Privacy Policy
In short. Todo Space has no accounts and works offline. Everything you type — lists, tasks, notes, reminders, settings — stays on your device, and we never see it. Only a little technical data ever leaves your device: anonymous crash diagnostics (to fix bugs), purchase validation (only if you buy the premium unlock), and routine checks for app updates. We show no ads, run no analytics, do no tracking, and never access your location.
1. Introduction
This Privacy Policy explains how Everyday Tools ("we", "us", "our") handles information in connection with the Todo Space application for Android ("the app"). We built Todo Space to work offline and without accounts, and we designed it to collect as little data as possible. This policy describes the limited data that leaves your device, why it does, who processes it, and the rights you have. By using the app you acknowledge the practices described here; if you do not agree, please discontinue use of the app.
2. Who we are
The party responsible for the limited processing described below (the "data controller" under the GDPR) is:
- Everyday Tools — independent app developer
- Email: everydaytools.dev@gmail.com
3. Information we process
The table below summarizes every category of data involved. Only the first three rows leave your device; your actual content never does.
| Data | Purpose | Legal basis | Recipient | Retention |
|---|---|---|---|---|
| Crash & error diagnostics (technical only — see §5a) | Detect and fix crashes and bugs | Legitimate interests | Sentry (EU) | Per Sentry's policy (up to ~90 days by default) |
| Purchase validation: Google Play purchase token + anonymous app-generated identifier | Verify a purchase and unlock premium features | Performance of a contract | Google Play, RevenueCat | As needed to manage the purchase and meet legal obligations |
| Update checks: app version, platform, IP address (server logs) | Deliver over-the-air app updates | Legitimate interests | Expo | Transient server logs |
| Your content: lists, tasks, notes, templates, reminders, settings | Core app functionality | Not applicable — stays on device | No one (on-device only) | Until you delete it |
4. Data stored only on your device
All of your content lives in local storage on your device and is never collected or transmitted to us: your lists, tasks, notes, and templates and any text you type into them; your reminder schedules, repeat rules, colours, themes, and app preferences; and your premium-unlock status. When you export a backup, the backup file is created on your device and shared only where you choose to send it — it is not sent to us or to any third party by the app.
5. Third-party services
We rely on a small number of independent service providers ("processors"). Each has its own privacy policy, which we encourage you to review.
a) Crash diagnostics — Sentry
If the app crashes or hits an error, it sends a technical diagnostic report to
Sentry so we can fix the fault. The report contains
only technical information: the error type, message, and code stack trace (file paths reduced
to app-relative); your device model, operating-system version, and the app version and build number; the
screen where it happened as a generic pattern (e.g. /list/[id], never a real identifier), the
app's internal database version, and non-text counters (such as how many items a list has, or a list's
status). It never contains the text of your lists, tasks, notes, or titles, your note
contents, clipboard or imported text, backup data, search terms, your name, email, IP address, or device
name, and we attach no screenshots or view of your screen. Reports are processed on Sentry's servers in the
European Union (Germany).
b) Purchases — Google Play & RevenueCat
The app is free and offers one optional premium unlock. If you choose to buy it, the payment is processed by Google Play Billing — we never receive or see your card or payment details. To confirm the purchase and unlock premium features, a Google Play purchase token and a random, app-generated identifier are processed by RevenueCat. This identifier is anonymous; the app does not link it to your name, email, or Google account.
c) App updates — Expo
The app checks for over-the-air updates from Expo (EAS Update). This transmits technical build information such as the app version and platform; Expo may record standard server-log data, including IP address, to deliver the update. No content or personal profile is sent.
6. What we do not collect or do
- No user accounts and no sign-in.
- No advertising and no advertising identifiers.
- No analytics or behavioural tracking, and no tracking across other apps or websites.
- No location data.
- No access to your contacts, photos, camera, or microphone for data collection.
- No selling or sharing of personal information for marketing or advertising.
A note on permissions. The app may ask for the notification permission solely to show the reminders you schedule. Those notifications are generated on your device; no notification content is sent to us or to any server. You can grant or revoke this permission in your Android settings at any time.
7. Legal bases for processing
For users in the European Economic Area and the United Kingdom, we process the limited data above on these bases under the GDPR / UK GDPR:
- Legitimate interests — for crash diagnostics (keeping the app stable and correct) and for update delivery. The data involved is technical and minimized, and we have weighed our interest against your rights and freedoms.
- Performance of a contract — to process and validate a purchase you initiate.
- Consent — where your operating system requires your permission (for example, to show notifications). You may withdraw such consent at any time in your device settings.
8. Data retention
- On-device content — retained until you delete it, clear the app's data, or uninstall the app.
- Crash diagnostics — retained by Sentry in line with its data-retention policy (up to approximately 90 days by default).
- Purchase records — retained by Google and RevenueCat as needed to manage your purchase and to meet legal and accounting obligations.
- Update logs — transient server logs held by Expo.
9. Data security
We minimize the data that leaves your device, and any data transmitted to our processors is sent over encrypted connections (TLS/HTTPS). Your content remains within the app's private storage area, isolated by the Android operating system. No method of transmission or electronic storage is completely secure, but we and our processors take reasonable technical and organizational measures to protect the limited data involved.
10. International data transfers
Some of our processors are located outside your country — for example, RevenueCat and Expo in the United States, and Google globally — so the limited data described above may be transferred internationally. Where such transfers are subject to data-protection law, they rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Crash diagnostics are processed within the European Union.
11. Your privacy rights
Because most of your information never leaves your device, the most powerful controls are always in your hands: edit or delete any content inside the app, revoke permissions in your Android settings, or clear all app data / uninstall the app. In addition, depending on where you live, you may have the following rights.
a) European Economic Area & United Kingdom (GDPR / UK GDPR)
You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on our legitimate interests, as well as to withdraw consent where processing relies on it. You also have the right to lodge a complaint with your local data-protection supervisory authority.
b) California (CCPA / CPRA)
We do not sell or share your personal information, and we have not done so in the preceding twelve months. You have the right to know what personal information is processed, to request its deletion or correction, and not to be treated in a discriminatory way for exercising your rights.
c) How to exercise your rights
To exercise any right over data held by our processors, contact us at everydaytools.dev@gmail.com. Please note that crash diagnostics are anonymous and may not be linkable to you, which can limit our ability to act on such a request.
12. Children's privacy
Todo Space is a general-audience productivity app and is not directed to children under 13 (or the minimum age of digital consent in your country). We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will take appropriate steps to address it.
13. Cookies and similar technologies
The app is a native Android application and does not use cookies or web-tracking technologies. When this policy page is viewed on the web it is served as static content and sets no advertising or tracking cookies.
14. Automated decision-making
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects concerning you.
15. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, for material changes, provide a notice in the app or on the store listing where appropriate. Your continued use of the app after changes take effect constitutes acknowledgment of the updated policy.
16. Contact us
If you have any question about this policy or your data, contact us at everydaytools.dev@gmail.com.