Skip to content
Radar :Tasks&Habits
View product

Your information, clearly explained

Privacy
Policy.

Radar : Tasks & Habits keeps your day organized on your own device or in your own browser first, may use pseudonymous Firebase cloud sync on mobile, and keeps permanent account connection and in-app support optional.

Effective July 18, 2026Last updated September 8, 2026

Privacy at a glance

  • ✓
    Local by defaultYour tasks and habits are stored on your device, or in your own browser, first.
  • ✓
    Pseudonymous cloud syncApp data may sync under an anonymous Firebase identifier; connecting a permanent account is optional.
  • ✓
    No advertising profileWe do not sell personal data, use third-party advertising SDKs or set tracking cookies.

On this page

Who we are Information we handle Device permissions How information is used Service providers Retention and deletion Your choices and rights Contact
Account controlsDelete your account → Related documentTerms of Use →
Plain-language summary

On iPhone and Android you can organize your day without connecting an email, Google or Apple account, and the App may create a pseudonymous Firebase identity and sync app data under that identifier. The browser app is different: it opens only after you sign in with a permanent Google or email/password account. Connecting a permanent account for cross-device recovery, submitting feedback and making a store purchase use the relevant providers described below. On both iOS and Android, RevenueCat processes pseudonymous purchase information so the App can verify and restore Premium access bought through the App Store or Google Play.

01

Who we are and what this policy covers

Radar : Tasks & Habits (the “App”) is provided by Project Null0 (“we,” “us” or “our”). This Privacy Policy explains how information is handled when you use the App on iPhone or Android, use the browser app at app.radarth.com, or visit radarth.com. The mobile and browser clients are two interfaces for the same product and share one Firebase backend, so the sections below apply to both unless a paragraph says otherwise.

For questions or privacy requests, contact contact@projectnull0.com.

02

Information we handle

Information stored on your device

The App stores the information you create on your device first so it can provide its core features. This may include tasks, projects, habits, schedules, notes, checklist items, task completion and archive history, ordering preferences, app settings and optional files you attach to tasks. A task attachment may be a photo or image, video, audio, voice or music file, document or another file type you explicitly select. When Firebase cloud sync is available, supported records and task attachments may also be sent to the Firebase services described below.

Information stored in your browser

The browser app keeps a working copy of the same records — tasks, projects, habits, schedules, notes, checklist items, task attachments, completion and archive history, ordering and settings — in your browser’s IndexedDB storage so the app stays responsive and can recover after a reload. Your browser also holds sign-in state maintained by Firebase Authentication, interface preferences such as sidebar width in local storage, short-lived navigation state in session storage, and one functional cookie that remembers your chosen language. None of this is used for advertising, profiling or cross-site tracking. Clearing site data in your browser removes the local copy; records already synced to your account stay in the cloud until you delete them.

Health, fitness and wellness content you choose

You may choose to use tasks and habits to record health, fitness or wellness information, including your own titles, notes, goals, schedules and progress for routines such as hydration, walking, exercise or nutrition. This optional user-entered content is stored and handled like other task and habit content: it stays on your device first and, when Firebase cloud sync is available, may be synchronized or backed up in Cloud Firestore under your pseudonymous authenticated user identifier. We use it only to provide App functionality, synchronization and backup, not for advertising, profiling or tracking.

Radar is a general productivity and habit-tracking tool. It does not provide medical advice, diagnosis, treatment, or emergency services.

Account and authentication information

The App may use a pseudonymous Firebase user identifier to support Firebase-backed features. On iPhone and Android you may keep that pseudonymous identity or connect an account using email and password, Google Sign-In or Sign in with Apple. The browser app has no pseudonymous mode: it requires a permanent Google or email/password account before any workspace is shown, and it may ask you to sign in again before a sensitive account change. Firebase Authentication may process your email address, authentication provider identifier and account profile details such as display name or profile image. Apple may provide a private relay address when you choose to hide your email. Passwords are handled by Firebase Authentication; we do not receive your payment-card details or a readable copy of your password.

Sign-in, security and SDK information on iOS

The current iOS release includes Google Sign-In SDK 9.2.0 and reCAPTCHA Enterprise Mobile SDK 18.9.1. The Google Sign-In privacy manifest declares that the provider may process a name, email address, phone number, coarse location, user ID, device ID, other usage data and other data types for sign-in functionality and provider analytics. The App does not offer phone-number authentication or request precise location.

Firebase Authentication may use reCAPTCHA to protect authentication from fraud and abuse. Its iOS privacy manifest declares device identifiers, product-interaction information such as app launches, taps, clicks or scrolling, crash data and performance data for security and App functionality. Firebase SDKs also process a linked user ID for authentication and unlinked diagnostic information for service analytics. These SDK categories are not used for advertising or tracking across apps or websites.

Profile information you choose to add

You can give the account a display name and a profile photo. The display name is stored in your Firebase Authentication profile and the photo is stored as a single image in Firebase Storage under your own user path. Both are optional, are shown only to you inside your own account, and are removed when you delete the account.

Security checks in the browser

The browser app protects backend requests with Firebase App Check using Google reCAPTCHA Enterprise. Your browser requests a token from Google for that check, which involves information Google needs to tell a real browser from automated abuse. It is used for security only, not to build an advertising profile.

Cloud-sync and account-backup information

When Firebase cloud sync is available, tasks, projects, habits, completion history, settings embedded in those records and related update timestamps are stored in Cloud Firestore under a pseudonymous authenticated user identifier. The contents and metadata of optional task attachments — including photos or images, videos, audio, voice or music files, documents and other selected files — and an optional profile photo may be stored in Firebase Storage under user-specific paths. The mobile and browser clients read and write the same records, so a change made in one appears in the other once it syncs. Connecting email/password, Google or Apple upgrades that Firebase identity so account-based recovery and cross-device access can be used. Access rules restrict records to the authenticated user associated with that identifier.

Feedback and support information

If you send a feature request or bug report from the App, we process the report type, subject and description. You may also choose to include a reply email address and screenshot. The report is authenticated, protected by Firebase App Check, rate-limited and delivered to Project Null0 through an authenticated OVH email service. A hashed user identifier and submission timestamp may be retained for up to seven days to enforce the rate limit. Feedback screenshots are delivered as email attachments and are not saved as task attachments or Firebase Storage objects by the feedback service.

Purchase and entitlement information

Apple or Google processes subscription purchases. On both iOS and Android, the App uses RevenueCat to validate App Store or Google Play purchases and determine whether Premium access is active. RevenueCat first generates a random anonymous App User ID for the installation and caches it on the device. If you connect a permanent Firebase account, the App then supplies its pseudonymous Firebase user ID to RevenueCat so purchase access can follow that account across devices and supported clients. The App does not send your name, email address or IDFA advertising identifier to RevenueCat.

RevenueCat may process the anonymous or Firebase-linked App User ID; product, purchase, transaction, subscription and entitlement history; purchase and expiration dates; an App Store receipt or Google Play purchase token and related store transaction information; and limited technical information needed to provide the service, such as device type, operating system, locale, currency code and last-seen time. We use this information for purchase validation, fraud prevention, introductory-offer eligibility, purchase restoration, entitlement delivery, troubleshooting and subscription reporting and analytics. We also use subscription reporting to measure the effectiveness of our Apple Ads campaigns as described below. This integration does not track you across apps or websites or send subscription events to Apple Ads. Neither we nor RevenueCat receives your full payment-card number or store billing credentials through this integration.

Apple Ads attribution on iPhone

The iPhone App sends an Apple AdServices attribution token to RevenueCat. RevenueCat uses it to ask Apple whether an eligible installation came from an Apple Ads campaign and, when available, to retrieve campaign, ad group, keyword, ad placement and campaign country or region information. This is campaign attribution, not your precise location or a history of your searches. RevenueCat associates the attribution with its pseudonymous customer record so we can compare subscription results by campaign and keyword. If you connect a permanent account, the existing RevenueCat identity flow can link that record to your Firebase user ID.

We use Apple's Standard attribution without requesting App Tracking Transparency permission or collecting the IDFA for this feature. The integration does not send your tasks, habits, notes, attachments or other workspace content to Apple or RevenueCat. Android and the browser app do not collect Apple AdServices tokens.

Website and technical information

Neither this website nor the browser app includes advertising, analytics trackers or marketing cookies, and the marketing site sets no cookies at all. Both are delivered by Vercel, whose infrastructure may process routine request information such as IP address, browser or device information, requested URL and request time to deliver the pages, maintain security and diagnose technical problems.

Apple App Privacy category summary

For the current iOS release, the App and its service providers disclose the following Apple data types: Name, Email Address, Phone Number, Coarse Location, Health, Fitness, Photos or Videos, Audio Data, Customer Support, Other User Content, User ID, Device ID, Purchase History, Product Interaction, Advertising Data, Other Usage Data, Crash Data, Performance Data, Other Diagnostic Data and Other Data Types.

Name, email address, phone number, coarse location, health data, fitness data, photos or videos, audio data, customer-support information, other user content, crash data, performance data and product-interaction information are used for App Functionality. User ID, Device ID and Other Data Types are used for App Functionality and Analytics. Purchase History is used for App Functionality and subscription Analytics. Advertising Data, Other Usage Data and Other Diagnostic Data are used for Analytics. Apple Ads attribution is treated as linked because RevenueCat associates it with its customer record. Data associated with account, cloud-content, optional health or fitness content, task-attachment, support, Google Sign-In or reCAPTCHA flows is treated as linked to the user, account or device. Purchase History is also disclosed as linked because RevenueCat is identified with the Firebase user ID after a permanent account is connected; Firebase Other Diagnostic Data is disclosed as unlinked. None of these categories is used for tracking.

03

Device permissions and content you choose

  • Task attachments: a task can include any file you explicitly select, including photos or images, videos, audio, voice or music files, documents and other files. The selected file and related metadata such as its name, type and size are stored locally and may be uploaded to the authenticated user’s Firebase Storage path when cloud sync is available. The App does not scan your other files or upload anything you did not select.
  • Profile and feedback images: the system photo or file picker is used only when you choose a profile photo or feedback screenshot. These optional images follow the profile and support handling described above.
  • Speech recognition and microphone: used when you start dictation for Inbox quick capture. On mobile, speech processing is provided by the operating system or platform speech service. In the browser app, dictation uses your browser’s own speech recognition, and some browsers send the audio to their vendor’s speech service to produce the transcript; that processing is governed by your browser vendor’s policies. In both cases the App receives only the resulting transcript and does not upload a separate audio recording to our backend.
  • Backup files: used when you explicitly export or import a manual JSON backup. You choose the file and destination through the operating system, or through your browser’s download and upload dialogs.

You can manage device permissions in iOS or Android settings, and site permissions such as microphone access in your browser’s settings. Disabling a permission may prevent the corresponding optional feature from working.

04

How and why we use information

We use information only as needed to:

  • provide task, project, calendar, habit, archive, synchronization and backup functionality, including for optional health, fitness or wellness content you enter;
  • authenticate users and keep cloud records separated by account;
  • validate purchases, determine introductory-offer eligibility, verify and restore Premium access, prevent purchase fraud and understand subscription performance;
  • measure which Apple Ads campaigns bring eligible iPhone installations and subsequent subscriptions, using the limited attribution information described above;
  • deliver feedback, respond when a reply address is provided and prevent abuse;
  • protect the App and services, troubleshoot failures and comply with legal obligations.

Depending on where you live, the legal basis may be performance of our agreement with you, your choice or consent when enabling an optional feature, our legitimate interest in securing and improving the service, or compliance with law. You can withdraw consent for optional processing, but this does not affect processing already completed lawfully.

05

Service providers and international processing

We use a limited set of service providers to operate specific features:

  • Google Firebase: pseudonymous Authentication, Cloud Firestore and Cloud Storage sync, optional permanent accounts, Cloud Functions and App Check-protected support and deletion actions. See Firebase Privacy and Security and the Google Privacy Policy.
  • Google Sign-In: optional account connection on supported platforms. Its iOS SDK manifest covers account and provider information, coarse location, identifiers and usage information for App functionality and provider analytics. See the Google Privacy Policy.
  • Google reCAPTCHA: fraud and abuse protection used by Firebase Authentication and by Firebase App Check in the browser app. Its iOS SDK may process a device identifier, product interactions, crash data and performance data for security and App functionality. See the reCAPTCHA Apple privacy details and the Google Privacy Policy.
  • Sign in with Apple: optional account connection in the mobile App on iPhone and Android, including Apple private email relay when selected, governed by Apple’s Privacy Policy.
  • Apple and Google Play: app distribution, subscription billing, entitlement information and platform speech or account services. See Apple’s Privacy Policy and the Google Privacy Policy.
  • RevenueCat: pseudonymous App Store and Google Play purchase validation, introductory-offer eligibility, entitlement delivery across supported clients, purchase restoration, fraud prevention, subscription reporting and Apple Ads attribution analytics on iPhone. RevenueCat acts as our service provider for end-user information and may process that information in the United States. See the RevenueCat Privacy Policy.
  • Vercel: hosting and delivery for radarth.com and the browser app at app.radarth.com, including the routine request information described above. See the Vercel Privacy Policy.
  • OVHcloud: authenticated email delivery for support messages.

These providers may process information in countries other than your own. Where required, such processing is subject to contractual and legal safeguards used by the provider. Firebase explains that service locations vary by product and that Firebase Authentication is operated from United States data centers. RevenueCat states that end-user information is stored using Amazon Web Services in the United States.

06

When information may be shared

We do not sell or rent personal information and do not use it for third-party behavioral advertising. RevenueCat purchase history is used for App functionality and subscription analytics, including measurement of our Apple Ads campaigns. The Apple Ads integration does not send subscription events to Apple Ads or track users across apps or websites. Information may be shared with the service providers above only to operate the App and features described in this policy, with authorities when legally required, or as part of a business reorganization subject to appropriate confidentiality and user protections.

07

Retention and deletion

  • Local information remains on your device until you remove it through the App, clear the App’s data or uninstall the App, subject to device backups controlled by you or the platform.
  • Account and cloud-backup information is retained while the relevant account and records remain active. You can delete an account directly in the iPhone or Android app from Settings or, when Premium access is inactive, from the subscription screen. The browser app does not yet offer that action, so delete from the mobile app or follow our public account-deletion instructions to email us. Confirmed deletion removes the Firebase Authentication account, its Cloud Firestore records and Firebase Storage attachments including any profile photo. An in-app deletion also removes the mobile app’s local task data and attachments and, when Sign in with Apple was linked, revokes that Apple authorization. A browser or other offline device keeps its local copy until you clear its site or app data. Store subscriptions are managed separately by Apple or Google and may continue billing until you cancel them in the relevant store account.
  • Support messages are retained only as long as reasonably needed to respond, document the request, secure the service and meet legal obligations. Feedback rate-limit records are configured to expire after seven days.
  • Purchase and entitlement information is retained by Apple or Google under their own policies. When a permanent Firebase account is linked to RevenueCat, in-app account deletion also instructs RevenueCat to permanently delete the customer record identified by that Firebase user ID. Apple or Google purchase records and an active store subscription remain governed by the store and are not canceled by deleting the App account. An anonymous RevenueCat customer that was never linked to a permanent account cannot be located from a Firebase UID; you may contact us with enough purchase information to request deletion where applicable, subject to records that the store, provider or law permits or requires to be retained.
  • Sign-in, security and diagnostic information is retained under the applicable Google and Firebase retention policies for authentication, fraud prevention, security, service analytics and legal obligations. In-app account deletion removes the associated Firebase Authentication account, but Google may retain limited security, provider-analytics or diagnostic information where its policies or law permit or require it.

Account or data deletion is separate from subscription cancellation. Deleting your account, deleting RevenueCat data or uninstalling the App does not cancel an Apple or Google subscription. To stop renewal and future billing, cancel through your Apple or Google store account. We may retain limited information longer where required by law, necessary to resolve disputes or needed to protect the service from abuse.

08

Security

We use access controls, authenticated requests, Firebase security rules, App Check, encrypted network connections and provider security controls appropriate to the service. No storage or transmission method is completely secure, so we cannot guarantee absolute security.

09

Your choices and privacy rights

You can choose whether to connect a permanent account on mobile, export or import a manual JSON backup, remove task attachments, add or remove a display name and profile photo, delete your Firebase account and associated app data from the mobile app, clear the browser app’s local copy through your browser’s site-data controls, and decide whether to include contact information or a screenshot in feedback. Uninstalling the App stops future sync from that installation; use in-app account deletion to remove the associated cloud records and the RevenueCat customer linked to a permanent account. Our account-deletion page explains both the in-app and email-request routes, what is deleted and what you should never send us. For a request concerning an anonymous RevenueCat customer, contact us and provide enough purchase information for us to locate the relevant record without sending payment-card details.

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy of personal information, withdraw consent and complain to a data-protection authority. To exercise a right, email contact@projectnull0.com. We may need to verify your identity before acting on a request.

10

Children’s privacy

The App is a general productivity tool and is not directed to children below the minimum age required to consent to digital services in their country. We do not knowingly request personal information from such children. If you believe a child has provided personal information without appropriate authorization, contact us so we can investigate and take appropriate action.

11

Changes to this policy

We may update this Privacy Policy when the App, service providers or legal requirements change. The current version will remain available on this page and the “Last updated” date will identify the latest revision. Material changes may also be communicated in the App when appropriate.

12

Contact us

Questions, account-data deletion requests and privacy requests can be sent to:

contact@projectnull0.com ↗

Please include “Radar : Tasks & Habits privacy” in the subject line so we can route the request correctly.

Radar :Tasks&Habits

A clearer home for tasks, projects, schedules and habits.

Product Pricing Sign in Privacy Policy Terms of Use Delete account Contact
© 2026 Project Null0 Privacy, without the fine-print maze.