Sipag

Privacy policy

Last updated September 8, 2026

This policy explains what the Sipag mobile app and this website collect, why, and what you can do about it. It is written to describe what the app actually does — if something here does not match your experience, please tell us at studio@collaub.com.

Sipag is operated by the developer of Sipag (“we”, “us”), who is the data controller for the information described below.

The short version

  • We collect your name, email and profile picture from Google when you sign in.
  • We store the groups you belong to and the to-dos you and your group write.
  • We store a push notification token if you allow notifications.
  • There are no adverts, no analytics or tracking SDKs, and no data sales.
  • You can delete your account and its data from inside the app at any time.

What we collect

Account information

Sipag uses Google Sign-In. We do not create or store passwords. When you sign in, Google gives us:

  • your name;
  • your email address;
  • your profile picture (as a link to the image Google hosts);
  • a Google account identifier that lets us recognise you next time.

We do not receive your Google password, and we do not get access to your Gmail, Drive, Contacts, Calendar or any other Google service.

Content you create in the app

  • Groups you create or join, including group names, invite codes, who is a member, when they joined, and who administers the group.
  • To-dos, including the title, any note, the category, the due date and time, the point value, the status, who it is assigned to, and who marked it done and when.
  • Points totals and completion streaks calculated from the above.

Anything you put in a group is visible to every member of that group. Treat a shared to-do list the way you would treat a note stuck to the fridge.

Device and technical information

  • If you allow push notifications, we store a notification token issued by Expo’s push service along with your platform (iOS or Android), so we can send reminders about your to-dos.
  • Our servers keep ordinary web logs — IP address, timestamp, the request made, and the app or browser version — which we use to keep the service running and to investigate faults and abuse. These are routinely discarded.

What we do not collect

Sipag has no advertising SDKs and no third-party analytics. It does not request or collect your location, contacts, photos, microphone, calendar, health data, or any device identifier used for advertising.

Why we use it

  • To run the app — signing you in, showing your groups, saving your to-dos, keeping members in sync.
  • To send reminders — push notifications about to-dos that are due or overdue, if you allowed them.
  • To keep score — points, streaks and the group leaderboard.
  • To keep the service working and safe — diagnosing errors, preventing abuse.

Where the UK/EU GDPR applies, our legal basis for the first three is performance of the contract you enter by using the app, and for the last our legitimate interest in operating a secure service.

Who we share it with

We do not sell your personal information, and we do not share it for advertising. We use a small number of service providers who process data on our behalf so the app can work:

  • Google — provides sign-in. Governed by Google’s own privacy policy.
  • MongoDB Atlas — hosts the database where your account, groups and to-dos are stored.
  • Expo — delivers push notifications to your device.
  • Our hosting provider — runs the servers that the app talks to.

We may also disclose information if we are legally required to, or where it is necessary to protect our rights or someone’s safety.

These providers may process data in countries other than yours. Where the UK/EU GDPR applies, transfers are made under the safeguards those providers offer, such as standard contractual clauses.

How long we keep it

We keep your account information and content for as long as your account exists. When you delete your account, the data described under deleting your account is removed from our live systems immediately. Backups are overwritten on a rolling basis and any residual copies are deleted within 30 days.

Your choices and rights

  • Access and correction — your profile, groups and to-dos are all visible and editable inside the app.
  • Deletion — see deleting your account. No email or form is required; it is a button in the app.
  • Notifications — you can turn push notifications off in your device settings at any time.
  • Revoking Google access — you can disconnect Sipag from your Google account at myaccount.google.com/permissions. This stops future sign-ins but does not by itself delete your Sipag data.

Depending on where you live you may also have the right to a copy of your data, to object to or restrict processing, or to complain to your data protection authority. Write to studio@collaub.com and we will respond within 30 days.

Children

Sipag is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has given us personal information, contact us and we will delete it.

Security

Traffic between the app and our servers is encrypted with HTTPS. Sign-in uses Google’s OAuth flow, so we never handle your password, and the session token is kept in your device’s secure storage. No system is perfectly secure, but we take reasonable steps to protect your data.

Changes to this policy

If we change this policy we will update the date at the top of this page, and for significant changes we will notify you in the app.

Contact

Questions about privacy, or a request about your data: studio@collaub.com.