Privacy Policy v6
About Marvelist
Personal information we collect
Account and identity information
- Name, email address, and profile photo (provided by you on registration)
- Account credentials – authentication is handled via Microsoft Entra External ID; plaintext passwords are never stored or held by Marvelist directly.
- Authentication tokens and sign-in session data generated by Microsoft Entra External ID during the login flow.
Device and session information
- Device model, operating system, and app or browser version
- Unique device identifier used for session and authentication management
- Whether the development (TestFlight beta) version is installed
- Session tokens issued on sign-in, stored securely and used for authentication
Push notification information
- Device push token (APNs token), shared with OneSignal to deliver notifications
- Notification preferences and targeting tags (for example, beta vs. production user status)
Usage and content data
- Lists, tasks, and items you create or share within the app
- Sharing relationships between users where list sharing is used
Analytics information (web app)
Where you consent to analytics cookies on the web app (see the Cookies and analytics section below), we collect, via Google Analytics:
- Pages or screens viewed and feature-usage events (for example, that a list was created), identified only by opaque internal identifiers — never the names or contents of your lists, tasks, or events
- Approximate location (country, region, or city) derived from your IP address; we do not retain your full IP address
- Device and browser type, and a cookie-based analytics identifier
- Your account identifier (an opaque UUID) used to recognise the same account across devices; we never send your name or email address to Google
Analytics cookies are off by default and are collected only if you accept them.
Product usage analytics (all platforms)
Separately from cookies, we collect a small set of usage analytics across the iOS app, watchOS app, and web app, and record equivalent events directly from our backend (for example, when a subscription starts or a plan limit is reached). This helps us understand which features are used and where people run into limits. Each event includes:
- A fixed event name describing what happened (for example, that a paywall was shown) — never the name or contents of anything you created
- The platform (iOS, watchOS, web, or our backend) and app version
- Your account identifier, used to avoid double-counting and to apply consistent sampling per account
- A short category label describing where in the app the event happened, and sometimes a second label with a specific detail (for example, "annual")
- A single number where relevant (for example, a plan limit)
- The time the event occurred
We do not collect, as part of this: the names or contents of your lists, tasks, notes, or events; search terms or any other free text you enter; your email address or display name; precise location; your IP address; advertising identifiers; or any special category data.
See the Product usage analytics section below for the lawful basis for this collection and how to object to it.
How we get your information and why
We use your information to:
- Create and manage your account
- Provide personalisation within the app
- Enable list sharing with other users you choose to share with
- Authenticate your identity securely across devices
- Send push notifications for reminders and app updates (where you have consented)
- Support Apple Watch and Siri/Shortcuts integrations
- Understand how the web app is used and improve it (web app only, and only where you consent to analytics cookies)
- Maintain service security and detect abuse
- Understand how the app is used across iOS, watchOS, and the web app, and improve it (see Product usage analytics)
Lawful basis under UK GDPR
- Your consent — for push notifications, optional personalisation, and analytics cookies on the web app. You can withdraw consent at any time: for notifications via your device or app settings; for web analytics via the Cookie settings control on the web app; or by contacting help@marvelist.co.uk.
- Contract performance — to provide the core app functionality you have signed up for, including account management, list storage, and sharing.
- Legitimate interests — to maintain the security of the service, prevent abuse, improve reliability, and understand how the product is used across platforms so we can improve it (see Product usage analytics), where these interests are not overridden by your rights.
Sharing with third parties
How we store your information
Your account and content data is stored securely on servers hosted within the United Kingdom and/or European Union. Data is encrypted in transit (TLS) and at rest.
International transfers
Some processors operate outside the UK and EU. Push notification data is processed by OneSignal, and web analytics data by Google, in the United States. Authentication data processed by Microsoft Entra External ID may be processed within the EU or globally depending on Microsoft's regional infrastructure. These transfers are protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework, Microsoft's Data Processing Addendum, and/or Standard Contractual Clauses. Product usage analytics data is processed using Cloudflare Analytics Engine, part of Cloudflare's global network, and may be processed in the United States. These transfers are protected by appropriate safeguards, such as the UK extension to the EU-US Data Privacy Framework and/or Standard Contractual Clauses.
Retention
We retain your personal information for as long as your account remains active. Upon receiving a deletion request, we will remove your personal data within 30 days. Some audit records may be retained for a longer period where required to comply with security or legal obligations. Web analytics data is retained by Google Analytics for a limited period in line with our configured retention settings.
Product usage analytics data is retained in Cloudflare Analytics Engine for up to three months, after which it is automatically deleted.
Account deletion
You can delete your account directly from the User Profile section of the app, or by contacting help@marvelist.co.uk. Deletion removes all personal information associated with your account, including your lists, tasks, profile data, protected lists and their keys.
Marvelist Vault (optional extra encryption)
Marvelist Vault is an optional feature that adds an extra layer of encryption to the contents of lists you choose to protect. When you protect a list, its tasks, notes, checklist items and comments are encrypted with keys unique to your account before they are written to our database, so those contents cannot be read directly from the database, a backup, or an export.
This is additional, application-layer encryption on top of the storage-level encryption already applied to all data. It is not end-to-end encryption. The keys are held by Marvelist in a key store kept separate from the database, which means Marvelist can still process your protected content where necessary to provide the service — for example to sync it across your devices or share it with people you choose.
Protected lists are excluded from the Marvelist assistant and AI features, and notifications about them are genericised so their contents do not appear in alerts. A list's name and description, and operational details such as due dates and completion status, are not encrypted by Vault and remain usable across the app. When you first set up Vault you are given a one-time recovery code. We do not store this code; it is your responsibility to keep it safe. Your protected content is included, in readable form, in any data export you request of your own account.
Third-party processors
We use a small number of third-party service providers (sub-processors) to operate Marvelist. These processors act only on our instructions and are contractually bound to protect your data.OneSignal, Inc.
Microsoft Entra External ID (Microsoft Corporation)
Google LLC (Google Analytics)
Backend Infrastructure (Azure and Cloudflare)
Apple, Inc.
Cloudflare, Inc. (Analytics Engine)
Product usage analytics described in the Product usage analytics section is processed and stored using Cloudflare Workers Analytics Engine, a distinct product from the general hosting infrastructure listed above. This data may be processed globally, including in the United States, under appropriate safeguards such as the UK extension to the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Data is retained for up to three months. See Cloudflare Privacy Policy.
Cookies and analytics (web app)
Essential cookies
Analytics cookies
Your choice and how to withdraw it
Product usage analytics
This section applies across the iOS app, watchOS app, web app, and our backend, and describes the product usage analytics referenced in Personal information we collect.
What we collect and why
We collect a narrow set of feature-usage events — for example, that a paywall was shown, or that a plan limit was reached — tagged with your account identifier, platform, app version, and timestamp. We use this to understand which features are used and how the app performs across platforms, so we can prioritise improvements. We never collect the names or contents of your lists, tasks, notes, or events, search terms, free text, your email address or display name, precise location, your IP address, or advertising identifiers as part of this analytics.
Lawful basis
We rely on our legitimate interests in understanding and improving Marvelist, having considered that the data collected is limited, excludes the content of anything you create, and does not identify you beyond your existing account. You have the right to object at any time.
How to opt out
Product usage analytics is on by default. You can turn it off for your account at any time: in the web app, go to Account → Privacy and switch off Share usage analytics. This preference applies to your whole account, so turning it off in the web app also stops collection from the iOS and watchOS apps, and takes effect immediately. An equivalent control is coming to the iOS and watchOS apps in a future release; this policy will be updated when it ships. You can also object by contacting privacy@tophhie.cloud or help@marvelist.co.uk.
Retention
Product usage analytics data is retained in Cloudflare Analytics Engine for up to three months, after which it is automatically deleted.
Push notifications
Apple platform features
Apple Watch
Siri and Shortcuts
Beta testing (TestFlight)
- Apple collects crash logs, usage data, and feedback submitted through TestFlight, in accordance with the Apple Privacy Policy.
- Beta builds may include additional diagnostic logging to help us identify and resolve issues. This logging is limited to technical diagnostic data (such as errors and feature usage counts) and does not include the content of your lists or personal data.
- We may use crash and diagnostic data from TestFlight to identify and fix issues before production release.
Your data protection rights
Under UK data protection law, you have the following rights. You are not required to pay any charge to exercise them, and we will respond within one month of receiving your request.- Right of access: Ask us for copies of your personal information.
- Right to rectification: Ask us to correct inaccurate or incomplete information.
- Right to erasure: Ask us to erase your personal information in certain circumstances.
- Right to restriction: Ask us to restrict processing of your personal information.
- Right to object: Object to our processing of your personal information.
- Right to portability: Ask us to transfer your data to another organisation or directly to you.
Children's privacy
Marvelist is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at help@marvelist.co.uk and we will take steps to remove that information promptly.Changes to this policy
How to complain
Have a question about this policy?
Reach out to Tophhie Cloud if you have any questions, concerns, or requests relating to this policy. We'll get back to you as soon as we can.