Privacy Policy

Last updated: August 18, 2026

1. Who we are

Tododo (“we”, “our”, “us”) is a task management service. Contact: privacy@tododo.io

2. Data we collect

  • Account data — email address, name (via Clerk)
  • Task data — tasks, subtasks, notes, due dates you create
  • Usage data — AI conversation history (stored in Redis, TTL 1 hour)
  • Device data — push notification token (for reminders)
  • Google Calendar connection data — your Google account email, OAuth access and refresh tokens, granted scopes, the identifier of the dedicated Tododo calendar, and mappings between eligible tasks and events Tododo creates
  • Payment data — handled entirely by Stripe; we never store card details

3. How we use your data

  • To provide and improve the Tododo service
  • To send reminders and notifications you have requested
  • To process payments and manage subscriptions
  • To respond to support requests

4. Google Calendar integration

Connecting Google Calendar is optional. If you connect it, Tododo requests your Google account email and permission to manage only calendars and events created by Tododo.

  • Tododo creates a separate calendar named “Tododo” and does not read or modify your other calendars or events
  • Active top-level tasks with an explicit date and time are sent to Google as 30-minute events, including the task title, notes, start time, end time, and a link back to Tododo
  • Updating, completing, cancelling, or deleting an eligible task updates or removes its corresponding Google event
  • OAuth tokens are encrypted at rest and are used only to provide the calendar synchronization you request
  • Disconnecting removes the dedicated Tododo calendar, revokes Google access, and deletes the stored connection and event mappings from Tododo

We do not use Google user data for advertising, profiling, or training generalized AI models, and we do not sell it. We disclose it only to Google as needed to perform the synchronization you request, or where required by law. Tododo's use of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

5. Data sub-processors

  • Clerk — authentication (EU DPA available)
  • Neon — PostgreSQL database (EU region)
  • Upstash — Redis cache (EU region)
  • Stripe — payment processing
  • Resend — transactional email
  • Anthropic / OpenAI — AI inference (messages processed, not stored by provider beyond inference)
  • Expo — push notifications
  • Google — optional Google Calendar synchronization

6. Data retention

We retain your data for as long as your account is active or as needed to provide the feature you requested. Google Calendar connection data is retained until you disconnect the integration or delete your Tododo account. You can disconnect Google Calendar from Settings → Integrations and delete your account from Settings → Data & Privacy.

7. Your rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Request access to your data by contacting us
  • Correct inaccurate data
  • Delete your data (Settings → Delete account)
  • Withdraw consent at any time
  • Lodge a complaint with your local supervisory authority

8. Cookies

The web app uses only strictly necessary cookies for authentication. No third-party tracking cookies are used.

9. Changes

We will notify you of material changes by email. Continued use after the effective date constitutes acceptance.

10. Contact

For privacy requests: privacy@tododo.io. You can also review the Terms of Service.