Legal
Last updated: 11 July 2026
Privacy policy
Tododay is a small, independent app. We use your data only to operate the service, to make your todo list appear on your phone, and never for profiling, personal targeting, or sale to third parties. This page explains what we store, why, and the limited exceptions below.
01Who we are
Tododay ("we") operates the Tododay app and this website. For anything related to your data, the data controller can be reached at [email protected]. Contacting us by email is the fastest way to exercise any of the rights below.
02What we collect
- Your email address: used only to sign you in, to deliver the account emails you request (such as a password reset code or an email change confirmation), and, if you write to us, to reply. You can change it any time inside the app.
- Your password: stored only as a bcrypt hash. We cannot read it, and neither could anyone who copied our database.
- Your display name: optional, only if you choose to set one, used only to greet you inside the app. It is end-to-end encrypted, see Encryption below.
- Your todos: the text, status (done, missed, staged) and timestamps of your tasks, so they can sync between the app and the server. The text of each todo is end-to-end encrypted, see Encryption below.
- Your preferences: like whether unfinished tasks should automatically carry over to the next day, used only to control app behavior for your account.
- Basic technical data: like any server, ours briefly processes your IP address to deliver responses and to rate-limit sign-in attempts. Traffic to the app and this website passes through Cloudflare, which sees the same kind of anonymised network-level data as part of keeping things fast and secure. None of it is used to build a profile of you.
- Anonymised website analytics: this marketing website requests your consent, through the on-screen cookie prompt, before using any analytics or advertising tool such as Google Analytics or Meta's pixel. Where permitted, these tools measure visits in aggregate, anonymised form and support general promotion of the app. This data is never linked to your account or your todos, never used to target you personally, and never present inside the app itself.
- Your cookie choice: whether you accept or decline that prompt, we store your choice in your browser's local storage for approximately six months, so you are not asked again on every visit. This choice is never transmitted to or stored on our server.
This is the complete list of data we collect. We do not collect location data, contact lists, or device fingerprints, and none of the above is ever used for profiling or personalised advertising.
03Why we process it
Your account and todo data is processed for exactly one purpose: providing the service you signed up for, keeping your account secure and your list in sync. In legal terms, that processing is necessary to perform our contract with you (providing the app) and to protect the service from abuse (our legitimate interest in rate-limiting and security). The website's anonymised analytics, where used, rest on our legitimate interest in understanding and promoting the app in general terms, never on identifying you individually.
04Where it lives
Your account and todos are stored on our own self-hosted server, not on a third-party cloud platform. The app also keeps a copy of your list on your own device so it works offline, and the optional home-screen widget reads that same on-device copy to show today's list on your home screen. The widget introduces no new collection and sends nothing anywhere, though anyone who can see your home screen can of course see the tasks it displays. The website and app sit behind Cloudflare for security and performance, and the website may use an analytics or advertising provider such as Google or Meta, as described above. Beyond that, nothing personal is shared with, sold to, or processed by any third party.
05What we will never do
- Sell your personal data or your todos to anyone.
- Use your account, your todos, or how you use the app to target ads at you.
- Build a personal profile of you or track you individually across the web.
- Email you anything except replies to messages you send us and the emails your account itself needs: password reset codes, email change confirmations, and a security notice to your old address if your account email is changed.
The only advertising we do is generic promotion of the app itself, using anonymised, aggregate analytics on this website, never anything drawn from your account.
06Security
Passwords are stored as bcrypt hashes. Session tokens are stored only as SHA-256 hashes, so a copy of the database cannot be used to hijack a session. Changing your password signs out every other device automatically. No security is perfect, but nothing we store is usable in plain form.
07Encryption
Your todo text and display name are encrypted on your device before they are ever sent to our server, using a key derived from your password. We store only the encrypted result and a copy of that key locked with your password. We cannot open either one, and neither could anyone who copied our database, including us.
A few fields stay unencrypted so the app can function: your email address, needed to sign you in, and basic todo metadata such as completion status, dates, and priority colour, which lets sync work without exposing what a task actually says.
This has one real consequence worth knowing: because we cannot read or recover your encrypted content, resetting a forgotten password normally cannot bring your existing tasks back. When encryption turns on for your account, the app gives you a one-time recovery key. Save it somewhere safe, it lets you reset your password without losing your tasks. Without it, a password reset starts your account's tasks fresh, there is no back door we can use to recover them, since building one would undermine the protection itself.
08Sessions
When you log in, you remain logged in on that device until you log out, change your password, or clear the app's data. This is a deliberate choice: a personal productivity app should not require you to re-enter your password on a regular basis. As a safeguard, a login that has not been used at all for twelve months is removed on our side; the device simply asks you to log in again.
09How long we keep it
Your account and todos are kept until you delete them. Deleting a todo in the app deletes it on the server too. Technical logs are short-lived and rotate automatically. If you ask us to delete your account, everything goes with it. The anonymised website analytics described above are never tied to an account in the first place, so there is nothing of yours left behind to keep.
10Your rights
Depending on where you live (for example under the GDPR), you have the right to access, correct, export, and erase your personal data, to restrict or object to its processing, and to complain to your local data-protection authority. With us it's simpler than that: correcting your email is Me, then Manage account, then Change email (we confirm the new address with a code and notify the old one), and both export and deletion are one tap inside the app itself, open Me, tap Manage account, then Export data or Delete account. Export writes every task you have to a file, in full, readable form, since it comes straight from your own decrypted copy, not from us (we could not decrypt it if we tried). Deletion is immediate and permanent: your account, your todos, and everything tied to them are gone the moment you confirm your password.
No app on hand, or no access to your device? Email [email protected] from the address you signed up with and we will delete your account by hand, or submit a request directly at tododay.co/delete-account. We can also confirm what account-level data we hold (your email, sign-up date, and similar) on request.
11Children
Tododay is not directed at children under 13 (or the higher age your country requires), and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
12Changes
If this policy changes in any material way, the date at the top will be updated and the app's store listing will note it. The principle behind it, that your data belongs to you, will not change.
13Contact
Questions about this policy, or requests regarding your data, can be sent to [email protected].