Privacy Policy
Effective date: April 23, 2026
Welcome. This is where we describe how Checklust handles your information. This policy applies to the website at checklust.com and any related services that display a link to this policy (collectively, the “Services”).
Checklust is a free, non-commercial community project. It is operated as a personal project by Sub_Pixel, based in California, United States. No money changes hands. No ads are served. No data is sold. Checklust is maintained on a best-effort basis by one person in their spare time; detailed terms of use, including warranty disclaimers and limitations of liability, live in our separate Terms of Service.
The important part, up front
Checklust exists to let you record and share sensitive personal information — your kink preferences, limits, and experiences. This is special category data under the EU General Data Protection Regulation (Article 9) and sensitive personal information under California law. We treat it accordingly.
- We do not use third-party analytics on your checklist responses.
- We do not log your responses in application logs.
- We do not serve ads and have no advertising partners.
- We do not sell, rent, or share your information for marketing.
- Share links are opt-in, use unguessable tokens, can be revoked at any time, and reveal no identity beyond the display name you choose to show.
The rest of this document is the detail behind those commitments.
Information we collect
From you, when you create an account
- Email address. Used to sign in, to send password reset emails, and to contact you about material changes to this policy or your account.
- Password. Stored only as a hash (via better-auth); we cannot read your password.
- Display name (optional). A name you choose for yourself. Shown to you in the app, and shown on shared checklists only if you explicitly opt in per share.
From you, when you use the Services
- Your checklist responses. Ratings (0–5), soft/hard limit markings, and “have done” flags for individual activities, for both the giving and receiving dimensions. Timestamps of when each activity was answered.
- Your checklists. Names you give your checklists, the date you created them, and when they were last updated.
- Your share links. The random tokens we generate when you create a share link, the associated checklist, optional expiry date you set, and view counts (so you can see if your share has been opened).
Automatically
- Session cookie. An HTTP-only, SameSite=Lax cookie under the name prefix
checklust.session_token, used to keep you signed in. MarkedSecurein production. This cookie is essential to the Services — without it you cannot stay signed in. - Basic request data. Our hosting provider (Cloudflare) logs standard request information — IP address, user agent, timestamp, requested URL — for security, abuse prevention, and service reliability. This data is processed under Cloudflare’s own policies and is not joined against your checklist responses.
What we do not collect
- We do not collect demographic information, payment information, ethnicity, age (beyond your attestation that you are 18+), or biographic profile information.
- We do not use third-party analytics (no Google Analytics, Plausible, PostHog, or similar).
- We do not use advertising cookies, tracking pixels, social media widgets, or any third-party tracking technologies.
- We do not scan, read, or analyze the content of your checklist responses for any purpose other than rendering them back to you or to someone you’ve chosen to share with.
How we use your information
We use the information we collect only for the following purposes:
- To provide the Services. To store your account, render your checklists, autosave your responses, compute progress and next-activity ordering, and serve shared views to people you send share links to.
- To authenticate you. To sign you in, manage your session, and let you reset your password.
- To communicate with you about the Services. Password reset emails, security notices, and notice of material changes to this policy. We do not send marketing email.
- To keep the Services secure and operational. To detect and prevent abuse, investigate technical issues, and enforce our Terms of Service.
- To comply with legal obligations. Where required by applicable law.
How we share your information
We share your information only in these limited circumstances:
- With people you’ve chosen to share with. When you generate a share link, anyone who has that link can view the checklist it points to, in read-only form, until you revoke it or it expires. You control when, whether, and how long to share. You control whether your display name appears on the shared view.
- With our hosting provider, Cloudflare. Checklust runs entirely on Cloudflare infrastructure — Cloudflare Workers, D1 (database), and Email Sending. Cloudflare is our sole processor and is contractually bound by their Data Processing Addendum. Cloudflare processes data in accordance with their own privacy policy: https://www.cloudflare.com/privacypolicy/.
- When required by law. If we receive a valid legal request (subpoena, court order, or equivalent) from a competent authority, we may be required to disclose information. We will push back on overbroad or improper requests. Given the free, personal-project nature of Checklust, we have no dedicated legal team and cannot guarantee specific response practices.
We do not:
- Share your information with affiliates, advertisers, analytics vendors, or marketing partners.
- Share your information for another party’s direct marketing purposes.
- Sell your information, under any definition of “sell” including the broader California definition that includes sharing for consideration.
Where your data is stored
Your information is stored on Cloudflare’s D1 database, which runs on Cloudflare’s global network. Cloudflare replicates and caches data across regions for performance and durability. This means your data may be stored or transmitted through countries outside your own, including the United States.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you should be aware that your information will be transferred to the United States. We rely on Cloudflare’s Standard Contractual Clauses and other safeguards Cloudflare maintains for international transfers.
Security
We use reasonable administrative, technical, and physical security controls appropriate for a project of this size:
- HTTPS for all traffic.
- HTTP-only, SameSite=Lax session cookies with the Secure flag in production.
- Password hashing via better-auth (we never store or see your password in plaintext).
- Share tokens with at least 192 bits of entropy (unguessable).
- Cloudflare’s platform-level security (WAF, DDoS mitigation, encryption at rest).
Things we want to be honest about:
- This is a personal project, not a company with a security team. We do not have SOC 2, ISO 27001, or equivalent third-party audits.
- We do not currently offer two-factor authentication. We may add it later.
- No system is perfectly secure. Please don’t record information in Checklust that you would not want disclosed in a worst-case breach.
If we ever become aware of a security incident that affects your information, we will notify affected users without undue delay and disclose what we know.
How long we keep your information
- Account and checklist data: retained as long as your account is active. If you delete your account, we delete your account record and all associated checklists, responses, and share tokens within 30 days.
- Share tokens: deleted immediately when you revoke a share, and deleted automatically at expiry if you set one.
- Email and security logs (at the Cloudflare layer): retained per Cloudflare’s own retention policies.
- Backups: deleted data may persist in routine backups for a short period before being overwritten in the normal backup rotation.
You can delete your account at any time from your account settings. All other fields on your account — email, display name, password, checklists, responses, share tokens — are also fully self-service. You can change anything you entered, and Checklust does not alter your data on your behalf.
Your rights
Depending on where you live, you may have legal rights over your information. Regardless of where you live, Checklust extends these rights to all users:
- Access. You can see all the information Checklust holds about you directly in the app. If you’d prefer a downloadable copy, you can request an export.
- Correction. Every field is self-serve — you can edit your email, display name, password, checklists, and responses in the app at any time.
- Deletion. You can delete your account and all associated data directly from your account settings. You can also revoke individual share links at any time.
- Export. You can request an export of your checklists and responses in a machine-readable format.
- Objection / restriction. You can ask us to stop processing your information, subject to our legal obligations.
- Withdraw consent. Where we rely on consent to process your information, you can withdraw that consent at any time by editing or deleting the relevant data.
To exercise any of these rights, email us at support@checklust.com. We’ll respond within 30 days, or 45 days for complex requests. We may need to verify your identity before acting on a request — typically by confirming control of the email address on your account.
If you live in California
Your privacy matters to us, and while Checklust as a small non-commercial personal project almost certainly isn’t required to comply with the California Consumer Privacy Act (CCPA, as amended by the CPRA), we try to mirror its protections as closely as we can. The rights listed above are available to all users regardless of whether the law technically applies to us.
For transparency, here’s how your information maps to California’s categories:
- Identifiers: your email address.
- Internet or other electronic network activity information: session cookie data, basic request logs at the hosting layer.
- Sensitive personal information: your checklist responses constitute information about your sex life and sexual orientation. We collect this information only because you choose to enter it, we use it only to provide the Services to you, and we do not use or disclose it for any secondary purpose.
We do not sell or share (in the CCPA/CPRA sense) personal information, and we have not done so in the past 12 months. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit.
If you live in the EEA, UK, or Switzerland
Our legal bases for processing your information under the GDPR are:
- Contract. Processing your account and checklist data is necessary to provide the Services you’ve asked for.
- Consent. Where we process your sensitive category data (your checklist responses), we rely on your explicit consent, which you give by creating a checklist and entering responses. You can withdraw consent at any time by deleting individual responses, checklists, or your account.
- Legitimate interests. For basic security, abuse prevention, and keeping the Services operational, where those interests are not overridden by your rights.
- Legal obligation. Where applicable law requires processing.
You have the right to lodge a complaint with your local Data Protection Authority.
If you live in Colorado, Connecticut, Virginia, or another US state with a similar law
You generally have rights similar to those listed above, including the right to appeal if we deny a rights request. We do not engage in profiling that produces legal or similarly significant effects.
Children
Checklust is strictly for adults. The Services are not intended for anyone under 18, and we do not knowingly allow or collect information from anyone under 18. If you’re under 18 and have signed up, or if you believe a minor has created an account, email support@checklust.com and we will delete the account and all associated data promptly. If you’re a minor who signed up by mistake, no hard feelings — we’ll take care of it, and you’re welcome back once you’re of age.
Cookies
We use exactly one cookie: the session cookie that keeps you signed in, described in the “Automatically” section above. We do not use analytics cookies, advertising cookies, social media cookies, or any third-party cookies. We honor Do Not Track and Global Privacy Control signals — they have no additional effect because we already don’t do the things those signals ask us not to do.
Changes to this policy
We may update this policy from time to time. If we make material changes, we’ll give you at least 30 days’ notice by email to the address on your account and by posting notice in the app. The current version is always available at checklust.com/privacy.
Contact
For any privacy question, rights request, concern, or general inquiry, email support@checklust.com.