Privacy policy
Version of 6 October 2026
This policy explains what personal data Semacheck processes, why, and what your rights are. It covers this website, the web app at app.semacheck.app and the Android app. In short: Semacheck keeps what it needs to show you your own checklists on your own devices, and nothing else. There are no ads, no analytics and no tracking.
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) is:
Aleksei SemenovEibenweg 2
85757 Karlsfeld
Germany
support@semacheck.app
Semacheck is a private project run by one person. There is no data protection officer, and none is required.
2. This website
The pages on semacheck.app set no cookies, run no scripts and load nothing from anywhere else. To deliver a page, the server necessarily processes your IP address and the address of the page you asked for; it does this in memory only and keeps no record of the visit. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in being able to publish the site.
3. The app
3.1 Signing in with Google
You sign in to Semacheck with your Google account. In the web app, Google’s sign-in is not
loaded until you press Continue with Google: before that, no page of Semacheck contacts
Google. When you sign in, Google tells Semacheck your Google account id, your email address and
your name, and nothing else (the scopes openid, email and
profile). What Google itself processes while you sign in is governed by
Google’s own privacy policy. On Android the app is fully usable without signing in, and your
checklists then stay on the phone.
3.2 What is stored, why, and for how long
All of the following is processed to provide the service you signed up for, under Art. 6(1)(b) GDPR (performance of the contract, which is the Terms of Use), except where another basis is named.
- Your account
- Your Google account id, email address and name, to recognise you when you sign in and to show you which account you are using. Kept until you delete your account.
- Your checklists and settings
- Everything you write: checklist names and items, ticks, which items are folded, the order, and each checklist’s sorting; and your settings (theme, text size, reordering speed, and how new checklists are sorted). Kept until you delete it or your account. When you delete a checklist or an item, a marker that it was deleted is kept for up to 90 days, so that your other devices learn of the deletion; the marker goes with your account, too.
- Your devices
- For each phone or browser signed in to your account: a random id, whether it is Android or the web, when it first and last synced, how far it has synced, and the version of the app; for a phone, also the push token described in 3.4. This is what lets each device catch up on what it missed. Device records are kept until your account is deleted; a device you sign out in Settings stays recorded as signed out, so that it stops syncing until somebody signs in on it again.
- Sign-in sessions
- A random token per signed-in browser or phone, of which the server keeps only a one-way hash. A session ends after 30 days at the latest, or when you sign out. After you delete your account, the hashes of its sessions are kept until they would have expired, so that a device still holding one is told the account was deleted rather than simply asked to sign in again.
- Records that keep syncing reliable
- For each change a device sends, a receipt of its ids and sequence numbers — never its content — kept for one year, so that a change retried after a lost connection is applied only once. And when two devices changed the same thing at once, a note of which kind of field it was and how far apart the changes were, again without content, kept for 90 days, to check that syncing works as designed. Legal basis for the second: Art. 6(1)(f) GDPR, our legitimate interest in a service that does not lose your changes.
3.3 Connection data and logs
To answer your devices, the server processes their IP addresses. It uses them in memory to deliver the answers and to limit how many requests one address can make, so that nobody can overload the service, and it does not store them. The server writes one log line per request — the time, the kind of request, whether it succeeded and how long it took, and where needed your random account id — with no IP address, no email address and nothing you wrote. Logs are kept for 14 days. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a working service that resists abuse.
3.4 On your phone
The Android app keeps your checklists on the phone itself. If you sign in, it syncs them as described above. So that a change made elsewhere reaches the phone at once, the app uses Google’s Firebase Cloud Messaging: Google gives the app a push token, the app sends it to Semacheck, and Semacheck asks Google to deliver a message that says only that something changed — never what. The phone then fetches the change from Semacheck directly.
3.5 In your browser
The web app keeps a few things in your browser, all of them needed for the service you asked for and none of them used to track you (§ 25(2) no. 2 TDDDG, so no consent is required):
- a sign-in cookie, valid for 30 days or until you sign out;
- changes you made that have not reached the server yet, so that they are not lost if the connection drops or the tab closes;
- which checklist you had open, how your list of checklists is ordered, which items each checklist is showing, which account was signed in last, and whether spell checking is on. Signing out removes what belongs to your account.
You can remove all of it at any time in your browser’s settings.
4. Writing to support
If you write to support@semacheck.app, your message and email address are used to answer you (Art. 6(1)(b) GDPR where it concerns your use of Semacheck, otherwise Art. 6(1)(f), our legitimate interest in answering). The address is forwarded by Cloudflare to my personal mailbox at Google (Gmail). Messages are deleted once the matter is closed, unless the law requires otherwise.
5. Who receives data
- netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, which hosts the servers in Nuremberg, under a data processing agreement.
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, which stores the encrypted backups (section 7) in Germany, under a data processing agreement. It cannot read them.
- Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA), for signing in (Google Identity Services and, on Android, Google Play services) and for push messages to phones (Firebase Cloud Messaging), under Google’s privacy policy. Google Play distributes the Android app under its own terms; if you allow your phone to share usage and diagnostics with Google, Google Play shows me anonymous crash reports and statistics about the app, which name nobody.
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, which forwards mail sent to the support address to my mailbox at Google (Gmail), under Cloudflare’s privacy policy. Cloudflare also answers the DNS lookups for Semacheck’s domains, but no request to this site, the app or its server passes through it.
Nothing is sold, and nothing is given to anybody else unless the law requires it.
6. Transfers outside the EU
Google and Cloudflare may process data in the United States. Both are certified under the EU–US Data Privacy Framework, on the basis of the European Commission’s adequacy decision (Art. 45 GDPR).
7. Backups
The database is backed up every night, encrypted before it leaves the server, and each backup is kept for 30 days. If you delete your account, it remains in the backups taken before that until they are deleted, at most 30 days later. If a backup ever has to be restored, every account deleted since it was taken is deleted again before the service goes back online. For that, the random id of each deleted account and the time of its deletion are kept beside the backups for the same 30 days.
8. What Semacheck does not do
No advertising, no analytics, no tracking, no profiling, no automated decisions about you, and no selling of data.
9. Security
Every connection is encrypted (HTTPS). Only I have access to the server, and the backups are encrypted with a key that is not kept on it. To be plain about it: your checklists are not end-to-end encrypted, so as the operator I could technically read what is stored. I do not, and would look only if you asked me to, for example to help with a problem.
10. Your rights
You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), to have it erased (Art. 17), to restrict its processing (Art. 18) and to receive it in a portable format (Art. 20). Semacheck asks for no consent, because it processes nothing that needs one, so there is no consent to withdraw. Most of this you can do yourself in the app: Export all checklists gives you everything you wrote, and Settings → Delete account erases your account and everything in it at once (see Delete account). For anything else, write to support@semacheck.app.
You also have the right to complain to a data protection authority, for example the one responsible for Semacheck: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Your right to object (Art. 21 GDPR)
Where Semacheck processes your data on the basis of legitimate interests (Art. 6(1)(f) GDPR) — the request handling and logs in section 3.3, the sync statistics in section 3.2, and answering mail that is not about your use of Semacheck — you have the right to object to it at any time, on grounds relating to your particular situation. Write to support@semacheck.app. The processing then stops unless there are compelling legitimate grounds for it that override your interests, or it is needed to establish, exercise or defend legal claims.
11. Age
Semacheck is for people aged 16 and over.
12. Do you have to provide data?
No. But without signing in with Google the web app cannot be used, and the Android app cannot sync.
13. Changes
If this policy changes, the new version is published here with its date, and changes that matter are announced on this site and in the app before they apply.