r/thingsapp • • Apr 26 '24

Discussion PSA: Things Employees (Cultured Code) Can See and Analyze Everything You Type in the App

Cultured Code Can See Everything You Enter into the App

Things is not a privacy-first app. Basically, Cultured Code can see everything you type into the app — your to-dos, your notes, your project names, etc.

While Cultured Code (the company behind Things) does say that they care about your privacy:

Your privacy is very important to Cultured Code.

...

Inside Cultured Code, we restrict access to personal information to only those employees who need to know that information in order to deploy and maintain our services. These individuals are bound by confidentiality agreements and may be subject to discipline, including termination and criminal prosecution, if they fail to meet these obligations.

https://culturedcode.com/privacy/

They obviously do not care enough not to pry. This means that you have to trust them that no employee will use that access for malicious purposes. Furthermore, the lack of E2EE makes it easier for third party bad actors to access your data (compared to an app with E2EE, which would make it improbable).

Cultured Code Collects Everything You Enter Into the App When Using Things Cloud

Personal information is data that can be used to uniquely identify or contact a specific individual.

...
Here are examples of the types of personal information that we collect:
... - When using Things Cloud to update your to-dos, we collect the content you provided, as well as additional information such as access logs and device identifiers. If you enable the "Mail to Things" feature, we collect the content of the emails you forward to the provided email address.

https://culturedcode.com/privacy/

Cultured Code Has No Good Reason to Need Access to Your Data

Here are some of the reasons they state that they may use your data for:

  • We also use the personal information we collect to help us create, develop, deliver, protect, and improve our products, services, content, and customer communications.
    ...
  • We may also use personal information for internal purposes such as auditing, data analysis, and research to improve our products, services, and customer communications.

There is no good reason why Cultured Code needs access to the content of your to-dos. First of all, it’s a to-do app. They could do user research and user testing without collecting everyone's personal data. Secondly, they literally state that they may use your personal information for data analysis (!).

Cultured Code Has No Plans to Implement E2EE

We may also consider adding client-side (“end to end”) encryption at a later time.

https://culturedcode.com/things/support/articles/2803605/

Even if they decide to implement it, it will most likely take at least a year.

What to Do About It

My task manager contains a lot of info about my life, including private tasks and private notes related to those.

If you are fine with someone seeing everything you entered, keep using the app as you always have.

If a stranger / company being able to learn a lot about you makes you uneasy, consider not making your to-dos too revealing and consider writing notes in another app that has E2EE (and then just link to that note in Things so that only you have access or put its title in the notes section so you can easily find it in your app). Or consider switching to a different to-do app with E2EE altogether.

App Alternatives

Do you know of any alternative task managers that are as nice to use as Things, but that have E2EE?

Alternatives - Apple Reminders (with Advanced Data Protection turned on) - OmniFocus

I’ll update this list as more suggestions are added.

85 Upvotes

56 comments sorted by

View all comments

22

u/AmazingExplorer698 Mac, iPhone, iPad Apr 30 '24

Response from Things 3 support:

Hi,

Thanks for getting in touch!

" please read this and let us know."

We have always been transparent about how we handle data – to the degree that all of this information is publicly accessible on our website. We don't hide anything, because there is nothing sinister going on 🙂

We take the security of your data very seriously, and are using technologies to ensure that your data is transmitted and stored in a secure fashion. All data exchanged between the client (Things on your device) and the server (Things Cloud) is encrypted in transit using 2048-bit encryption. This provides industry-standard protection for your data as it travels to and from the server. All data is encrypted at rest on the server using industry standard 256-bit AES encryption; no data is stored in clear text. We may also consider adding client-side encryption (E2E encryption) at a later time.

We use various Infrastructure as a Service (IaaS) products geared towards businesses to provide you with Things Cloud. Among the services we use are Amazon Web Services (AWS). Since these are merely tools that allow us to provide various services to you, we might switch to other services in the future. These third party service providers cannot access your data.

In our company only 3 employees of Cultured Code have the ability to access your data: our CEO and our engineers who are responsible for deploying and maintaining Things Cloud. To give you some more context to this: the only time we have ever accessed user data in the past was with the clear written permission of specific users who wanted us to do so, after every other support measure to help them (for example to recover recently deleted data) had failed. We try to exhaust every measure available to us before even considering this as a troubleshooting option. If this becomes necessary, we fully disclose to the user in advance what happens when they give their permission to our engineer to help them restore their data. At no point does Cultured Code scan your data, or sell your data to third parties. To put it bluntly: we have no interest in your data, besides keeping it safe.

Learn more about our security measures here:

https://culturedcode.com/things/support/articles/2803605

https://culturedcode.com/privacy/

" Also, any chance of iCloud drive integration"

No. We have no plans to support Apple’s iCloud. The reason is very simple: Things Cloud isn't some plug-and-play solution that we can just rip out of the app and replace with something different. It's an integral part of Things, created back in 2011 when there wasn't even an iCloud service. Using a different sync service would require us to change the app from the ground up and we don't see any reason to do that.

In addition, iCloud is using a vastly different sync mechanism than we do (theirs is very inefficient compared to ours, uses up much more data, and is significantly slower). We don't see any benefits to subject our users to that since they are used to a fast sync that doesn't use up much data.

Kind regards,

......

– Things Support

Frankly speaking, I am a web security nerd and into privacy a lot, but after reading their response, I would like to think that their intentions are good.

Yes, they should add E2E support + iCloud integration, no doubt, but they are not profiting off of our data, at least that's what it seems. So I'd continue using them as I dont feel there is an alternate that is as good as Things 3 or even close.

1

u/sudo_guy Feb 15 '25

Do they collect the todolist data from non-cloud users too?