Privacy Policy

Last updated August 25, 2026

This Privacy Policy explains how TextTodo collects, uses, stores, and deletes information when you use its conversational task, reminder, and optional Google Calendar features through iMessage. TextTodo is currently available only through iMessage and does not support SMS.

Privacy at a glance

Information we process

AI processing and model training

TextTodo uses Google’s Gemini API to understand requests and compose responses. Gemini may receive your current request, limited recent conversation context, and the task, reminder, timezone, or planning information needed to respond. Day-planning requests may include relevant task details, your constraints, and Calendar busy times, but not unrelated Calendar event titles.

TextTodo does not train AI models with your information. TextTodo uses the paid Gemini API, under which Google does not use prompts or responses to improve its models. Owner-initiated OpenAI Codex reviews use an account configuration where model training is disabled. Google and OpenAI may still process or retain limited information for safety, abuse prevention, legal compliance, and service operation under their applicable terms.

Limited owner access

TextTodo’s owner may occasionally review retained messages to answer support requests, diagnose failures, prevent abuse, and improve response reliability. The owner can also see the full iMessage identifier associated with an account, meaning the phone number or email address used to message TextTodo. Administrative access is authenticated, limited, and logged.

For a quality review, the owner may use OpenAI Codex through a read-only interface that replaces the iMessage identifier with an anonymous reference and excludes credentials, Google tokens, and hidden model reasoning. This interface does not create another TextTodo database archive, but the resulting review conversation follows OpenAI’s account and retention controls. A short-lived diagnostic snapshot may include one user's identifier and up to seven days of retained activity; it expires within one hour and can be retrieved only once.

How Google Calendar data is used

Google Calendar access is optional. When connected, TextTodo uses the Google Calendar API to show your requested agenda, calculate availability, preview a requested day plan around existing events, and create, update, or delete one-time events in your primary calendar. A day-plan preview changes Google Calendar only after you confirm it. TextTodo maintains an event text reminder only when you explicitly request one.

Agenda and availability information is fetched from Google when needed. TextTodo does not copy your entire calendar into its database. Calendar information is not used for advertising, profiling, or AI-model training, and is not manually reviewed except as permitted by the Google API Services User Data Policy.

Service providers

TextTodo relies on Google for Gemini and Google Calendar, OpenAI for owner-initiated Codex quality reviews, Supabase for database hosting, Vercel for application hosting and job delivery, Apple for iMessage, and BlueBubbles for the connection to Apple Messages. These providers process information only as needed for their described role and under their applicable terms. Your use of iMessage remains subject to Apple’s terms and privacy practices.

Data sharing and sale

TextTodo does not sell your personal information or Google user data. It does not share Google user data for advertising. Data is disclosed only to service providers needed to deliver the requested features, when you direct us to do so, or when required by law.

How TextTodo protects sensitive Google user data

TextTodo treats Google Calendar information and OAuth credentials as sensitive data and uses safeguards designed to protect them against unauthorized access, use, alteration, loss, or disclosure.

Retention

Information may be retained longer only when reasonably necessary to comply with law, resolve a dispute, address security or abuse, or enforce an agreement.

Your choices and deletion

You may disconnect Google Calendar by messaging “Disconnect Google Calendar.” This revokes access when possible and deletes the stored Google connection, linked event metadata, and linked TextTodo calendar reminders.

You may send /delete_my_data to delete your TextTodo user record, tasks, reminders, conversation history, durable inbound message text, connected Google Calendar information, and user-linked product and diagnostic records. Only the minimal information needed to deliver the deletion acknowledgement remains until delivery is finalized. Security access records without message bodies may remain for their stated retention period. You may also revoke TextTodo directly from your Google Account permissions. Information retained independently by a service provider is controlled by that provider.

Google API Services User Data Policy

TextTodo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Children

TextTodo is not directed to children under 13, or under the minimum age required to manage a Google Account in their country. Users must be legally able to consent to these practices or use the service with authorization from a parent or guardian.

Changes

We may update this policy as the service changes. The current version and its effective date will remain available on this page.

Contact

Questions or deletion requests may be sent to trytexttodo@gmail.com.