DunCrux Privacy Policy
Effective date: September 5, 2026
DunCrux (“DunCrux,” “we,” “us,” or “our”) is operated by Ten Digit Grid. This Privacy Policy explains how we collect, use, disclose, and retain information when you use the DunCrux mobile or desktop application (the “App”).
1. Privacy at a glance
- DunCrux is local-first. You can use its core task-management features without creating an account.
- Your task content stays on your device unless you sign in and separately enable cloud sync on that device.
- Cloud sync is off by default and must be enabled separately on each device.
- Anonymous usage analytics are on by default in supported production builds. You can turn them off at any time under Settings > Share anonymous usage analytics.
- Production builds use automatic crash reporting to help us diagnose errors.
- We do not display third-party advertising, collect advertising identifiers, sell personal information, or share personal information for cross-context behavioral advertising.
2. Information we process
Information stored locally on your device
The App stores the information you enter and generate in a local SQLite database. Depending on how you use DunCrux, this may include:
- task, subtask, and update text;
- keywords, tags, keyword aliases, keyword scores, and keyword history;
- due dates, completion dates, snooze dates, ordering, and completion status;
- task activity and timing information used to calculate your in-app insights;
- saved section names, icons, filters, and ordering;
- deleted items in Trash, revision history, and synchronization metadata; and
- randomly generated record and device identifiers.
The workload insights shown inside the App are calculated from this task data. They are not the same as the optional Firebase usage analytics described below.
Before first enabling sync, the App may create a database backup in its local application storage. When you choose Export all data, the App also creates a JSON export in local application storage. These files may contain the task content described above.
Account information
An account is optional. If you sign in with Google or Apple, we receive and process a Firebase account identifier and information the sign-in provider makes available, which may include your name, email address (including an Apple private relay address), profile image, and the identity provider connected to your account. We do not receive your Google or Apple password.
Authentication requests may also involve IP addresses, user-agent information, and security data used to prevent fraud and abuse.
Synced task content
If you sign in, have an eligible subscription, and turn on Sync this device, the App sends your DunCrux data to Google Firebase. Synced data may include the local content listed above, record identifiers, timestamps, deletion markers, device identifiers, sequence counters, revision history, and conflict-recovery copies. The cloud workspace is associated with your Firebase account identifier.
Signing in by itself does not upload your task content. Turning sync off stops new cloud synchronization on that device but does not delete information that was already synced.
Purchase and subscription information
When purchase features are available, the App uses RevenueCat and the Apple App Store or Google Play to process and verify purchases. DunCrux sends your pseudonymous Firebase account identifier to RevenueCat as the App User ID. We receive subscription and entitlement status, expiration information, and a link for managing an applicable subscription. RevenueCat and the app store may process transaction identifiers, product purchased, purchase date, price, currency, storefront, renewal status, and related purchase information.
The App does not directly receive or store your full payment-card number. The code disables RevenueCat's automatic device-identifier collection and does not send RevenueCat your email address or task content. Like other network services, RevenueCat may process technical information such as an IP address as part of providing its service.
Anonymous usage analytics
In supported production builds, DunCrux uses Google Analytics for Firebase when Share anonymous usage analytics is enabled. This setting is enabled by default and may be turned off at any time in Settings. No historical activity is uploaded when analytics are enabled.
The App sends events such as creating, completing, reopening, or deleting a task or subtask; the entry point used; whether a deleted item was complete; the number of affected subtasks; open-duration measurements; paywall outcomes; purchase-restore outcomes; and changes in entitlement status. The App does not add task or subtask text, tags, keywords, due dates, record IDs, account IDs, email addresses, display names, or exact event timestamps to these custom analytics events.
Google Analytics may automatically process an app-instance identifier, app and device information, session and engagement statistics, and approximate location derived from a masked IP address. DunCrux does not set a Google Analytics User ID. Advertising-ID collection is disabled in the App's native configuration.
Crash and diagnostic information
Supported production builds use Firebase Crashlytics automatically to identify and fix crashes and application-not-responding events. Reports may include a Crashlytics installation identifier, Firebase installation identifier, session identifier, crash time, stack traces, exception type and message, app version, device model, operating-system version, hardware and memory information, and other technical state associated with a crash.
DunCrux does not deliberately add your account identifier, email address, task content, tags, custom keys, or custom log messages to Crashlytics reports. However, an unexpected error message could incidentally contain information present at the point of failure.
App integrity and security information
We use Firebase App Check with Google Play Integrity on Android and Apple App Attest or DeviceCheck on Apple platforms. These services process device or app attestation material and short-lived security tokens to verify that requests come from an authentic copy of the App and to protect accounts and cloud data against abuse.
3. How we use information
We use information to:
- provide local task management, search, insights, export, and recovery;
- authenticate accounts and keep account sessions secure;
- synchronize data across devices when you enable sync;
- process purchases, restore purchases, and determine feature access;
- diagnose crashes, maintain reliability, and prevent abuse;
- understand aggregate feature usage when analytics are enabled;
- respond to support, privacy, or legal requests; and
- comply with law and enforce our agreements.
Where applicable law requires a legal basis, we process account, sync, and purchase information to perform our contract with you; security and essential diagnostic information for our legitimate interests in operating and protecting the App; analytics according to your choice and any consent required by law; and other information as needed to comply with legal obligations.
4. When we disclose information
We disclose information only as needed for the purposes described above:
- Google Firebase and Google Cloud: authentication, Firestore cloud storage, Cloud Functions, App Check, Analytics, and Crashlytics.
- Google and Apple: optional identity-provider sign-in and app-integrity verification.
- RevenueCat: purchase validation, subscription status, entitlements, paywalls, and purchase restoration.
- Apple App Store and Google Play: purchase and subscription processing.
- Legal and safety recipients: when reasonably necessary to comply with law, legal process, or valid government requests; enforce agreements; or protect the rights, safety, and security of users, DunCrux, or others.
- Business transaction recipients: if DunCrux is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to applicable law and appropriate safeguards.
These providers process information under their own terms and privacy notices, including:
- Firebase privacy and security information
- Google Privacy Policy
- Apple Privacy Policy
- RevenueCat Privacy Policy
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and the App does not contain third-party advertising SDKs.
5. Retention
- Local data: Active App data remains on your device until you delete it, use Remove data from this device, delete your account, uninstall the App, or the operating system removes it. Signing out does not remove the local workspace.
- Local backups and exports: Export files and sync-enrollment backups are separate files in the App's local storage. The App removes backup files older than 30 days when it creates a new enrollment backup, but the current account deletion flow does not expressly delete existing backup or export files. They may therefore remain until you delete them, uninstall the App, or the operating system removes the App's storage.
- Cloud task data: Current synced content remains until you delete it or successfully delete your account. Deleted content, change records, conflict copies, and prior revisions are generally retained for approximately 30 days for Trash, synchronization, and recovery. Minimal tombstones may remain after deleted payloads are purged so an offline device cannot recreate deleted records. They are removed when the account's cloud workspace is deleted.
- Account information: Firebase Authentication retains account information while the account exists. Google states that, after deletion is initiated, authentication data is removed from live and backup systems within 180 days.
- Crash reports: Google states that Crashlytics keeps crash stack traces and associated identifiers for 90 days before beginning removal from live and backup systems.
- Analytics: User-level and event-level Google Analytics data is retained according to our Firebase/Google Analytics configuration, currently up to 14 months. Standard aggregated reports may not be affected by that setting.
- Purchases: RevenueCat, Apple, and Google retain transaction and subscription information under their policies and legal obligations.
We may retain limited information longer when required by law, needed to resolve disputes, prevent fraud, enforce agreements, or maintain security.
6. Your choices and rights
You can:
- use the core App without creating an account;
- turn cloud sync on or off separately on each signed-in device;
- turn Firebase usage analytics off in Settings;
- export the active DunCrux dataset to JSON using Export all data;
- remove the active profile from a device using Remove data from this device (this does not delete its synced cloud data);
- permanently delete your synced DunCrux workspace stored under your account in Firestore and then delete your Firebase Authentication account, active local database, and RevenueCat customer record using Delete account; and
- manage or cancel an App Store or Google Play subscription through the applicable store.
Deleting a DunCrux account does not cancel an App Store or Google Play subscription. Manage or cancel an active subscription with the store before or after deleting the account.
Depending on where you live, you may also have rights to request access, correction, deletion, portability, restriction, or objection; withdraw consent; or appeal our response. You may exercise these rights by using the in-App controls or contacting us at [email protected]. We may need to verify your identity and may retain information when an exception under applicable law applies. We will not discriminate against you for exercising a privacy right.
7. Security
We use technical and organizational safeguards designed to protect information. Cloud requests use encrypted network connections, Firebase data is logically separated by account, direct client writes to canonical cloud records are blocked, and protected mutations use authenticated Cloud Functions and App Check. No security measure is perfect, and we cannot guarantee absolute security.
Protect access to your device and your Google or Apple account. JSON exports and local database backups may contain sensitive task content, so store and share them carefully.
8. International processing
DunCrux's service providers may process information in the United States and other countries where they operate. Firebase Authentication is operated from United States data centers. DunCrux currently uses a North America multi-region Firestore database and Cloud Functions in us-central1. Where required, we rely on contractual or other lawful safeguards for international transfers.
9. Children's privacy
DunCrux is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If local law requires a higher age for a child to consent to data processing, a parent or guardian must provide any required permission. Contact us if you believe a child has provided personal information contrary to this section.
10. Changes to this policy
We may update this Privacy Policy as DunCrux changes. We will revise the effective date and provide any additional notice required by law. Material changes apply prospectively unless otherwise stated or permitted by law.
11. Contact us
For privacy questions or requests, contact:
Ten Digit Grid
Email: [email protected]