TinyTodo

Privacy policy

Your list.
Your choices.

Draft for the private beta · Updated 6 October 2026

TinyTodo stores your list on your Mac. Cloud sync and access by AI clients are optional. This policy describes the current beta.

Contact

Support and privacy contact details will be published here before public release.

What stays on your Mac

Without cloud sign-in, task titles, notes, colors, reminders, repeat schedules and completion history are stored locally. Notification permissions and app preferences are managed on your device. Backups and exports are saved to a location you choose; that location may itself sync through a service you use.

What optional sync stores

When you sign in, TinyTodo merges your local list into your account. The cloud service stores your tasks and schedules, task identifiers and versions, completion and deletion state, recent changes, and records needed to synchronize edits reliably.

Sign in with Apple is processed through Amazon Cognito. Apple provides an account identifier and may provide your email address or a private relay address. TinyTodo uses the verified account identifier to separate accounts. TinyTodo does not receive your Apple password. App session credentials are stored in the macOS Keychain; TinyTodo stores hashes of its own connection tokens on the server.

When you connect an AI client

A client you authorize can read task content and recent changes, and perform the actions listed on the consent screen. Depending on your permissions, those actions include creating, completing, editing, deleting and restoring tasks. AI clients cannot delete your TinyTodo account.

Content returned to a client is handled by that provider under its own terms and privacy policy. Disconnecting a client stops future access but does not remove content already copied into conversations or other systems. Only connect clients you intend to share your list with.

Why data is processed

Account and task data are used to provide the features you request. The proposed basis for this processing is performance of the service agreement. Limited operational records are used to keep the service secure and reliable, based on the legitimate interest in operating the service. Support correspondence is used to answer your request. The legal basis will be finalized before public release.

Service providers and location

TinyTodo’s cloud backend uses Amazon Web Services in Ireland (eu-west-1). Apple provides sign-in, and any AI provider you connect processes the content it receives. The backend region is not a promise that all providers process all data exclusively in the EEA. Provider agreements and any required international-transfer safeguards must be finalized before public launch.

Website, cookies and logs

The product pages do not include analytics scripts, advertising pixels or marketing cookies. Sign-in uses a short-lived, secure browser cookie to bind the login to your browser. Service logs contain operational details such as request identifiers, status, route and latency, with a configured retention of 14 days. The application does not intentionally log task content, passwords or tokens.

How long data is kept

Your own exports, backups and data already shared with AI providers are outside this account-deletion process. See Manage your data for the practical steps and limits.

Your choices and rights

You can use the local list without cloud sign-in, disconnect AI clients, export your tasks and delete your account. Depending on applicable law, you may also request access, correction, deletion, restriction or portability, or object to processing based on legitimate interests. Use the contact details on this page for requests once available. You can complain to your local data-protection authority; in Norway, this is Datatilsynet.

Changes to this policy

Changes will be published here with an updated date. Material changes to connected data use will be explained before they take effect.