top of page
Hintergrund im darkmode mit feinen grünen abstrakten linien.jpg

Privacy Policy

This Privacy Policy informs you about the processing of personal data in the tDo mobile application on iOS and Android and in the cloud features operated for that app, in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and § 165 of the Austrian Telecommunications Act 2021 (TKG 2021). It does not replace the website imprint or the general website privacy notice.

tDo is local-first. Lists you keep only on your device stay on your device. Cloud processing starts only if you share a list, join a shared list, or generate a list with AI, and only after you accept this Privacy Policy and the Terms of Use in the app.

The full notice is this page. The app does not keep a separate copy of the legal text. Settings, the paywall, and the cloud-consent screen open this URL and the Terms of Use URL.

1. Controller

Xinger Solutions GmbH
Seefeldgasse 5
3462 Absdorf
Austria

  • Email: office@xinger.org

  • Phone: +43 676 83924444

  • Commercial register: FN 520445 k

  • VAT ID: ATU74837313

We have not appointed a data protection officer (not required for us under Art. 37 GDPR). For privacy requests, data-subject rights, and reports of illegal content on shared lists, use the email address above.

2. What tDo is

tDo is a checklist and to-do app. You can:

  • create lists and tasks that are stored on your device

  • optionally share a list with other people via a 6-character code and a 6-digit PIN

  • optionally generate a list from a short description using AI

  • optionally subscribe to tDo Premium to remove ads

tDo does not require a name, email address, or password. There is no public user profile.

3. Overview of processing

Situation: Using tDo without sharing, AI, or Premium
What happens: Lists, tasks, and settings stay on your device. If you are not a Premium subscriber, advertising SDKs may run (see section 8).

Situation: Sharing or joining a list
What happens: An anonymous device account is created. That list (name, tasks, completion state, appearance) is stored on our EU server so people with the code and PIN can sync in near real time.

Situation: Generating a list with AI
What happens: The same anonymous account is used. Your prompt is sent to our server and then to an AI provider to create a list. We do not store the prompt text in our logs.

Situation: tDo Premium
What happens: Apple or Google process the purchase. RevenueCat checks whether your store account has the Premium entitlement. Ads are then switched off.

4. Data we process

Personal data includes any information that relates to you, including identifiers that do not show your name (for example an anonymous user ID, an advertising ID, or an IP address).

4.1 Data on your device (local)

Stored locally (Hive / Shared Preferences), for example:

  • list names, colours, icons, sort order

  • task titles, completion state, timestamps

  • settings: language, colour scheme, whether completed tasks are shown

  • whether you accepted cloud features, and which legal-document version you accepted

  • share credentials for lists you own or joined: share code and PIN

  • a queue of changes waiting to sync while you are offline

The PIN is stored as a one-way hash on the server. On this device the PIN and code are stored so you can keep sharing without typing them again. Local storage is protected by the operating system’s app sandbox. It is not extra-encrypted by tDo. Anyone with unlocked access to your device, a backup, or a copy of the app files could read local lists and the locally stored PIN.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract: providing the app you installed).

This local data does not leave the device unless you use sharing, joining, or AI generation as described below, or unless your device backup includes the app data (section 4.10).

4.2 Anonymous cloud account (only after consent)

When you first share, join, or generate a list with AI, tDo creates an anonymous session on our server (Supabase Auth). No name, email, or password is collected. The identifier is a random user ID.

Legal basis: Art. 6(1)(a) GDPR (consent) together with Art. 6(1)(b) GDPR (providing the cloud feature you requested).

You can refuse. Local lists keep working.

Uninstalling the app does not always delete this anonymous server account. To ask us to delete it, email us as in section 10.

4.3 Shared list content

For a list you share or join, we store on our server:

  • list ID, name, colour, icon, sort order, created/updated time

  • task ID, title, completion state, sort order, timestamps

  • membership: which anonymous user IDs belong to the list (owner or editor)

  • share code

  • PIN as a one-way hash (not in plain text)

  • failed PIN attempts and a temporary lock timestamp after too many wrong tries

  • soft-deleted tasks until they are removed from the server copy

The app keeps an open connection (realtime) while a shared list is on screen so changes from others appear without a manual refresh.

Unshared lists are not uploaded.

Legal basis: Art. 6(1)(a) and 6(1)(b) GDPR.

Important: Shared list content is not end-to-end encrypted. Access is controlled by membership and by the code plus PIN. People you give both values to can read and edit the list. We can technically access server-side list content (for example to operate, secure, delete, or take down illegal content). Do not put secrets, passwords, health data, or other sensitive data in a shared list if you are not willing to accept that.

4.4 Data that comes from other people

If you join a shared list, we receive list and task content that other members wrote. If you share a list, other members receive content you wrote. That is needed to sync the list.

Legal basis: Art. 6(1)(b) GDPR (the sharing feature you asked for) and, for other members’ content stored so you can use the list, Art. 6(1)(f) GDPR (legitimate interest in providing the shared list).

Source (Art. 14 GDPR): the other participants in that list, via our server.

4.5 Share audit log

To prove consent and to limit abuse, the server logs:

  • time

  • anonymous user ID

  • event type (for example consent, share created, join success, failed attempt, lockout, leave, stop sharing, list deleted)

  • share code (not the PIN)

  • legal-document version you accepted

PINs and task titles are not stored in this log. Entries are deleted after 26 months.

Legal basis: Art. 6(1)(c) GDPR (accountability and proof of consent) and Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention). You may object to processing based on legitimate interests (section 11).

4.6 AI list generation

If you generate a list with AI:

  • your prompt and UI language are sent to our server, then to Groq to run a language model

  • the result (a suggested list name and tasks) is returned to the app; you decide whether to keep it

  • we log only: anonymous user ID, prompt length (not the text), locale, model name, status, item count, time

  • rate limit: 8 successful generations per anonymous user per hour

The feature is labelled in the app as list generation with AI. Output is machine-generated and can be wrong.

Legal basis: Art. 6(1)(a) GDPR (consent). You submit the prompt yourself.

We do not keep the prompt text in our audit log after the request. Groq processes the prompt to produce the result. Groq’s own retention and location follow Groq’s privacy policy. We cannot promise that Groq never logs a prompt.

Do not include names or other personal data of third parties in a prompt unless you have a legal basis to do so.

4.7 In-app purchases (tDo Premium)

If you subscribe:

  • Apple or Google process payment, tax, and the store account

  • RevenueCat receives an anonymous app user ID and purchase / entitlement status so tDo can remove ads and restore purchases after reinstall

  • we do not receive your full card number or your store password

Legal basis: Art. 6(1)(b) GDPR (subscription contract) and Art. 6(1)(c) GDPR where we or the stores must keep records.

4.8 Advertising (free version only)

If Premium is not active, tDo shows banner ads and occasional full-screen (interstitial) ads via AppLovin MAX. Interstitials may appear after you already have at least one list and create another list, after you share or join a list, or after you import an AI-generated list.

Depending on your consent in the consent screen (CMP) and, on iOS, Apple’s App Tracking Transparency prompt, advertising partners may process:

  • advertising IDs (GAID on Android, IDFA on iOS if you allow tracking)

  • IP address, device type, OS version, app version, language, country / region inferred from network

  • coarse location derived from IP (not GPS from tDo)

  • ad interactions (impressions, clicks)

  • SKAdNetwork conversion signals on iOS

  • diagnostic data the ad SDK needs to fill and measure ads

Android declares the AD_ID permission. iOS shows a tracking purpose string for personalized ads.

If you subscribe to Premium, ad initialization is stopped and ads are not shown.

Legal basis:

  • storing or reading identifiers on your device: consent under Art. 6(1)(a) GDPR and § 165 TKG 2021

  • personalized advertising: Art. 6(1)(a) GDPR

  • serving non-personalized ads after you refuse personalization, to fund the free app: Art. 6(1)(f) GDPR (legitimate interest), as far as the CMP and partners allow that mode

You can change advertising consent later in Settings > Privacy settings (the CMP). On iOS you can also change tracking in the system settings. This in-app entry is the privacy-choices control for advertising.

We do not use your list titles or task text to target ads.

4.9 Technical data on our server

When the app talks to our API (share, join, AI, realtime), standard server logs may include IP address, time, requested path, user agent / app version, and status code, for security and operation. We do not use this to build a marketing profile.

Legal basis: Art. 6(1)(f) GDPR (operation and security of the service).

4.10 Clipboard, backups, and OS permissions

  • Clipboard: if you copy a share code or PIN in the app, that text is placed on the device clipboard. Other apps you paste into may then see it.

  • Device backups: iCloud Backup, Android Backup / device transfer, and similar OS backups may include tDo’s local files (lists, settings, locally stored code and PIN). Those backups follow Apple’s or Google’s rules, not ours.

  • Permissions tDo declares: internet and network state (cloud, ads, purchases); Android advertising ID; Google Play Billing. tDo does not ask for camera, microphone, contacts, photos, or precise location.

Legal basis: Art. 6(1)(b) GDPR for features you use; backups are initiated by you or the OS.

4.11 Data we do not collect

We do not collect:

  • your name, postal address, or email as part of a tDo account

  • precise GPS location

  • contacts, photos, microphone, or camera

  • payment card details (the stores handle those)

  • crash analytics such as Firebase Crashlytics in the current tDo app

  • marketing emails from tDo (we have no email login)

5. Purposes

We process data to:

  1. store and display your lists on your device

  2. sync a list you chose to share with people who have the code and PIN

  3. generate a list from a prompt you enter

  4. show ads in the free version, with a consent choice in the EEA/UK

  5. provide and restore tDo Premium

  6. prevent abuse (PIN lockout, rate limits, audit)

  7. comply with law, including taking down illegal hosted content when we are notified

  8. defend legal claims

  9. improve reliability of cloud features (maintenance flag, error handling)

We do not sell your list content. We do not use shared task titles for advertising.

6. Recipients and processors

Recipient: Xinger Solutions GmbH
Role: Controller; operates the tDo API and database
Data: Shared lists, anonymous IDs, audit and AI metadata
Location: EU

Recipient: EU infrastructure host of our virtual server
Role: Processor (hosting)
Data: Server contents and backups as stored by us
Location: EU

Recipient: Other people with the code and PIN
Role: Independent users of that list
Data: Shared list and task content
Location: Wherever they use the app

Recipient: AppLovin Corporation (MAX)
Role: Independent controller / provider of the ad platform
Data: Device and ad data per their policy and your CMP choice
Location: USA and other countries

Recipient: Google (AdMob and Play services)
Role: Ad demand / store / billing
Data: Ad identifiers, app activity for ads; purchases on Android
Location: USA / global

Recipient: Other MAX demand partners
Role: Ad networks selected in our MAX dashboard
Data: Device and ad data if they win an auction
Location: Various, often USA

Recipient: Apple
Role: App Store, ATT, billing, SKAdNetwork
Data: Purchases, tracking permission, attribution
Location: USA / global

Recipient: RevenueCat, Inc.
Role: Processor / provider for subscription status
Data: Anonymous app user ID, entitlement, store product IDs
Location: USA

Recipient: Groq, Inc.
Role: Processor / provider for AI inference
Data: Prompt and locale for the duration of generation, plus any retention under Groq’s policy
Location: USA

Advertising partners can change over time. See AppLovin’s legal and partner information: https://legal.applovin.com/.

We disclose data to authorities or lawyers only if required by law or to establish, exercise, or defend legal claims.

7. Transfers outside the EEA

Our list-sync database is operated by us in the European Union.

These providers process data in the United States or other third countries:

Where GDPR requires a transfer tool, we rely on the EU-U.S. Data Privacy Framework for certified organisations, and/or the European Commission’s Standard Contractual Clauses, plus the provider’s security measures. Personalized ads and AI generation only run after you choose those features (and, for ads, after the CMP / ATT choice).

If you are in the United Kingdom, UK GDPR applies in a similar way. You may also contact the ICO (https://ico.org.uk).

8. Advertising in more detail

  • Mediation: AppLovin MAX chooses which network fills a banner or interstitial.

  • Google AdMob is integrated (app IDs are in the Android and iOS manifests).

  • Consent: In GDPR regions, MAX’s Terms and Privacy Policy flow / CMP is shown. You can reopen it under Settings > Privacy settings.

  • iOS tracking: Personalized tracking uses IDFA only if you allow it in Apple’s prompt. If you deny it, you may still see ads that are not based on that identifier. tDo respects the ATT answer.

  • Premium: No ad SDK traffic after Premium is confirmed.

Your choices:

  • refuse or limit personalization in the CMP

  • deny App Tracking Transparency on iOS

  • reset or opt out of the advertising ID in system settings (Android: Google settings; iOS: Tracking)

  • subscribe to tDo Premium

Partner policies:

Under some US state laws, sharing advertising identifiers with ad networks for cross-app advertising can be treated as a “sale” or “share” of personal information. tDo does not sell list content. You can opt out of personalized ads via the CMP and OS controls above. To request that we help as far as we control the data, email office@xinger.org.

9. Retention

Data: Local lists and settings
Retention: Until you delete them or uninstall the app (device backups may last longer under OS rules)

Data: Shared list content
Retention: Until the owner stops sharing (the server copy of that list is then deleted) or you ask us to erase it where we still hold it

Data: Local copy after stop sharing
Retention: Stays on each participant’s device until they delete it

Data: Share audit log
Retention: 26 months, then deleted

Data: AI audit (no prompt text)
Retention: Limited to what we need for quota and abuse control; we do not keep the prompt

Data: Anonymous cloud account
Retention: Until you ask us to delete it, or we delete unused accounts in the course of operations

Data: Server access logs
Retention: Short operational period, unless needed for security incidents

Data: Premium status
Retention: As long as the store subscription and restore need it; store invoices follow Apple/Google rules

Data: Ad data
Retention: According to each ad partner’s policy and your consent

Uninstalling tDo deletes local data on that device. It does not automatically delete a shared list still used by others, our audit records, store purchase records, or an anonymous server account we can no longer match to you without extra information.

10. How you can stop cloud use, change ad consent, and delete data

In the app:

  • Stop sharing (owner): the share code stops working and the server copy of that list is removed. Others keep their local copy, which no longer syncs.

  • Delete the list only on this device: other members keep their copy and can keep syncing if sharing is still active.

  • Leave a list you joined: you drop off the membership; the owner’s list can remain.

  • Privacy settings: reopen the advertising CMP.

  • Uninstall the app: local data on that device is removed.

To request erasure of server-side data we still hold (anonymous ID, leftover membership, audit rows where legally possible), email office@xinger.org. Because there is no email login, include:

  • that you are writing about tDo

  • share codes you used, if any

  • approximate dates

  • platform (iOS or Android)

We may not be able to identify a purely local-only user. Ad partners and Apple/Google/RevenueCat need their own tools for their copies of identifiers (device ad settings, store account, CMP).

You can withdraw consent for cloud features by not using them and by asking us to delete the anonymous server account where identifiable. Withdrawal does not affect processing that already happened. Ads consent is withdrawn or changed in Privacy settings and in the OS.

11. Your GDPR rights

You have the right to:

  1. Access (Art. 15)

  2. Rectification (Art. 16)

  3. Erasure (Art. 17)

  4. Restriction (Art. 18)

  5. Data portability (Art. 20): you can copy list content from the app; we can export server-side shared list data we hold if we can identify you

  6. Object to processing based on legitimate interests (Art. 21), including non-personalized ads funded by legitimate interest and security logs, on grounds relating to your particular situation

  7. Withdraw consent at any time (Art. 7(3)), without affecting processing that already happened

  8. Lodge a complaint with a supervisory authority

Austrian authority:
Österreichische Datenschutzbehörde
Barichgasse 40-42
1030 Vienna
Austria
https://www.dsb.gv.at
Email: dsb@dsb.gv.at

If you live in another EU/EEA country, you may also contact your local authority.

We do not use automated decision-making that produces legal or similarly significant effects (Art. 22 GDPR). Ads targeting and AI list suggestions are not that kind of decision.

12. Whether you must provide data

Installing tDo does not require you to give us your identity. Local use works without an account.

You must allow the processing described for sharing, joining, or AI if you want those features. You must allow Apple or Google to process purchase data if you subscribe. You can refuse advertising personalization; the free app may then show less relevant ads, or you can remove ads with Premium.

13. Children

tDo is a general-audience productivity app. It is not directed at children under 16 and is not in Apple’s Kids Category.

We do not knowingly collect personal data from children under 16 for advertising or cloud accounts. Austrian law sets 14 as the age for a child’s own consent to information society services (DSG § 4). Personalized advertising and third-country AI processing are not intended for children.

If you believe a child has provided data, contact office@xinger.org. We will delete what we can identify.

14. Security

We use HTTPS for API traffic, hashed PINs on the server (bcrypt), row-level access rules so only list members can read a shared list, rate limits, and a PIN lockout after repeated failures. The public API exposes only the paths the app needs.

No method is perfect. A code plus PIN is a shared secret: treat it like a house key. Send it only to people you trust, change the PIN if it leaks, and do not screenshot it in untrusted chats.

15. Third-party policies (links)

16. Changes

If we change this Privacy Policy in a material way (for example a new processor or a new cloud purpose), we will update this page, the document version, and the date above. For cloud features, the app may ask you to accept the new version before you share, join, or generate again.

17. Contact

Xinger Solutions GmbH
Seefeldgasse 5, 3462 Absdorf, Austria
office@xinger.org

Terms of Use: https://www.digitalworkplace.at/tos-tdo
Imprint: https://www.digitalworkplace.at/impressum

bottom of page