privacy
Privacy Policy
Last updated: 7 July 2026
This privacy policy is provided in several languages for your convenience. The English version is the authoritative and governing text; if a translation differs from it, the English version prevails.
This policy explains what personal data we collect when you use the getpsst.app website and the Psst apps, why we collect it, and the rights you have over it. It covers both the website (and its email sign-up) and the Psst apps.
Who is responsible for your data
Psst is operated by the maker of Psst. For any privacy question, or to exercise the rights below, email our support address. This is how to reach the data controller.
What we collect
- Your email address, when you submit it through the beta sign-up form on this site.
- Technical data such as your IP address, browser type, and request time, processed by our hosting and security provider when you load any page. We do not run advertising or analytics trackers on this site.
What the Psst app collects
Beyond this website, the Psst apps for iOS and Android handle the data below. Psst is local-first — your lists work on your device without an account — and when you sign in and use sync, this data is stored on our servers so it can sync across your devices and to lists you share.
- Account and profile — your email address (you sign in with an email code, Google, or Apple), your display name, and an optional profile photo.
- Your content — the lists, items, notes, comments and messages, tags, and any photos or files you add. Content in a shared list is visible to the people you invite to it.
- Location — if you set a location reminder, Psst uses your device's precise location, including in the background, so a reminder can fire when you arrive at or leave a place you choose. Your live location is matched against your reminders on your device (geofencing); we do not continuously track you or keep a history of where you go. When you view a map preview of a saved place, that place's coordinates are sent to our server and on to a maps provider (Google Maps, or Wikimedia as a keyless fallback) only to fetch the preview image. We never sell location data or use it for advertising.
- Notifications — a device push token, through Apple's or Google's push service, so we can send your reminders and shared-list notifications.
- Purchases — if you subscribe, the purchase is handled by the App Store or Google Play through RevenueCat; we receive your subscription status, not your card details.
- Diagnostics and analytics — crash and error reports (through Sentry) and a small number of explicit usage events (through PostHog, hosted in the EU, with anonymized IP addresses and no session recording or automatic screen capture), so we can fix problems and see which features are used.
The app also asks, only with your permission, to use your camera and photo library (profile picture and attachments), your microphone (adding items by voice), and your calendar (syncing task due dates to a calendar you choose). Each is used only for that feature, and you can revoke any of them in your device settings. App data is processed by our backend at api.getpsst.app together with Apple and Google (sign-in, push, and App Store / Google Play billing), RevenueCat (subscription status), Sentry (diagnostics), PostHog (EU analytics), and Google Maps or Wikimedia (map previews). We do not sell your personal data or use it for third-party advertising.
Why we collect it, and the lawful basis
- Beta waitlist and launch notifications. We use the email you submit to send you a beta invite and to tell you when the app is available. The lawful basis is your consent, given when you submit the form (GDPR Article 6(1)(a)). You can withdraw it at any time.
- Running the app. Your account, content, and reminders are processed to provide the service you asked for (GDPR Article 6(1)(b)). Location, camera, microphone, and calendar are used only after you grant permission (Article 6(1)(a)), which you can withdraw in your device settings at any time.
- Serving and securing the site. Technical data is processed to deliver pages, prevent abuse, and keep the service available. The lawful basis is our legitimate interest in running a secure website (GDPR Article 6(1)(f)).
Who processes it for us
We share data only with the providers that make the service work, acting on our instructions as processors:
- Cloudflare hosts this site (Cloudflare Pages) and provides its network security; it processes technical data such as your IP address.
- Our backend at api.getpsst.app receives and stores the email you submit through the sign-up form.
We do not sell your personal data.
How long we keep it
We keep your sign-up email until the beta ends and the launch notifications have gone out, or until you ask us to delete it, whichever comes first. Technical request logs are kept only as long as needed for security and troubleshooting, then discarded.
Your rights
Under the GDPR and similar laws you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, and receive it in a portable form. Where we rely on consent, you can withdraw it at any time without affecting earlier processing. To exercise any of these, email our support address.
If you are in the EU or UK and believe we have mishandled your data, you have the right to complain to your local data protection supervisory authority.
Changes to this policy
If we change how we handle your data, we will update this page and move the date at the top.