Skip to content

Privacy Policy

What we collect, why we are allowed to, who else sees it, and how to make us delete it.

Last updated 27 August 2026 · SLIDESVAMP, LLC

The short version

You give us an email address and five short lines of text a day. We store them so we can show them back to you. If you agree to it, we also count which features get used — never what you wrote. We do not use advertising or tracking pixels, and we have never sold anyone’s data and will not. If you want it all deleted, email support@getonepercentbetter.net and we will, within 30 days.

The rest of this page is the same thing said carefully, because a summary is not a policy.

1. Who we are

Get1%better is operated by SLIDESVAMP, LLC, a limited liability company registered in the State of Delaware, United States. For data protection purposes we are the data controller: we decide what is collected and why.

Registered address: 131 Continental Dr, Suite 305, Newark, DE 19713, United States.

Questions, requests and complaints all go to support@getonepercentbetter.net. A person reads that address.

2. What we collect

Things you give us

  • Email address and password. Required to have an account. Your password is hashed by our authentication provider before it is stored — it is never written down in a form we can read, and we cannot tell you what it is.
  • Profile details, all optional. A display name, a profile photo, and your time zone. The time zone exists so “today” means your today and your day rolls over at your midnight.
  • What you write. The task titles you type, the date each belongs to, their order, and the moment you tick one off. This is the substance of the service. Treat it the way you would a notebook someone else is storing for you: it is private, but it is not encrypted in a way that hides it from us, so do not put secrets in it.

Things we generate

  • Account timestamps — when you signed up, when a record last changed.
  • Payment records, only if you buy a paid plan. Your Stripe customer reference, which plan you are on, whether the subscription is active, and when the period ends. Card numbers never reach our servers. Checkout is hosted by Stripe on Stripe’s own pages; we receive confirmation that you paid, not the means you paid with.
  • Server logs. Our host records IP addresses and request metadata for a short period, as any web server does. We use them to keep the service up and to investigate abuse, not to build a picture of you.

3. What we do not collect

This list is as much a part of the policy as the one above, and we intend to keep it true:

  • No analytics at all unless you accept it. If you do, PostHog counts which features get used. It never receives your task text, your folder names or your searches, and there is no session recording.
  • No advertising, ad networks, or tracking pixels.
  • No third-party fonts or scripts loaded from other companies’ servers. Our fonts are served from our own domain, so loading a page tells nobody but us that you visited.
  • No location data, contacts, or device fingerprinting.
  • No selling, renting or sharing of personal data with anyone for their own purposes. Not now, and if that ever changed we would have to ask you first.
  • No automated decision-making or profiling that produces legal or similarly significant effects.

Under the UK and EU GDPR every use of personal data needs a lawful basis. Ours:

What forDataLawful basis
Running your accountEmail address, password, profile detailsPerformance of a contract — we cannot give you an account without them (GDPR Art. 6(1)(b))
Storing what you writeYour tasks, their dates and completion timesPerformance of a contract — this is the service you asked for (Art. 6(1)(b))
Taking paymentPlan, subscription status, Stripe customer referencePerformance of a contract (Art. 6(1)(b)), and a legal obligation for tax records (Art. 6(1)(c))
Keeping the service up and unabusedIP address and request metadata in server logsLegitimate interests — security, fraud prevention and diagnosing faults (Art. 6(1)(f))

Where we rely on legitimate interests, you can object — see your rights.

5. Who else sees it

We use three service providers. They process data on our instructions under contract, and none of them may use it for their own purposes:

ProviderWhat they doWhat they see
SupabaseDatabase, authentication and file storageEmail address, password hash, profile details, tasks, avatar images
CloudflareHosting, content delivery and network securityIP address and request metadata, held briefly in server logs
StripePayment processing (only if you buy a paid plan)Name, email, billing address and card details — collected by Stripe, never by us
PostHogProduct analytics (only if you accept analytics cookies)Account id, which features you used, page paths, browser and country — never task text

Beyond those, we will disclose data only where the law requires it — a valid court order or equivalent legal process — or to establish or defend a legal claim. If we are ever compelled to hand over your data we will tell you, unless we are legally barred from doing so.

If the business is ever sold or merged, account data would transfer with it. You would be told before that happened, and it would not change the commitments on this page without your agreement.

6. Where your data goes

We are a United States company and our providers operate globally, so your data may be processed outside the United Kingdom and European Economic Area. Where it is, those transfers are covered by the European Commission’s Standard Contractual Clauses and the UK Addendum, which each of the providers above offers as part of its data processing agreement.

7. How long we keep it

  • Your account and your tasks: until you ask us to delete them. We do not expire accounts for inactivity, and we do not quietly delete old history — a record with holes in it would defeat the point of keeping one.
  • After a deletion request: removed from our live systems within 30 days. Encrypted backups roll over on their own schedule and are fully cycled within 90 days.
  • Payment and tax records: retained for seven years after the transaction, because tax law requires it. This is the one category we cannot delete on request.
  • Server logs: a short rolling window, then discarded.

8. Your rights

If you are in the UK or the EEA the GDPR gives you the following. We extend them to everyone who uses Get1%better, regardless of where you live, because operating two standards would be more effort than honouring the higher one.

  • Access — a copy of everything we hold about you.
  • Rectification — correct anything wrong. Most of it you can edit yourself on your profile.
  • Erasure — delete your account and its contents.
  • Portability — your data in a machine-readable file, to take elsewhere. Available now, on any plan, from your settings as CSV or JSON.
  • Restriction and objection — tell us to stop a particular use, including anything based on legitimate interests.
  • Withdraw consent — where we relied on consent, withdraw it at any time. This does not undo what was lawful before you withdrew.

How to use them: email support@getonepercentbetter.net from the address on your account. We will respond within 30 days, and it is free. Export is self-service on your profile. Account deletion is not built yet, so for that one email is the route — and it works today.

If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to your national data protection authority without contacting us at all. In the UK that is the Information Commissioner’s Office; in the EEA it is the supervisory authority where you live.

9. If you are in the United States

Several states, California among them, give residents rights to know what is collected, to delete it, and to opt out of its sale or sharing. The first two are covered above and available to you on the same terms. The third does not arise: we do not sell or share personal information, as those terms are defined under the California Consumer Privacy Act, and we do not offer financial incentives in exchange for data. We will not discriminate against you for exercising any of these rights.

10. Security

Everything is served over HTTPS. Passwords are hashed by our authentication provider. Session cookies are set httpOnly and secure, so a script running in your browser cannot read your session token. Database access is constrained by row-level security, meaning the rules that stop one account reading another’s tasks are enforced by the database itself rather than by application code remembering to check.

No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach ever affects your personal data we will notify the relevant supervisory authority within 72 hours as required, and tell you directly where there is a high risk to you.

11. Children

Get1%better is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.

12. Changes to this policy

When this policy changes, the date at the top changes with it. If a change materially affects your rights or how we use your data, we will email registered users before it takes effect rather than rely on you noticing a new date.

13. Contact

SLIDESVAMP, LLC — support@getonepercentbetter.net