Privacy Policy
Last updated 28 August 2026
ToDo is a task list that your own AI assistant fills in. Understanding the privacy of it turns on one fact: ToDo never connects to your email, calendar or chat. It has no credentials for them and cannot read them. Your Claude or ChatGPT subscription reads those through connectors you have already authorised, decides what needs doing, and sends the result here.
What is stored
Because your assistant writes your list, the list contains whatever it chose to put there. In practice:
- Tasks — the title and description your assistant wrote, which bucket it chose, its reason, any due date, and who a task should be delegated to.
- Source details — where a task came from: the provider, the message or event identifier, the sender, the subject line, and a short quoted snippet. This is a derived copy of parts of your mail and calendar, and it is the most sensitive thing here.
- Links — the URLs that open the original item in Outlook, Gmail, Teams, Zoom or a calendar.
- Drafts — if you turn the setting on, the text of replies your assistant wrote for you.
- Your actions — what you completed, dismissed, snoozed or delegated, and when. This is sent back to your assistant so it stops re-raising things you have handled.
- Your account — email address, name if given, timezone, and a hash of your password.
- Sessions and devices — browser and approximate IP for each sign-in, so you can recognise and end them, plus push notification tokens for devices where you enabled notifications.
- Connection tokens — a hash of each token you create for an assistant, its name, and when it was last used.
What is not stored
- Your email account credentials — ToDo has none and never asks for them.
- Full message bodies, attachments, or your mailbox. Only what your assistant chose to include in a task.
- Your plaintext password, or the plaintext of any connection token. Both are stored only as hashes.
- Analytics, advertising identifiers, or third-party trackers. There are none in this application.
Why it is stored
Solely to run the service for you: to show your list, to open the right message when you tap a task, to send the notifications you asked for, and to tell your assistant what you have already handled. Your data is not sold, rented, or used to train any model.
Who else sees it
- Your AI assistant provider — Anthropic or OpenAI, depending on which you connect. They receive your tasks because they write them and read them back. Their handling is governed by their own terms, not this policy.
- Hosting and database providers — this deployment runs on infrastructure operated by The NetSys Group, who should name their hosting and database providers and regions here.
- Email delivery — the provider configured for confirmation and password reset messages sees your email address.
- Push services — Apple, Google and browser vendors relay notifications. They see the notification and the device it is bound for.
Nobody else. There is no advertising, no data brokerage, and no analytics vendor.
How long it is kept
- Open tasks stay until you or your assistant clear them.
- Completed tasks are removed automatically after the period you choose in Settings — a day, a week, a month, or never.
- Records of what you have handled persist so your assistant does not re-raise them, and go when you delete your account.
- Expired sessions, used email links and rate-limit counters are deleted automatically.
Deleting everything
Settings → Account → Delete my account. It takes effect immediately and removes your account, every task, every source detail, every draft, every connection token and every device registration. There is no soft delete and no recovery. Export your data first from the same screen if you want a copy.
Your rights
Depending on where you live you may have rights to access, correct, export or erase your personal data, and to object to its processing. Access and export are available in the app immediately; erasure is the delete button above. For anything else, contact jbaum@netsysgroup.com.
Security
- Passwords are hashed with scrypt and a per-password salt.
- Session cookies and connection tokens are stored only as SHA-256 hashes; a token's plaintext is shown once, at creation.
- Sign-in, sign-up and password reset are rate limited.
- Every record is scoped to its owner, and that isolation is covered by automated tests on every change.
- Changing or resetting your password signs out every other device.
No system is perfect. If you find a security problem, please report it to jbaum@netsysgroup.com rather than disclosing it publicly.
Children
ToDo is not intended for anyone under 16, and accounts are not knowingly created for them.
Changes
If this policy changes materially, the date above changes and account holders are notified by email before it takes effect.