Privacy Policy
Effective date: September 26, 2026
This policy explains how Todo Thing handles information in our apps and at todothing.app.
Who we are and how to contact us
THINGS THINGS THINGS LLC operates Todo Thing and is responsible for your personal information (the data controller). For privacy questions, access or correction requests, or help deleting data, email hello@thingsthingsthings.studio.
What we collect
- Account information: your email address (including an Apple private-relay address), Google or Apple account identifier (subject ID), account status, and sign-in session records. We do not receive your Google or Apple password.
- Planner content: todos, subtasks, folders, daily focus text, ordering, preferences, and AI results you save. Reminders, notification schedules, and widget copies are also stored on your device.
- Voice and AI input: when you use voice on iOS, Android, or the web, audio is sent through our server to OpenAI for transcription, and the transcript is processed to extract todos. Other AI features send relevant task or focus text and context for first steps, long-todo summaries, cleanup, day suggestions, and research.
- Google Calendar: when connected, authorization tokens and event information such as titles, times, descriptions, locations, and meeting links needed to display or manage your calendar.
- Usage analytics: optional feature-use events, counts, app and device metadata, and a randomly generated analytics identifier on iOS and Android. These events do not intentionally include your name, email, planner text, recordings, or calendar content. We do not enable session replay. Although the setting is called Anonymous Analytics, an installation identifier can distinguish repeat visits.
- Diagnostics: error codes, operation timings, app version, device/installation identifier, and account attribution used to investigate failures. Android uses a hash of the opaque account identifier; iOS uses the opaque account identifier (usr_…). Native diagnostic uploads do not include email, todo text, or free-form error messages. Anonymous Analytics controls both usage analytics and remote diagnostics on iOS and Android; turning it off stops future collection and uploads. Web diagnostics can include an account identifier and are separate from the native setting.
- Security and deletion records: authorization leases, rate limits, deletion requests, and minimized records that prevent access after deletion. Android Restore Credentials use a public key and opaque account handle, not your password or planner content.
- Support and network information: information you choose to send us and connection metadata, such as IP addresses, processed by our hosting and service providers to deliver and protect the service.
How we use information
We use account and planner information to sign you in, synchronize your planner, and provide reminders and features you request. Calendar and AI data are used to provide the features you choose. Analytics help us understand feature use; diagnostics and security records help us fix faults, prevent abuse, and honor deletion requests. Support information lets us respond to you.
Where applicable, we process information to provide the service you request, for our legitimate interests in security and reliability, to meet legal obligations, and with your consent for optional access or processing where consent is required. We do not sell personal information or use planner content for advertising.
Service providers and sharing
We use the following providers and processing services for these purposes:
- Apple: optional iOS account sign-in, including Hide My Email. We retain an authorization token to revoke Todo Thing’s access when account deletion is fulfilled. Apple handles your Apple Account under its own privacy policy.
- Google: account sign-in and, when you connect it, Google Calendar authorization and event access. Google also supports Android Restore Credentials when available. Google handles your Google account under its own privacy policy.
- OpenAI: transcription of voice audio and processing of text for AI features, including task extraction, first steps, long-todo summaries, cleanup, day suggestions, and research. Relevant input is sent when those features run. OpenAI states that API data is not used to train its models by default.
- PostHog: optional usage analytics for the native iOS and Android apps, hosted in its US Cloud region.
- Cloudflare: website and API hosting (Pages and Workers), planner/session storage (KV), account-security storage (D1), and network security.
- thingsx3 diagnostics worker: our shared diagnostic logging service, hosted on Cloudflare Workers and D1, which receives operational diagnostics to troubleshoot Todo Thing. This is our infrastructure, not a separate advertising company.
Providers may process information outside your country. We may also disclose information where required by law or necessary to protect rights and security. Google Calendar information is used to provide the connected planner features, not for advertising.
OpenAI: your choice and retention
On iOS and Android, before your first voice or AI action, Todo Thing asks permission to share input with OpenAI. Tap Allow to enable AI for that account on that device, or Not now to continue using the planner without AI. Consent is stored locally per account; another device asks separately. AI Todo Suggestions starts off. You can withdraw permission in Settings → Behavior → AI features (OpenAI), which stops future AI requests. Turning AI off does not delete previously saved results or recall input already sent.
iOS and Android share the recording for transcription and the resulting todo text for task extraction, and share todo titles when combining voice todos. Text features share the relevant todo titles, folder names, and day context to generate first steps, game plans, cleanup, and day suggestions. OpenAI does not use API inputs or outputs for model training by default. Audio transcription has no application-state or abuse-monitoring retention; text sent to the Responses API may remain in abuse-monitoring logs for up to 30 days, or longer if legally required. We set store: false for new responses. Details: OpenAI API data controls.
Retention
- Account and planner data: kept while you use your account, until you delete the content or request account deletion. Deleted-item synchronization markers can remain for 30 days so removed items do not reappear.
- Sessions: expire after a 30-day window that can be renewed while you use the service. Signing out invalidates the current session; account deletion disables access across sessions.
- Calendar: connection credentials are retained until disconnection or account deletion. Event copies are used to show your calendar. Deleting Todo Thing does not delete your Google account or events that remain in Google Calendar.
- Voice: audio is temporary input, not stored as part of your synchronized planner. Transcription text and AI results that you save become planner content. OpenAI lists no application-state or abuse-monitoring retention for its audio transcription endpoint.
- AI text: we request that OpenAI not store new response objects. OpenAI may retain API content in abuse-monitoring logs for up to 30 days, or longer when legally required. Earlier stored responses follow OpenAI’s response-storage policy. We do not promise zero-data-retention for our OpenAI project. See OpenAI’s API data controls.
- Remote diagnostics: seven days, followed by the next daily cleanup run. Device diagnostic buffers are bounded and can remain until cleared, replaced, or removed with local app data.
- PostHog events: up to seven years under the current pay-as-you-go plan’s retention, unless deleted sooner. Turning analytics off stops future analytics collection; it does not automatically erase previously collected events.
- Deletion security records: minimized account-deny and keyed email-hash records remain indefinitely to prevent a deleted account from being reactivated. These records do not contain planner content or a plaintext email address.
- Support correspondence: retained while needed to resolve your request and meet legal obligations. You can request its deletion by email. Restricted provider recovery copies may persist for their recovery window; they are not used to restore access to a deleted account.
Delete your account and data
Request deletion in either app or on the web, even after uninstalling:
- iOS: Settings → Services → Account → Delete. Sign in with your account if prompted, type DELETE, and confirm the request.
- Android: open Settings → Delete Account, then follow the confirmation steps.
- Web: visit Delete account, sign in with Google, type DELETE, and submit.
Once your request is accepted, account access is disabled. We complete deletion of account and planner data from our active systems within 30 days of the request. Content-free deletion audit reports are kept for 90 days. A status-only browser receipt lasts 35 days so you can check completion on the deletion page after account sessions are erased. Acceptance and local app cleanup are separate from server erasure; an accepted request is not a claim that erasure has already finished.
Deletion removes planner data, account identity records, sessions, Calendar connection credentials, and Restore Credential records from our active service. The minimized permanent security records described above remain. Previously collected analytics follow their retention period; contact us for help requesting deletion of analytics associated with your installation. Provider recovery copies and legally required records follow the limits described above. Other devices may retain local copies until their app data is cleared; uninstall or clear Todo Thing on devices you no longer use.
If you cannot sign in or need help exercising a privacy right, email hello@thingsthingsthings.studio. We may need to verify that the account belongs to you. Depending on where you live, you may also have rights to obtain a copy, correct information, restrict or object to processing, or complain to your local data-protection authority.
Children
Todo Thing is not directed at children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has supplied personal information so we can investigate and remove it.
Security
We use HTTPS/TLS for network connections, access controls for server data, and platform credential protection: Keychain on iOS and Keystore-backed credential storage on Android. We limit diagnostic content and restrict administrative access. No service can guarantee absolute security.
Your choices and withdrawing consent
- Turn off Anonymous Analytics in the native app’s settings to stop optional usage analytics and remote diagnostic uploads. On iOS it is off until you enable it in onboarding or Settings; older default-on iOS preferences are reset to off. On Android it is on by default, as disclosed during onboarding.
- Choose whether to use AI features. Turn off automatic first-step suggestions and long-todo summaries where available, and avoid voice, cleanup, suggestions, or research if you do not want the corresponding content sent for AI processing.
- Decline or revoke microphone and notification permissions in your device or browser settings.
- Disconnect Google Calendar in Todo Thing, or revoke Todo Thing’s access in your Google account settings.
- Delete individual planner content, sign out, or request account deletion. Contact us to withdraw consent or ask about other privacy choices. Withdrawal affects future processing and does not undo processing already performed.
Changes to this policy
We will publish updates on this page and change the effective date. For material changes, we will provide an additional notice in the app or another appropriate way before new processing begins, and request consent when required.