Legal

Terms of Service

These Terms of Service apply to the MonoList mobile application, developed and published by Michael Guggenberger.

1. Scope

These terms apply to your use of MonoList. By downloading and using the app, you accept these terms.

2. Description of Service

MonoList is a task list app for personal lists, tasks, notes, and reminders. The app stores your task data locally in SQLite on your device. There is no MonoList user account and no MonoList backend for your task data.

3. Usage Rights

By downloading MonoList, you receive a non-exclusive, non-transferable right to use the app for private purposes on your own devices.

4. Voluntary Support Purchases

MonoList is free and ad-free. Optional one-time support purchases are voluntary tips that help fund development. They unlock no features, remove no limits, and create no entitlement state. Purchases are processed by Apple's App Store or Google Play and are subject to their respective terms and refund policies.

5. Reminders and Backups

MonoList may offer local reminders, manual export, encrypted backup files, and optional automatic encrypted snapshots. You are responsible for keeping exported files, backup destinations, and backup passphrases safe. MonoList cannot recover lost passphrases.

6. Liability

MonoList has been developed with care. However, errors, interruptions, data loss, or incorrect reminder behavior cannot be fully excluded. To the extent permitted by law, liability for damages arising from use of the app is excluded; mandatory statutory liability remains unaffected.

7. Data Protection

Our Privacy Policy applies. MonoList stores task data locally by default. Data is only transferred if you export it yourself, save backups to a destination you choose, contact us, or complete an in-app purchase through Apple or Google.

8. Changes to these Terms

Michael Guggenberger may update these terms where required for legal, technical, or organisational reasons. The published version in effect applies.

9. Governing Law

Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods. Mandatory consumer protection rights in your country of residence remain unaffected.

Privacy Policy

This Privacy Policy explains which data this website and the MonoList mobile application process, what it is used for, and which rights you have. The controller is Michael Guggenberger, Straßganger Straße 58, 8052 Graz, Austria. Last updated: August 1, 2026.

1. Controller

The controller for MonoList is Michael Guggenberger, Straßganger Straße 58, 8052 Graz, Austria. You can contact us by email at info@miguapps.com. No data protection officer has been appointed.

2. Visiting this website

When you visit this website, the web server processes technically necessary access data so that the site can be delivered, operated reliably, and protected against misuse. This includes in particular your IP address, the date and time of the request, requested URL or file, data volume transferred, status code, referrer URL, browser, operating system, and user agent. The website is hosted by Vercel Inc.; Frankfurt am Main, Germany, is configured as the region for this website. Vercel may use further subprocessors and its global edge infrastructure for delivery, security, support, and error analysis. The legal basis is our legitimate interest in secure and reliable operation under Article 6(1)(f) GDPR. Access data is retained only as long as required for operation, error analysis, and security, then deleted or anonymized unless a security incident or legal obligation requires longer retention. The website uses only the NEXT_LOCALE language-preference cookie (German or English). It is a session cookie, is deleted when you close your browser, is transmitted only over HTTPS in production, and is set with SameSite=Lax. It is technically necessary to provide the language version you select; the legal basis is Article 6(1)(f) GDPR. No non-essential cookies, accounts, forms, advertising, or analytics scripts are used.

3. Contact by email

If you contact us by email, we process your email address, message, attachments, and technical communication data such as sender and recipient addresses, subject line, and sending and receiving times to respond to your request. We use Apple's iCloud Mail for email communication. Depending on the subject of your request, the legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual communication, or Article 6(1)(f) GDPR based on our legitimate interest in handling enquiries. Emails are deleted once they are no longer needed to handle your request, unless statutory retention obligations apply.

4. Local storage and app functions

By default, MonoList stores the data you enter locally on your device: lists, task text, notes, completion status, creation and update times, ordering, reminder times, and technical reminder identifiers. Task data is stored in SQLite. The app also stores local settings such as language, appearance, display options, App Lock status, backup settings, backup destination, and backup status. The purpose is to provide the app functions you expressly request; the legal basis is Article 6(1)(b) GDPR. There is no MonoList account and no MonoList server for this data, and we cannot access your lists, tasks, or notes. The app does not request special categories of personal data. Since free-text fields can contain any content, you should not enter sensitive data there unless necessary.

5. Manual export, import, and restore

You can export your MonoList data as a readable JSON file or as an encrypted .mlbackup file. A JSON export is unencrypted. When you save or send a file through the share sheet, the recipient or service you choose and its privacy notice determine further processing. When restoring, MonoList reads only a file you explicitly select. Encrypted exports are protected with a passphrase you choose. MonoList never sends the passphrase to us and cannot recover it. Restoring replaces the currently stored lists and tasks after confirmation.

6. Optional automatic encrypted backups

Automatic backups are optional. If you enable them, MonoList derives an encryption key from your passphrase on your device and stores that derived key locally in the operating system's protected Secure Store; the passphrase itself is neither stored nor sent to us. The key is deleted when you disable automatic backups, but may also be lost through the operating system. The app writes encrypted snapshots to a destination you choose: app storage, an Android folder you select, or MonoList's iCloud Drive container on iOS. The content of lists and tasks is encrypted before it leaves the app. Technical metadata remains unencrypted, including the creation time in the file name and the number of lists and tasks in the file envelope. No more than seven automatic snapshots per backup destination and build channel are retained; disabling the feature does not automatically delete existing backup files. We do not operate a server for these storage locations and cannot access backup content. An Android folder you select may be synchronized by its provider, such as a cloud-storage service.

7. In-app purchases

MonoList's only store products are optional, repeatable support tips. Payment processing, store accounts, and refunds are handled by Apple or Google under their own terms and privacy notices. MonoList processes the product ID and technical transaction data only locally and temporarily where needed to retrieve prices or complete or consume a support purchase. This data is not sent to MonoList servers, permanently stored, or logged. The legal basis for app-side processing is Article 6(1)(b) GDPR. Support purchases unlock no features and do not change how task data is handled.

8. Permissions and device services

MonoList may request notification permission for local task reminders. It does not retrieve push tokens or use its own push service. For a reminder, the app provides the operating system with the task title, a technical task ID, and the time; depending on your device settings, the task title may be visible on the lock screen or in the notification center. For import, export, and a backup folder, MonoList accesses only files or folders that you explicitly select and does not scan media libraries. If you enable optional App Lock, MonoList uses your device's Face ID, fingerprint, or passcode. The app does not receive raw biometric data, only whether authentication succeeded. App Lock does not encrypt the local SQLite database; the protection of stored data otherwise depends on your device's security mechanisms.

9. No ads, no analytics tracking

MonoList and this website contain no advertisements, analytics tracking, or third-party tracking scripts. We do not collect data for marketing or analytics purposes. Technical server logs used for delivery and security, and the operating-system, store, and storage functions described in this policy, are unaffected.

10. Retention and deletion

Local app data remains on your device until you delete it in the app, remove the app, or your device deletes it. Export files and backups remain under your control at their storage location until you delete them there. Automatic backups are rotated as described in section 6. If you send us data for support, we use it only to handle your request and delete it once it is no longer needed, unless statutory retention obligations apply.

11. Recipients and international transfers

Recipients may include Vercel Inc. as hosting and CDN provider, Apple as the provider of iCloud Mail and iCloud Drive, and Apple or Google for app-store and operating-system functions. If you choose a cloud provider as backup destination or a service for sharing an export, that provider is an additional recipient chosen by you. Vercel may process technical access data outside the EU or EEA. Vercel describes Standard Contractual Clauses or other appropriate transfer mechanisms for this purpose; you can request further information and a copy of the applicable safeguards at info@miguapps.com. Apple, Google, and cloud or sharing providers you choose process data under their own privacy notices and may also process it outside the EU or EEA.

12. Your rights

Under the GDPR, you have rights including access, rectification, erasure, restriction of processing, data portability, objection, and, where processing is based on consent, withdrawal of that consent. Because MonoList does not receive your task data by default, many of these rights can be exercised directly in the app, for example by exporting, editing, or deleting your data. You also have the right to lodge a complaint with a data-protection supervisory authority, in particular the Austrian Data Protection Authority.

13. Contact

If you have questions about this policy or your privacy rights, contact us: Michael Guggenberger, Straßganger Straße 58, 8052 Graz, Austria. Email: info@miguapps.com