Privacy Policy
Last updated August 25, 2026
The free tier: your content stays on your device
On the free tier the app has no account, and your todo content is never uploaded to True To-do. Your weeks, your outlines, and your per-weekday templates are written to your browser's storage on the device you typed them on. They are not uploaded, not backed up by us, and not readable by us. If you clear your browser's site data or storage for the app, that content is gone and we cannot restore it. Removing the installed app may or may not clear that storage — this varies by browser and platform, so clearing the site's storage is the reliable way to delete it.
Your browser may also delete it on its own, without asking you. Browsers reclaim storage from sites you have not used recently — Safari, for example, clears a site's stored data after about seven days of browser use without a visit. This is the browser's behaviour, not ours, and because nothing is on our side we cannot restore what it removes. Two things reduce the risk: installing the app to your home screen or desktop, which most platforms treat as a stronger signal to keep its data, and Pro, which keeps a cloud backup of every week. If your weeks matter to you, do not rely on browser storage alone.
The app does send limited technical and usage telemetry, which never includes the text of your to-dos — see Analytics and error reporting below.
This has a consequence worth stating plainly: there is no free-tier account to delete, because there is nothing on our side to delete.
What a Pro account holds
This is the full inventory of personal data connected to a Pro account. For each category we give its source, why we hold it, the GDPR lawful basis we rely on, the categories of recipient it may be shared with, and how long we keep it. Those recipient categories are described further under Who else touches your data. We do not sell any of it and we do not share any of it for advertising.
Account identity
Your email address, an internal identifier for your account, which sign-in method you used, and — if you sign in through a third-party provider — any name and profile photo that provider returns to us. We also record when the account was created and the time of the most recent sign-in. We never receive your password or your contacts from a third-party sign-in.
- Source — you, and your chosen login provider.
- Purpose — to create and secure the account, identify you across devices, and contact you about billing or a service problem.
- Legal basis — performance of your Pro contract.
- Recipients — our authentication provider; our cloud hosting provider; our payment processor (Stripe), which receives your email address to attach it to the subscription.
- Retention — for the life of the account. Deleted from live systems when you close the account, then from backups on their normal rotation (see Closing your account).
Your weeks and templates
The content of your to-dos: your weekly outlines, your per-weekday templates, and the small set of preferences that sync with them (which weekdays you show, the names you give weeks). It is stored as an opaque blob that our systems do not parse, encrypted in transit and at rest.
- Source — you, as you use the app.
- Purpose — to sync your weeks to your other devices and keep a cloud backup. We do not routinely inspect or analyze your todo content. Authorized access is limited to operating, securing, restoring, and supporting the service; complying with law; or actions you request. It is not used to train anything, and we do not sell it or share it for advertising.
- Legal basis — performance of your Pro contract.
- Recipients — our cloud hosting and storage provider.
- Retention — kept until you delete it in the app or close the account; see How long it is kept.
Subscription and payment records
Which plan you are on and whether it is current, plus the customer and subscription identifiers issued by our payment processor,Stripe. Stripe itself holds the payment and billing data behind the subscription, and also holds it for its own purposes under its ownprivacy policy. We never see or store your full card number.
- Source — our payment processor, from the details you enter at checkout.
- Purpose — to run the subscription, apply the correct tax, handle refunds and disputes, and keep lawful financial records.
- Legal basis — performance of your Pro contract for running the subscription; legal obligation for keeping tax, accounting, and payment records. The payment processor's own handling of this data rests on its own legal bases, set out in its privacy policy.
- Recipients — our payment processor; our cloud hosting provider for the identifiers and status we store; tax and accounting authorities where the law requires.
- Retention — the plan status lives with the account; billing and tax records are kept for the period tax and accounting law requires, typically several years, regardless of what happens to the account.
Marketing consent
Whether you opted in to marketing emails, and the timestamp and context of that choice (or of a later withdrawal).
- Source — you, at sign-up or later.
- Purpose — to send marketing emails only if you asked for them, and to be able to show that you did.
- Legal basis — consent for sending the emails; our legitimate interest and legal obligation for keeping the record of consent.
- Recipients — our cloud hosting provider for the record; our email provider to deliver any emails you opted into.
- Retention — the opt-in flag is cleared when you withdraw consent or close the account; a minimal record that consent was given or withdrawn, and when, is kept for a limited period afterwards as evidence.
Support correspondence
If you contact support, we keep what you send — the support-form message or email, and the thread that follows. The support form runs an automated anti-abuse check in your browser; we receive only a pass or fail result.
- Source — you; our anti-abuse provider for the check result.
- Purpose — to answer you, keep context for follow-ups, and stop automated abuse of the form.
- Legal basis — performance of the contract where the query concerns your account; legitimate interests otherwise and for the anti-abuse check.
- Recipients — our email provider, for the support mailbox and our replies; our anti-abuse provider.
- Retention — up to 24 months after the matter is resolved, then deleted.
Security and diagnostic logs
Server-side records of requests to our service: IP address, timestamps, the approximate location that the IP implies, a session identifier, and which operation was requested. Request URLs in this app do not contain the text of your to-dos.
- Source — generated automatically as you use Pro.
- Purpose — to detect and investigate abuse, debug sync and sign-in failures, and keep the service secure.
- Legal basis — legitimate interests.
- Recipients — our cloud hosting provider.
- Retention — roll off within 90 days.
Product and error telemetry
Which screens are opened and which features are used, plus the technical details of errors — browser, app version, stack trace — along with a device or session identifier and a correlation ID used to tie an error to the session it happened in, and the approximate location implied by your IP. When you are signed in, an internal account identifier is attached as well, so that we can trace an error back to your account while debugging it; this identifier is not your email address, and it appears only on the short-lived raw data described below, never on the aggregate figures we keep. The text of your to-dos, week names, and imported content are never included.
- Source — generated automatically by the app.
- Purpose — to find crashes and see which parts of the app people actually use.
- Legal basis — legitimate interests.
- Recipients — our analytics and error-reporting provider.
- Retention — raw event and error data rolls off within 30 days; aggregated figures are kept indefinitely and are not tied back to your account.
Email delivery events
For the transactional and any opted-in emails we send you, our email provider reports whether each one was delivered, bounced, or was marked as spam.
- Source — our email provider.
- Purpose — to know whether account and billing emails are reaching you, and to stop sending to addresses that hard-bounce or complain.
- Legal basis — legitimate interests.
- Recipients — our email provider; our cloud hosting provider.
- Retention — delivery logs are kept by our email provider for a short period (around 90 days); a bounce or complaint flag against your address is kept for as long as the account is open.
Payments
Pro payments are handled by Stripe. We never see or store your card number. The processor handles the card details directly and returns only what we need to run the subscription. Stripe also holds your payment information for its own purposes, and its handling of it is governed by its own privacy policy.
Analytics and error reporting
The app reports usage and errors to a third-party analytics and error-reporting service, and this marketing site counts page views with the same service. Both are configured without cookies and without cross-site tracking identifiers, and neither is an advertising network. They report to separate collections, and we do not link your visits to this site with your use of the app.
The app stores a random identifier on your device. It is generated in your browser's local storage the first time the app runs, contains no information about you, and lets us tell that the same device came back — so we can see whether people keep using the app, rather than only how many times it was opened. It is not linked to your name, your email, or your account, and we cannot use it to identify you. Turning off "Send usage & crash data" in Settings → Privacyerases it, and switching telemetry back on later starts a new one rather than resuming the old. If your browser sends a Do Not Track or Global Privacy Control signal and you have not chosen otherwise, it is never created at all. This marketing site stores no such identifier — it counts page views only.
What the app reports is which screens are opened, which features are used, and the technical details of errors — browser, app version, stack trace.The text of your to-dos is never included in telemetry or error reports. We use this to find crashes and to see which parts of the app people actually use. Telemetry from a signed-in session is linked to your account for up to 30 days so we can debug a problem that affects you specifically; after that only account-free aggregate figures remain. We do not use any of this to build a profile of you, and we do not run advertising or share this data with advertisers.
Do Not Track and Global Privacy Control
Some browsers can send a "Do Not Track" (DNT) or Global Privacy Control (GPC) signal. These signals exist mainly to opt you out of the sale of your personal information and cross-context behavioral advertising.We do not sell or share your personal information, we do not serve advertising, and we do not track you across other sites or apps — so there is nothing for these signals to switch off. Because our practice is already the outcome a DNT or GPC signal asks for, we treat that request as satisfied and do not change our behavior based on the signal.
Who runs this
True To-do is operated by Nathan R., an individual sole proprietor in the United States, and is the data controller for the information described here. Questions about anything on this page go to support@truetodo.com. If you need to reach us by post — or need our details in writing for a formal request — email us and we will provide them.
Who else touches your data
Only the parties needed to run the service, and only for that purpose.
- Providers acting on our instructions. Cloud hosting and storage, the account email we send you, and the analytics and anti-abuse services described above. Each is contractually bound to process your data only on our instructions and only to provide their service to us.
- Stripe and Auth0.Our payment processor and sign-in provider handle some of your data as independent controllers and also hold it for their own purposes under their own privacy policies, not this one — see Stripe's privacy policy and Auth0's privacy policy. We only receive back what we need to run your subscription or sign you in.
- Legal authorities. We will disclose data if legally compelled to, and if that happens we will tell you where we are legally permitted to and where it is reasonably practicable.
- A successor. If True To-do is sold, merged, reorganized, or its assets are transferred — in whole or in part, including in connection with an insolvency — your data may be transferred to the successor as part of that transaction or during due diligence under a confidentiality obligation. The data moves with the service, and this policy continues to apply until you are told otherwise.
We do not sell your personal information and we do not share it for advertising.
How long it is kept
Your synced weeks stay for as long as you want them. We do not put an expiry clock on your content, and we do not delete old weeks to save space — cloud backup of every week is the thing you paid for, so keeping it is the point. Your history stays browsable as far back as it goes.
This is about the copy held on our servers. The copy on your own device is separate: it is not affected by any of the below, and the app keeps working offline against it whether or not you have Pro.
The only thing that removes your content from our servers is you asking. Delete it in the app, or ask us to close the account, and we remove your synced data — see Closing your account for what that does and does not reach.
When a Pro subscription lapses, sync uploads stop, but the copy of your weeks already on our servers stays. We do not put it on a deletion schedule, and we do not send warnings before removing a non-subscriber's cloud content because we do not proactively remove it at all. If you resubscribe later, sync simply resumes against the data that was waiting.
Separately: billing records are kept as long as tax and accounting law requires, whatever else happens to the account. Diagnostic and security logs roll off within 90 days. Raw product telemetry, including any link to your account, is deleted within 30 days; only aggregate figures that are not tied back to your account are kept after that.
Your rights
You can ask us to show you what your Pro account holds, correct it, export a machine-readable copy of the data you gave us, restrict or object to a particular use of it, delete it outright, or withdraw any consent you gave — email support@truetodo.com. Depending on where you live these rights may arise under the GDPR, the UK GDPR, or US state privacy laws such as the CCPA; we extend them to everyone regardless of where you are.
We acknowledge every request without undue delay and aim to respond within 30 days. Where a request is complex, or you have made several, we may extend that by up to a further two months and will tell you why within the first month.
If you think we have handled your data wrongly you can complain to your data protection supervisory authority — in the UK the Information Commissioner's Office, in the EEA the authority for the country where you live or work — though we would appreciate the chance to put things right first.
Where the GDPR applies, we rely on these lawful bases:
- Contract — creating and running your account, syncing and backing up your weeks, taking payment, and providing account support.
- Legal obligation — keeping tax, accounting, and payment records for the period the law sets.
- Legitimate interests — keeping the service working, secure, and free of abuse, answering non-account support queries, and keeping a record that marketing consent was given or withdrawn. We have weighed each of these against your interests and rights.
- Consent — sending marketing emails, and any optional analytics we ask you to turn on. You can withdraw consent at any time, from any marketing email or by contacting us, without affecting anything done before you withdrew it.
Closing your account
When you close your Pro account we cancel any active subscription, sign out your sessions, and delete your synced data, your account details, and your marketing preferences from our live systems. The copy of your data on your own devices is not touched — clear the app's site data on each device to remove it there.
A few things do not go away immediately. Some billing, tax, and security records must be kept for a period set by law, whatever happens to the account. Deleted data can also persist in our encrypted backups until those backups expire on their normal rotation, after which it is overwritten and unrecoverable. Nothing in this residue is used for any purpose other than the legal obligation or backup integrity that requires it to exist.
Where your data lives
Our servers are in the United States. If you use Pro from outside the US, your synced content is transferred to and stored in the US. The providers that work on our instructions to run the service — cloud hosting and storage, the account email we send you, analytics and error reporting, and the anti-abuse check on the support form — may also process data in the United States and in other countries where they or their own subprocessors operate.
Where this involves moving personal data out of the UK, the EEA, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum for UK data), together with the technical safeguards described under Security — traffic encrypted in transit and synced content encrypted at rest. Our providers are contractually bound to equivalent terms for any onward transfer. To ask for a copy of the safeguards that apply to a particular transfer, email support@truetodo.com.
Our payment processor (Stripe) and our sign-in provider (Auth0) decide their own transfer arrangements as independent controllers under their own privacy policies — see Stripe's privacy policy and Auth0's privacy policy. We receive back only what we need to run your subscription or sign you in.
A current list of the providers we use to run the service is available on request — email support@truetodo.com.
Sensitive information in your to-dos
You control what you enter into True To-do, and you are responsible for it, including any personal information about other people. The service is not designed, and is not certified, to hold data that is subject to a specific regulatory regime or that would cause serious harm if disclosed. You must not use it as a system of record for:
- protected health information governed by health-privacy law;
- account credentials, passwords, or authentication secrets;
- full payment-card numbers or financial-account credentials;
- government-issued identification numbers;
- information whose handling is restricted by law and requires safeguards we do not represent that we provide.
Security
Traffic is encrypted in transit and synced content is encrypted at rest. That said, no service can promise perfect security, and we do not. If a breach affects your data we will notify you and the relevant regulators as required by law.
Children
True To-do is intended for adults. You must be at least 18 to use the app or hold a Pro account. The service is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn that we have collected personal information from a child under 13, or that someone under 18 has created a Pro account, we will close the account and delete the associated data. If you believe a child has provided us personal information, email support@truetodo.com.
Changes
If this policy changes we will update the date at the top. For a change that materially reduces your privacy, we will email Pro account holders before it takes effect rather than relying on you to re-read this page.