➚ Fleche
Start free

Privacy policy

Last updated: 2 October 2026

🏹 The short version

  • We collect what Fleche needs to work: your account, your rules and todos, and the few settings you choose. Nothing else.
  • No ads, no third-party trackers, no selling your data. Ever. We count visits with privacy-friendly analytics that run on our own server and use no cookies.
  • Your data lives on servers in the European Union (Hetzner, Germany).
  • You can delete your account and everything in it yourself, in one click, from Settings.
  • Questions or requests: [email protected].

This policy explains how fleche.io (the hosted version of Fleche, "the service") handles your personal data, in line with the EU General Data Protection Regulation (GDPR). It does not cover self-hosted copies of Fleche: whoever runs those is responsible for them.

Who we are

The data controller is My Dynamic Production SRL, Rue du Curé 18a, 4280 Moxhe (Hannut), Belgium, company number (BCE/KBO) 0676680512, VAT BE0676680512.

For anything about your data, write to [email protected]. A real person (the developer) reads it.

What we collect, and why

DataWhyLegal basis
Account: name, email address, password (stored hashed, we can never read it), timezone Create your account, log you in, reset your password, start your day at the right local time Contract (Art. 6.1.b)
Your content: rules, todos, descriptions, pictures you upload, points That's the product: generating and showing your todos Contract
Notification settings: the hour your day starts, email and/or Telegram choice, your Telegram chat ID if you connect Telegram Send you your daily list where you asked for it Contract
API keys you create (stored hashed) and when they were last used Let your own tools access your account Contract
Payment: the date you bought the lifetime plan. Card details are handled by Stripe and never reach us. Unlock unlimited history, refunds, accounting Contract, and legal obligation for accounting records (Art. 6.1.c)
Usage statistics: pages visited, referrer, browser, device type and approximate country Understand which features are used and improve Fleche Legitimate interest
Technical data: IP address, browser, pages requested, error reports Keep the service secure and working, investigate bugs and abuse Legitimate interest (Art. 6.1.f)

We don't use your data for advertising, we don't build profiles, and no decision about you is made automatically. The "chance" in your rules is a dice roll about your todos, not about you.

The community hub

If you publish a rule pack on the hub, its name, description, rules and your display name become public, after a manual review. If you delete your account, your packs stay available but your name is removed from them.

Who else handles your data

We use a few providers ("processors") that only act on our instructions:

ProviderWhat forWhere
Hetzner Online GmbHServers and databaseGermany (EU)
Cloudflare, Inc.Sending emails, storing the pictures you uploadGlobal network; transfers outside the EU covered by the EU-US Data Privacy Framework and Standard Contractual Clauses
Stripe Payments Europe, Ltd.The lifetime payment (only if you buy it)Ireland (EU); Stripe is a controller for its own fraud and legal obligations, see stripe.com/privacy
TelegramDelivering your daily list, only if you connect Telegram yourselfOutside the EU; Telegram's own privacy policy applies to your use of Telegram

Usage statistics are collected with Rybbit, an open-source analytics tool we run on our own server: the data never goes to an analytics company, no cookies are set, and visitors are counted without building a profile of you.

We also receive technical error reports in a private Telegram chat so we can fix bugs fast. These may contain the page you visited and your user ID, never your password or your todos' content on purpose.

We never sell or rent your data, and only hand it to authorities when the law requires it.

How long we keep it

Cookies

Fleche only uses cookies that are strictly necessary: one to keep you logged in (session) and one to protect forms against forgery (XSRF-TOKEN). Our analytics don't use cookies, and there are no advertising or third-party cookies, so there's no cookie banner to click through. Fonts and icons are served from our own server.

Your rights

Under the GDPR you can at any time:

Write to [email protected]. We answer within one month. If you think we got something wrong, you can complain to the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, dataprotectionauthority.be, or to the authority of your own EU country.

Security

Connections are encrypted (HTTPS), passwords and API keys are stored hashed, and access to the servers is limited to the developer. No system is perfect: if a breach ever affects your data, we'll tell you and the authority as the GDPR requires.

Children

Fleche is not meant for children under 16. If you're younger, please ask a parent before signing up.

Changes

If we change this policy in a way that matters, we'll email you before it applies. The date at the top always shows the latest version.