri or Shortcuts with Marvelist, Apple may process your voice input and intent data in accordance with the Apple Privacy Policy. We do not receive your voice input or raw Siri data. We only receive the resolved intent (for example, "add item X to list Y") that iOS passes to the app.

Beta testing (TestFlight)

Marvelist beta versions are distributed via Apple TestFlight. If you are a TestFlight beta tester, please be aware that:
  • Apple collects crash logs, usage data, and feedback submitted through TestFlight, in accordance with the Apple Privacy Policy.
  • Beta builds may include additional diagnostic logging to help us identify and resolve issues. This logging is limited to technical diagnostic data (such as errors and feature usage counts) and does not include the content of your lists or personal data.
  • We may use crash and diagnostic data from TestFlight to identify and fix issues before production release.
Beta testers are subject to the same data rights and protections described in this policy. If you wish to stop participating in the beta, you can remove the TestFlight app and contact us to request removal from the beta programme.

Your data protection rights

Under UK data protection law, you have the following rights. You are not required to pay any charge to exercise them, and we will respond within one month of receiving your request.
  • Right of access: Ask us for copies of your personal information.
  • Right to rectification: Ask us to correct inaccurate or incomplete information.
  • Right to erasure: Ask us to erase your personal information in certain circumstances.
  • Right to restriction: Ask us to restrict processing of your personal information.
  • Right to object: Object to our processing of your personal information.
  • Right to portability: Ask us to transfer your data to another organisation or directly to you.
To exercise any of these rights, contact us at privacy@tophhie.cloud or help@marvelist.co.uk.

Children's privacy

Marvelist is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at help@marvelist.co.uk and we will take steps to remove that information promptly.

Changes to this policy

We may update this policy from time to time. When we make material changes, for example, introducing a new type of data collection or a new third-party processor, we will notify you via push notification and/or email before those changes take effect.

The "last updated" date at the top of this page will always reflect when the policy was most recently revised. We encourage you to review it periodically.

How to complain

If you have concerns about how we handle your personal information, please contact us first — we'd like the opportunity to put things right.

Email: help@marvelist.co.uk

If you remain unhappy with our response, you have the right to complain to the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113

Have a question about this policy?

Reach out to Tophhie Cloud if you have any questions, concerns, or requests relating to this policy. We'll get back to you as soon as we can.

Contact us about this policy