Privacy
Effective date: 1 July 2026
This is the privacy policy of CODILLA LIMITED, a private limited company registered in England and Wales under company number 12907388, whose registered office is at 86–90 Paul Street, London, EC2A 4NE, UK (“CODILLA”, “we”, “us”, “our”).
This policy explains what personal data we collect when you use our website at codil.la, when you contact us, and when you use any software application published by us (including but not limited to one-click-do and County). It sets out how we use that data, the lawful bases on which we rely, the third parties involved, and the rights available to you under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
CODILLA LIMITED is a data controller in respect of the personal data described in this policy. We have not appointed a Data Protection Officer; we are not required to do so under Article 37 of the UK GDPR.
1. What this policy covers
This policy covers:
- The codil.la website and any subdomains operated by CODILLA LIMITED.
- Email correspondence with the support address published on the support page.
- The following mobile applications published by CODILLA LIMITED, as and when they are made available: one-click-do, County, and any subsequent application for which we do not publish a separate privacy policy.
Where we publish a separate privacy policy for a specific application, that policy applies to that application in place of this one.
2. The website: what we collect
The codil.la website is a static site. It:
- Does not set cookies.
- Does not use browser local storage or IndexedDB.
- Does not run analytics, tag managers, or advertising SDKs.
- Does not embed third-party tracking pixels, share buttons, or web fonts.
- Does not present contact forms; the only interactive elements are
mailto:links.
The site is served over HTTPS from a static-hosting provider (Netlify, Inc.). Our hosting provider processes the technical information required to serve a web page — such as your device’s IP address, the request path, and the HTTP User-Agent string — as part of ordinary web-server operation. That information is processed by the hosting provider on our behalf, in accordance with Netlify’s privacy policy. We do not maintain server logs beyond what our hosting provider retains for its own operational and security purposes.
The hosting provider may set a short-lived, strictly-necessary cookie for load-balancing or CSRF protection where required for the service to function. Cookies of this kind are exempt from the consent requirement under regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003.
If we ever introduce cookies, local storage, or access technologies beyond the strictly-necessary carve-out — for example, to add analytics — we will present a compliant consent banner before those technologies are set or accessed.
3. Email correspondence
When you write to us at the support address published on the support page, we receive your email address, any name or signature block you include, and the contents of your message. We use this information solely to respond to your enquiry and, where the correspondence relates to a specific product, to keep a record of the issue for support purposes.
- Lawful basis: our legitimate interest in responding to enquiries and providing support (UK GDPR Article 6(1)(f)).
- Recipients: email is processed by our mail provider on our behalf. We do not forward or disclose email content to any third party except where required to respond to your enquiry, where the correspondence forms part of a subsequent contractual relationship, or where required by law.
- International transfers: our mail provider stores email on servers within the United Kingdom or European Economic Area where possible. Where transfers to the United States occur, they take place under the UK Extension to the EU-US Data Privacy Framework or under the ICO’s International Data Transfer Agreement, together with a transfer risk assessment.
- Retention: support-related correspondence is retained for 24 months from the date of the last message in the thread, after which it is deleted from live mailboxes. Emails that form part of an account record or accounting record are retained for as long as required by law (typically six years for accounting records under the Companies Act 2006).
4. Applications: general framework
The subsections below apply to all software applications published by CODILLA LIMITED.
4.1 What we collect
We collect only the personal data required to operate the application. Depending on the specific application, this may include:
- Account identifiers: an email address that you supply during sign-up and a chosen handle or display name.
- Authentication records: verification codes issued during passwordless sign-in and their status.
- User-generated content: the data you create and store within the application (for example, tasks, notes, counters, count logs, hashtags, and comments).
- Social graph: where an application supports following, blocking, or sharing between users, the resulting relationships.
- Device identifiers for notifications: a push-notification device token — on iOS, issued by Apple Push Notification service (APNs); on Android, issued by Firebase Cloud Messaging (FCM) — generated on your device when you enable notifications.
- Diagnostic and security logs: authentication events, error records, and abuse-prevention signals.
We do not collect any of the following:
- Your real name (beyond what you voluntarily include in a display name).
- Precise location data.
- Contacts, photos, or camera roll content, unless a specific feature you explicitly invoke requires it.
- Health, fitness, biometric, or financial-account information.
- Advertising identifiers or attribution identifiers of any kind.
4.2 How we collect it
We collect data:
- Directly from you when you sign up, sign in, or use application features.
- Automatically as part of ordinary application operation — for example, timestamps of your log entries.
- From Apple and Google, limited to what each app-store operator provides for distribution (for example, subscription status if we ever add paid tiers).
4.3 What we do with it
We process this data to:
- Provide the service you asked for. Lawful basis: performance of the contract to which you are a party (UK GDPR Article 6(1)(b)).
- Maintain security and prevent abuse. Lawful basis: legitimate interest (Article 6(1)(f)) in operating a secure service.
- Send you notifications where you have enabled them. Lawful basis: consent (Article 6(1)(a) and PECR regulation 22), which you can withdraw at any time.
- Meet legal obligations, including tax, accounting, and responding to lawful requests from public authorities. Lawful basis: legal obligation (Article 6(1)(c)).
We do not:
- Sell your personal data.
- Rent, license, or otherwise disclose your personal data to any third party for advertising or marketing purposes.
- Use your personal data to train third-party artificial-intelligence models, nor share it with third-party generative-AI providers. This is stated explicitly in accordance with Apple App Store Review Guideline 5.1.2(i).
- Carry out automated decision-making or profiling of the kind that produces legal effects or similarly significant effects on you.
4.4 Third parties (processors)
We use the following third-party service providers to operate our applications. Each acts as a data processor under a data-processing agreement with CODILLA LIMITED, and provides protections equivalent to those set out in this policy.
- Amazon Web Services, Inc. (Amazon.com, Inc. group; EEA/UK contracting entity Amazon Web Services EMEA SARL, Luxembourg). Provides compute, storage, and identity infrastructure (Amazon Cognito, AWS Lambda, Amazon DynamoDB, Amazon S3, Amazon CloudWatch). Data resides primarily in the AWS
eu-west-2(London) region. See the AWS GDPR Center and Cognito data-protection documentation. - Exponent Inc. (“Expo”) (San Francisco, California, USA). Provides mobile push-notification delivery via Expo Application Services. Processes only the push device token and the delivery envelope of each notification; message contents are not retained after delivery. See Expo’s privacy explanation and privacy policy.
- Apple Inc. (Cupertino, California, USA). Provides the Apple App Store distribution channel, the Apple Push Notification service, and the iOS Speech framework used for on-device voice transcription. Apple’s own privacy policy applies to their processing.
- Google LLC (Mountain View, California, USA; EEA/UK contracting entity Google Ireland Limited, Dublin). Provides the Google Play distribution channel, Firebase Cloud Messaging (FCM) for Android push notifications, and the Android speech-recognition service used by our applications where on-device recognition is not supported (see section 5.1). Google’s own privacy policy applies to their processing.
- Netlify, Inc. (San Francisco, California, USA). Hosts the codil.la website. See Netlify’s privacy policy.
We do not use any third-party analytics, advertising, attribution, or crash-reporting SDK in our applications.
4.5 International transfers
Some of our processors are established in the United States. Where personal data is transferred to the United States:
- We rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) where the recipient organisation is self-certified under the Framework.
- Otherwise we rely on the ICO’s International Data Transfer Agreement, or on the ICO’s International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment consistent with the ICO’s international transfer guidance (2026).
Data processed in the AWS eu-west-2 (London) region does not leave the United Kingdom in the course of ordinary application operation.
4.6 Retention
Unless stated otherwise for a specific application, retention periods are as follows:
- Account records (email, handle, display name, related identifiers): until you delete your account. Following deletion, data is purged from live systems within 30 days and from encrypted backups within 90 days.
- User-generated content (tasks, notes, counters, count logs, comments): until you delete the content or your account, whichever is first.
- Authentication and security logs: 90 days from the date of the event.
- Push-notification device tokens: until you disable notifications or delete your account; then removed from live systems within 30 days of the change.
- Anonymised, aggregated usage statistics (no personal identifiers): retained indefinitely for product-development purposes.
Where any obligation under UK law requires longer retention (for example, six years of accounting records under the Companies Act 2006), we retain the minimum necessary to meet that obligation.
4.7 Account deletion
Applications that support account creation also support in-app account deletion, in line with Apple App Store Review Guideline 5.1.1(v) and Google Play’s User Data policy on account deletion. To delete your account, open the application, go to Settings → Account, and select Delete account. Deletion is confirmed within the application and takes effect subject to the retention windows stated in section 4.6.
If for any reason you cannot complete deletion in-app, you may write to us via the support page and we will delete your account within one calendar month.
5. Application-specific notes
5.1 one-click-do
one-click-do is a personal-productivity application. In addition to the framework in section 4:
- Voice capture uses the operating system’s speech-recognition APIs.
- On iOS, we use Apple’s Speech framework configured for on-device recognition (
requiresOnDeviceRecognition = true). The audio is transcribed on your iPhone or iPad; the raw audio recording is not transmitted to our servers, to Apple, or to any third party. - On Android, we use Android’s
SpeechRecognizerservice and request offline recognition (EXTRA_PREFER_OFFLINE = true) where the device and Android version support it. Where the device does not support offline recognition, the recorded audio may be sent to Google’s speech-recognition service; in that case Google acts as an independent controller for that recognition step and processes the audio under Google’s privacy policy. We do not receive or store the audio at any point. - In both cases, only the resulting text is stored — locally on your device first, and, on sync, on our servers as ordinary task text.
- On iOS, we use Apple’s Speech framework configured for on-device recognition (
- Local outbox. Tasks and captured text are written to a local SQLite database on your device before any network activity. This is a reliability measure to ensure captures are not lost if the network is unavailable; it is not a form of tracking.
5.2 County
County is a social counting application. In addition to the framework in section 4:
- Public counters and public logs are visible to other users of the application. By marking a counter or a log as public, you make it available on the relevant per-tag leaderboard and in the social feed. Do not mark a counter public if you do not want it to be visible.
- Your handle and display name are visible to other users. Do not choose a handle that identifies you unless you are content to be identified within the application.
- Blocking and reporting. The application provides in-app controls to block other users and to report content, in line with Apple App Store Review Guideline 1.2 and Google Play’s user-generated content policy.
6. Your rights
Under the UK GDPR you have the following rights in relation to your personal data:
- The right to access a copy of your data.
- The right to rectification of inaccurate data.
- The right to erasure (“right to be forgotten”).
- The right to restrict processing in certain circumstances.
- The right to data portability for data you provided.
- The right to object to processing based on legitimate interests.
- The right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us via the support page. We respond within one calendar month, in accordance with Article 12(3) of the UK GDPR. There is no fee, except in the limited circumstances described in Article 12(5).
If you are not satisfied with our response, you have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or by telephone on 0303 123 1113.
7. Providing data — required or optional
Providing an email address is required to create an account in an application that requires an account; without it we cannot verify sign-ins. All other information is optional. Not providing optional information does not affect the functioning of the application, save that features that specifically require that information will be unavailable.
8. Automated decision-making
CODILLA LIMITED does not carry out automated decision-making, including profiling, of the kind that produces legal effects or similarly significantly affects you. No such decisions are made using the personal data described in this policy.
9. Children
Our applications are not directed at children. Where an application is subject to an Apple App Store age rating or a Google Play content rating, that rating is set on the relevant store product page. If you become aware that a child has provided personal data to us, please contact us via the support page and we will delete it.
10. Third-party artificial intelligence
CODILLA LIMITED does not share your personal data with third-party generative-AI providers, and does not use your personal data to train third-party artificial-intelligence models. This position is stated explicitly in accordance with Apple App Store Review Guideline 5.1.2(i).
If we ever introduce a feature that relies on a third-party AI service, we will update this policy to describe the processing, obtain your consent before the feature is enabled for you, and give you the option to decline without losing access to the rest of the application.
11. Changes to this policy
We may update this policy from time to time. Where the changes are material — for example, a new category of processing, a new processor, or a change to the lawful basis on which we rely — we will notify existing account holders by email or through the relevant application before the changes take effect. The most current version of this policy is always the one published at codil.la/privacy.
12. Contact
For any question about this policy, or to exercise any of the rights described above, see the support page.
You may also write to us at the registered office set out at the top of this policy.