Last updated 09/2026
Takto is operated by Takto Ltd. We are the “data controller” for the personal data described here, which means we decide how and why it’s used. Contact us about anything in this policy at hello@takto.app.
When you create an account:
When you set up your profile:
As you use Takto:
If you subscribe: your Stripe customer and subscription identifiers, and your subscription status. We do not receive or store your card number, expiry, or security code — those go directly to Stripe.
Automatically: standard server and security logs from our hosting provider, which include IP addresses and may be retained briefly for security and debugging.
We don’t use advertising cookies or third-party trackers. Storage in your browser is limited to keeping you signed in and remembering how many idea sets you’ve generated.
| What we do | Why | Lawful basis |
|---|---|---|
| Create and run your account | To give you the service you signed up for | Contract |
| Generate ideas from your niches and formats | The core function of Takto | Contract |
| Save and schedule your ideas | So they’re there when you come back | Contract |
| Send posting reminder emails | Reminders are part of how the service works, and you can switch them off at any time | Legitimate interests / contract |
| Take payment and manage subscriptions | To provide the paid tier | Contract |
| Send account emails | To operate your account securely | Contract |
| Keep the service secure and debug faults | To protect users and keep Takto working | Legitimate interests |
| Comply with tax and accounting duties | We have to | Legal obligation |
We don’t sell your data, and we don’t use it to train AI models.
Takto runs on third-party services. Each one only receives what it needs:
| Provider | What they get | Purpose |
|---|---|---|
| Supabase | Account details, profile preferences, saved ideas | Authentication and database |
| Vercel | Server logs, requests | Hosting the app and its API |
| Anthropic (Claude) | Your selected niches, formats and techniques — not your name, email or account ID | Generating ideas |
| Stripe | Email address, payment details you enter with them | Taking payment, managing subscriptions |
| Resend | Email address and the ideas due that day | Sending reminder emails |
| Google (Gmail SMTP) | Email address | Sending subscription confirmation emails |
Some of these transfer data outside the UK. Where that happens we rely on the UK’s adequacy regulations or on standard contractual clauses with the provider.
We may also disclose data if we’re legally required to, or to protect our rights or someone’s safety.
Under UK GDPR you can ask us to access, correct, delete, restrict, or port your personal data, to object to how we use it, or to withdraw consent where we relied on it. Email hello@takto.app and we’ll respond within one month.
You can turn off reminder emails yourself at any time: Profile → Posting Reminders → Off. That stops all reminder emails immediately. You’ll still receive essential account emails such as password resets, because they’re needed to operate your account securely.
If you’re unhappy with how we’ve handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We’d appreciate the chance to put it right first.
Passwords are hashed by our authentication provider and never stored in readable form. Traffic is encrypted in transit. Card details never touch our servers.
No system is perfectly secure. If a breach affects your rights and freedoms, we’ll notify you and the ICO as required.
Takto isn’t intended for under-18s and we don’t knowingly collect their data. If you believe a child has given us personal data, contact hello@takto.app and we’ll delete it.
We may update this policy. If a change matters to you, we’ll tell you by email or in the app. The “last updated” date always reflects the current version.
hello@takto.app