Privacy Policy
Last updated 20 August 2026
The short version. Galka works without an account and stores your tasks on your device. If you choose to sign in, your email address and the tasks you sync are stored on the Galka server so your own devices can stay in step. Nothing is sold, shared with advertisers, or used to track you across other apps or websites.
Who is responsible
Galka (“the app”) and the sync service at api.getgalka.ru are operated by
Andrey Fanyagin. Questions about this policy, or about the data held about you, go to
support@getgalka.ru.
Using the app without an account
Without signing in, the app is entirely local. Your tasks, projects, tags, notes and history live in a database on your device (and in the shared app group used by the widget). The app makes no network requests, and we receive nothing at all — not usage statistics, not crash reports, not analytics. There is no third-party analytics or advertising SDK in the app.
What is stored when you sign in
| Data | Why it is stored |
|---|---|
| Email address | Identifies your account and is how you sign in. It is also the only way to reach you about the service. |
| Password | Stored only as a salted bcrypt hash. The password itself is never written down and cannot be recovered from the hash. |
| Your content | Tasks, projects, sections, tags, notes, checklists, dates, repeat rules and the activity log — everything the app needs to reproduce your data on your other devices. |
| Device identifier and name | A random identifier generated by the app for each device, plus the name you gave it. It marks which device made a change, so a device does not re-download its own edits, and it lets you sign a device out. |
| Access tokens | One token per signed-in device, so you stay signed in. Signing out revokes it. |
| Timestamps | Each record carries the time it was last changed. That is what decides which version of a task wins when two devices edit it. |
The server keeps ordinary web-server request logs (IP address, time, path, response code) for a short period, for security and debugging. No profile is built from them.
We do not collect location data, contacts, photos, health data, advertising identifiers, or any behavioural analytics. There is no tracking, so the app never asks for permission to track you.
Where it is stored, and who can see it
Your data is held on the Galka server and its database, run for this service alone. Traffic between the app and the server is encrypted with HTTPS. Your content is not end-to-end encrypted: an administrator with database access could technically read it, and does so only when strictly necessary to operate or repair the service.
Your data is never sold, rented, or handed to advertisers or data brokers. It is disclosed to third parties only where the law requires it, and only to the extent required.
Other services the app can talk to
- Your own server. Galka lets you point the app at a different server address. If you do, this policy no longer applies to the data you sync — the operator of that server holds it.
- Import on the Mac. Importing from another task app reads that app's local database on the same Mac, and the Reminders import asks the system for access to your reminders. Both read only, and the imported data goes into Galka. Neither sends anything anywhere.
- Notifications. Reminders are scheduled locally by the system on your device. No push server is involved and no notification content leaves the device.
How long it is kept
Synced content is kept for as long as your account exists. Deleting a task moves it to the Trash; emptying the Trash replaces it with a tombstone — a record of the deletion with the content removed — which is retained so your other devices learn that the task is gone. Deleting your account removes your account and its content, including those tombstones. Backups may hold a copy for up to 30 days before they age out.
Your choices
- Use the app without an account. Every feature except sync works signed out.
- Sign a device out. Settings ▸ Account ▸ Sign out revokes that device's token; the local copy of your tasks stays on the device.
- Get a copy of your data. Write to support@getgalka.ru and we will send you a machine-readable export.
- Correct it. Editing a task in the app updates the stored copy.
- Delete your account. Write to support@getgalka.ru from the address the account uses, asking for deletion. The account and its content are removed within 30 days, and you get a confirmation.
If you are in the EEA or the UK, the legal basis for processing your account and content is performance of the contract you enter by creating an account, and you have the rights of access, rectification, erasure, restriction, portability and objection described above, as well as the right to complain to your local data protection authority.
Children
Galka is not directed at children under 13, and we do not knowingly hold data about them. If you believe a child has created an account, write to us and it will be removed.
Changes to this policy
If this policy changes in a way that affects how your data is handled, the date at the top is updated and, where the change is significant, we email the address on your account. Continuing to use the service after a change means you accept the updated policy.
Contact
Andrey Fanyagin — support@getgalka.ru