Cookie Policy
Last Updated: August 5, 2026
Effective Date: August 5, 2026
1. About This Policy
This Cookie Policy explains how Eidos Vale Pty Ltd (ACN 700 845 978), an Australian proprietary limited company registered in Victoria, Australia, which operates the ActionList platform under its registered business name ActionList, uses cookies and similar technologies on the ActionList website, web application, and iOS mobile application ("the Service").
It sits alongside our Privacy Policy, which explains the wider picture: what personal information we collect, the legal bases we rely on, where your data is stored, and your rights. Where this Policy names a specific provider, that is the provider we use today — see Section 5.
2. What We Mean by "Cookies"
We use "cookies" loosely in this Policy to cover cookies and the equivalent browser and device storage technologies — principally local storage, which is what the Service actually relies on for most purposes. ActionList is a single-page application and a native app wrapper, so it stores most state in local storage rather than in traditional HTTP cookies. The privacy considerations are the same, and so is your right to consent.
3. Strictly Necessary — Always Active
These are required for the Service to function. They do not track you across sites, are not used for advertising, and cannot be switched off while you are using the Service. Under the EU/UK ePrivacy rules these do not require consent.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| Supabase authentication token | Local storage | Keeps you signed in and refreshes your session. Without it you would be logged out on every page load. | Until you sign out or the session expires |
al_analytics_consent | Local storage | Remembers your analytics consent choice, so we do not ask again on every visit and so we know not to load non-essential tools. Stores only your decision, its version, and when you made it. | Until you clear site data or change your choice |
ACTIONFLOW_QUERY_CACHE | Local storage | Caches your own tasks, habits, reminders and other content on your device so the app opens instantly and keeps working offline. Cleared when you sign out. | Until you sign out or clear site data |
af_sync_queue | Local storage | Holds changes you made while offline — the task you ticked, the habit you logged — until they can be sent to the server. Namespaced to your account, and each change is removed once it has been accepted. Present only in builds where offline editing is enabled. | Until the change is synced, or you clear site data |
| Theme and display preferences | Local storage | Remembers your chosen theme and interface preferences. | Until you clear site data |
4. Analytics and Diagnostics — Consent Required
These are non-essential. They are not loaded and set nothing at all until you actively consent. Our default is off: if you dismiss or decline the consent banner, no analytics or diagnostics tooling is initialised.
We use them for two purposes:
- Product analytics and usage measurement — which features are used and how people move through the app, so we can decide what to improve. Currently provided by Mixpanel.
- Error monitoring, logging, and performance diagnostics — technical error reports and performance data, so we can find and fix crashes and slow paths. Currently provided by Sentry.
We minimise what these receive. Error monitoring is configured not to send default personal identifiers, and session replays mask text and input content — so the content of your tasks, notes, and messages is not captured. We do not use any of this for advertising, and we do not sell it.
5. Providers May Change
The providers named above are the ones we use at the date of this Policy. We may replace them with a different analytics or logging provider — for example a self-hosted or alternative observability platform — as the Service grows. When that happens we update this Policy, and the categories of data and the purposes described here stay the same. If a change materially alters what is collected or who receives it, we will ask for your consent again rather than relying on the consent you gave before.
6. Managing Your Choices
- In the app: go to Settings > Privacy & Security to grant or withdraw analytics consent at any time. Withdrawing takes effect immediately and stops the tools running.
- At first visit: the consent banner lets you accept or decline before anything non-essential loads.
- In your browser: you can block or clear cookies and site data through your browser settings. Blocking strictly necessary storage will sign you out and may stop parts of the Service working.
- On iOS: clearing the app data or reinstalling the app clears all local storage described here.
Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
7. Third-Party Sites
The Service links to and integrates with third-party services (for example calendar providers and payment processing). Those providers set their own cookies under their own policies, which we do not control. Review their policies for details.
8. Changes to This Policy
We may update this Cookie Policy from time to time. We will post the updated version here and revise the "Last Updated" date above. Material changes to non-essential tracking will be accompanied by a fresh consent request.
9. Contact
Operator: Eidos Vale Pty Ltd (ACN 700 845 978)
Business name: ActionList (ActionList.io)
Registered in: Victoria, Australia
Questions about this Policy: privacy@actionlist.io
Privacy complaints (Australia): Office of the Australian Information Commissioner — oaic.gov.au