Privacy Policy — Last Done
last updated 24 September 2026
The short version: Last Done works without an account, and then everything you enter stays on your phone. If you choose to sign in (with Apple or Google) and subscribe, your lists are also stored on our server in the European Union so they can sync between your devices. The App sends anonymous crash reports and usage statistics so we can fix problems and improve it — they are not linked to your account — and you can switch this off in Settings. There are no ads and no tracking across apps. Payments go through Apple or Google, with RevenueCat handling subscription status; we never see your card. You can export everything to a file at any time and delete your account from inside the app.
Last Done (“the App”) is published by Best App Maciej Gorzala, the studio behind KiddoWise (“we”, “us”). This policy explains, in plain language, what the App stores, where, and why — and what you can do about it. The App is a tool for adults and is not directed at children.
Data that stays on your phone
Without an account, the App is entirely local. It keeps, on your device:
- Your lists and the things on them — names, icons, colours, intervals, notes, whether reminders are on, and the order you arranged them in.
- Your completions — the day you marked something done and how (from the App, a reminder, or a widget).
- Settings — theme, language, whether due dates are on, and the time of day for reminders.
None of this is sent to us. It is removed when you delete the App — with one caveat: your phone’s own backup (Google backup on Android, iCloud backup on iOS) may include the App’s data, like it does for most apps, under the backup settings of your device and Apple’s or Google’s own privacy terms. We do not receive those backups.
Reminders
Reminders are scheduled and shown by your phone itself; they are never sent through a server. On Android 13 and later the App asks for the notification permission first. A reminder contains the name of the thing it is about, so it may be visible on your lock screen.
Widgets
Home-screen widgets draw from a copy of your list that the App writes to storage shared with the widget on the same device. It never leaves the phone.
Export and import
You can save your whole list as a JSON file (lists, things, completions, settings, and the App version that wrote it) through your phone’s share sheet, and load such a file back. Where you send that file — a cloud drive, a message, your computer — is your choice, and it is covered by that service’s privacy terms, not ours.
Your account (optional)
You can sign in with Apple or Google. We use Supabase for accounts, and this is what an account consists of on our server:
- a random account identifier we create,
- the identifier Apple or Google assigns to you for our App,
- your email address as provided by Apple or Google — with Apple you may choose “Hide My Email”, in which case we get a relay address,
- with Google, the basic profile information carried in its sign-in token (your name and profile picture URL), which the App does not display or use.
When you sign in with Apple, the App asks Apple for your name and email, but only Apple’s identity token reaches our server; your name is not stored by us.
Your sign-in session is kept in the Keychain on iOS and in encrypted storage on Android. Signing in on its own does not upload your lists — that only happens with an active subscription (see the next section). Signing out leaves everything on your phone untouched.
Cloud sync (with a subscription)
With an active subscription, the App keeps your data in sync with our server so it can follow you to another phone. What is stored on the server:
- your lists and their names;
- the things on them — name, icon, colour, interval, note, reminder setting, archive state, order, and when they were created and changed;
- your completions — the day, how they were made, and which account made them;
- markers for things you deleted, so that the deletion reaches your other devices. A deleted thing is not shown anywhere, but its marker stays until you delete the account.
The server is hosted by Supabase in the European Union. Access is enforced on the server for every row: only your account can read or write your data. We use this data solely to provide sync; we do not analyse it, sell it, or use it for advertising.
When the subscription ends, the server stops sending and accepting changes. Nothing is deleted: your phone keeps its complete copy, and your data stays on the server, ready if you subscribe again — or until you delete your account.
Subscription and payments
The subscription is bought through the App Store or Google Play and billed by Apple or Google. We never receive your payment details.
We use RevenueCat to know whether a subscription is active. RevenueCat receives the purchase receipt from the store, an app-specific user identifier that we set to your account identifier, and basic device and App information (such as platform and App version). RevenueCat then tells our server your subscription’s product, status, and expiry date — that is all our server keeps about it. RevenueCat’s own privacy policy governs its processing.
Crash reports and usage statistics
To find out what breaks and what works, the App sends anonymous crash reports and usage statistics. This is on by default, and you can switch it off at any time in Settings → About → Share anonymous usage and crash reports. Switching it off takes effect immediately, including for anything still waiting to be sent. It applies whether or not you have an account.
The App never puts the names of your lists, things, or people, your notes, your email, or your account identifier into them, and neither is linked to your account (see the one exception we cannot control, under crash reports). We use them only to fix and improve the App — not for advertising, and not to follow you across other apps or websites.
Crash reports (Sentry)
When the App runs into an error, it sends a report to Sentry, hosted in the European Union (Germany). A report contains:
- the type of error and where in the App’s code it happened (a stack trace);
- the App version and build;
- the device model and manufacturer, operating-system version, screen and memory details, language and time zone;
- a random identifier that Sentry creates for this installation.
For errors in the App’s own code, we strip every error message and description before the report leaves the phone, keeping only the type of error, its location in the code, and our own fixed labels. Crashes in the phone’s system or in third-party components (for example, the sign-in or purchase libraries) are reported by those components directly, and the system’s own error message may be included — we cannot filter those messages. We have told Sentry not to store IP addresses, and the App sends no screenshots, screen recordings, or record of what you tapped.
A report can also come from the “Done” button on a reminder, if that fails. Sentry keeps crash reports for up to 90 days.
Usage statistics (TelemetryDeck)
The App sends a small set of anonymous signals to TelemetryDeck, hosted in the European Union:
- that the App was opened (a session);
- that you started, finished, or skipped the introduction screens;
- that a thing was added — only whether it was your first, second, or a later one;
- that a thing was marked done in the App;
- that the subscription offer was shown, and from which part of the App;
- that a subscription was bought (monthly or yearly) or restored;
- that you signed in, and whether with Apple or Google.
Each signal also carries the App version, device model, operating-system version, language, region, time zone, and your device’s accessibility settings (such as text size). It is tied to a random identifier for this installation, which is hashed on your phone and hashed again by TelemetryDeck; on iOS the identifier may be derived from the one your phone shares between apps from the same developer. Times are rounded to the hour, and TelemetryDeck does not store IP addresses. TelemetryDeck keeps these statistics without a fixed deletion date.
When the App goes online
The App connects to the internet for the account, sync, and subscription features, and for crash reports and usage statistics, as described above. Like any internet request, these carry your device’s IP address and standard request details, which the providers involved (Supabase, RevenueCat, Sentry, TelemetryDeck, Apple, Google) may record in ordinary, transient server logs. We do not use such logs to profile you.
Without an account, the App connects only to send crash reports and usage statistics — and not even that once you switch them off.
Third parties
The App contains no advertising and no cross-app tracking. The outside services involved are:
- Apple — Sign in with Apple, the App Store, and subscription billing.
- Google — Google Sign-In, Google Play, and subscription billing.
- Supabase — hosts your account and synced data, in the European Union.
- RevenueCat — subscription status.
- Sentry — anonymous crash reports, in the European Union.
- TelemetryDeck — anonymous usage statistics, in the European Union.
- Cloudflare — hosts
kiddowise.dev, which serves this page.
We do not sell your data or share it for marketing.
Deleting your account
You can delete your account from inside the App: Settings → Account → Delete account. This removes, from our server, your account, the lists you own, everything on them, all completions, and your subscription status record. It cannot be undone.
Two things to know before you do:
- Your data on the phone stays. You are deleting the account, not your list. Delete the App if you also want the local copy gone.
- Your subscription is not cancelled, because it lives in the App Store or Google Play, not in your account. Cancel it there — the App shows the button before you confirm the deletion.
If you no longer have the App installed, write to us at hello@kiddowise.dev from the email address linked to your account and we will delete it for you.
Your rights
Under the GDPR you have the right to access, correct, export, and delete your personal data, to restrict or object to its processing, and to lodge a complaint with your local data-protection authority. In practice:
- Export — the App’s “Save a copy” gives you all your data as a file.
- Correct — edit anything in the App; changes sync to the server.
- Delete — delete the account in the App, or write to us.
- Anything else — email hello@kiddowise.dev.
We process account and sync data because you asked for those features (performance of a contract), and we keep it for as long as your account exists. We process crash reports and usage statistics on the basis of our legitimate interest in keeping the App working and improving it; you can object at any time by switching them off in Settings. Because they are not linked to you, we cannot find or delete the reports of one particular person — switching them off stops any more from being sent.
Children’s privacy
Last Done is not directed at children under 16 and we do not knowingly collect personal data from them. If you believe a child has created an account, write to us and we will delete it.
Changes to this policy
If our data practices change, we will update this page and revise the date above before the change takes effect.
Contact
Questions about this policy? Write to us at hello@kiddowise.dev.