Privacy Policy
Last updated August 25, 2026
This Privacy Policy explains how TextTodo collects, uses, stores, and deletes information when you use its conversational task, reminder, and optional Google Calendar features through iMessage. TextTodo is currently available only through iMessage and does not support SMS.
Privacy at a glance
- TextTodo does not sell your personal information.
- TextTodo does not use your information to train AI models. Its configured Gemini and Codex services do not use your content to train general-purpose AI models.
- Messages are processed only to provide, maintain, support, secure, and improve the reliability of TextTodo.
- TextTodo's owner may occasionally review recent messages for support, troubleshooting, abuse prevention, and response-quality checks. This access is protected and logged.
- You can delete your TextTodo data by sending
/delete_my_data.
Information we process
- Messaging information: the phone number or email address you use for iMessage, incoming commands, TextTodo replies, timezone, and limited delivery information needed to send reliable responses.
- Task information: task titles, status, deadlines, private notes, recurring-task rules, reminders, referenced occurrence and lead times, and recurring message settings you explicitly choose. During timezone setup, time-dependent commands may be stored temporarily in an ordered queue; their request text is cleared immediately after successful replay or a reported terminal failure.
- Conversation context: the latest 20 conversation messages, used to understand follow-up requests such as “move that to Friday.” Older context is deleted as newer messages are saved.
- Google account connection: an opaque Google account identifier, an encrypted OAuth refresh token, and synchronization metadata. TextTodo does not store your Google password.
- Linked calendar-event information: event identifiers, titles, start and end times, status, and synchronization metadata only for events created through TextTodo or events for which you explicitly request a TextTodo reminder.
- Planning information: day-plan previews, selected tasks or user-supplied schedule-block titles, proposed or supplied block times, conflict markers, confirmation status, and resulting Google event identifiers.
- Reliability and website information: limited model-usage, latency, tool, error, delivery, and feature-usage information used to understand whether TextTodo works correctly. Website measurements may include the page, link placement, broad device class, and sanitized campaign label, but not message or task text, contact information, OAuth credentials, full URLs, or a persistent visitor identifier. Hidden model reasoning is not collected.
AI processing and model training
TextTodo uses Google’s Gemini API to understand requests and compose responses. Gemini may receive your current request, limited recent conversation context, and the task, reminder, timezone, or planning information needed to respond. Day-planning requests may include relevant task details, your constraints, and Calendar busy times, but not unrelated Calendar event titles.
TextTodo does not train AI models with your information. TextTodo uses the paid Gemini API, under which Google does not use prompts or responses to improve its models. Owner-initiated OpenAI Codex reviews use an account configuration where model training is disabled. Google and OpenAI may still process or retain limited information for safety, abuse prevention, legal compliance, and service operation under their applicable terms.
Limited owner access
TextTodo’s owner may occasionally review retained messages to answer support requests, diagnose failures, prevent abuse, and improve response reliability. The owner can also see the full iMessage identifier associated with an account, meaning the phone number or email address used to message TextTodo. Administrative access is authenticated, limited, and logged.
For a quality review, the owner may use OpenAI Codex through a read-only interface that replaces the iMessage identifier with an anonymous reference and excludes credentials, Google tokens, and hidden model reasoning. This interface does not create another TextTodo database archive, but the resulting review conversation follows OpenAI’s account and retention controls. A short-lived diagnostic snapshot may include one user's identifier and up to seven days of retained activity; it expires within one hour and can be retrieved only once.
How Google Calendar data is used
Google Calendar access is optional. When connected, TextTodo uses the Google Calendar API to show your requested agenda, calculate availability, preview a requested day plan around existing events, and create, update, or delete one-time events in your primary calendar. A day-plan preview changes Google Calendar only after you confirm it. TextTodo maintains an event text reminder only when you explicitly request one.
Agenda and availability information is fetched from Google when needed. TextTodo does not copy your entire calendar into its database. Calendar information is not used for advertising, profiling, or AI-model training, and is not manually reviewed except as permitted by the Google API Services User Data Policy.
Service providers
TextTodo relies on Google for Gemini and Google Calendar, OpenAI for owner-initiated Codex quality reviews, Supabase for database hosting, Vercel for application hosting and job delivery, Apple for iMessage, and BlueBubbles for the connection to Apple Messages. These providers process information only as needed for their described role and under their applicable terms. Your use of iMessage remains subject to Apple’s terms and privacy practices.
Data sharing and sale
TextTodo does not sell your personal information or Google user data. It does not share Google user data for advertising. Data is disclosed only to service providers needed to deliver the requested features, when you direct us to do so, or when required by law.
How TextTodo protects sensitive Google user data
TextTodo treats Google Calendar information and OAuth credentials as sensitive data and uses safeguards designed to protect them against unauthorized access, use, alteration, loss, or disclosure.
- Connections to TextTodo, Google, and the hosted database use HTTPS/TLS.
- The database is encrypted at rest, and Google refresh tokens receive additional AES-256-GCM encryption with a key kept separately from the database.
- Credentials and temporary Google access tokens are restricted to server-side processes and are not persistently exposed to users or application logs.
- Administrative access is password-protected, rate-limited, uses short-lived secure sessions, and is logged.
- TextTodo requests only the Google permissions needed for its Calendar features and deletes connection information when you disconnect or delete your account.
Retention
- Latest 20 conversation messages: until displaced by newer messages or you delete your account.
- Account, task, reminder, timezone, and preference information: while your account is active or until you delete it.
- Google connection and linked-event information: until you disconnect Google Calendar or delete your account.
- Message-delivery jobs, completed setup metadata, planning previews, and detailed reliability diagnostics: seven days. Queued setup-request text is cleared sooner after replay or a reported terminal failure.
- Diagnostic snapshots: up to one hour, or less if retrieved or revoked.
- Sanitized product measurements: 90 days.
- Expired administrator sessions: 30 days.
- Administrator authentication and access records without message bodies: one year.
Information may be retained longer only when reasonably necessary to comply with law, resolve a dispute, address security or abuse, or enforce an agreement.
Your choices and deletion
You may disconnect Google Calendar by messaging “Disconnect Google Calendar.” This revokes access when possible and deletes the stored Google connection, linked event metadata, and linked TextTodo calendar reminders.
You may send /delete_my_data to delete your TextTodo user record, tasks, reminders, conversation history, durable inbound message text, connected Google Calendar information, and user-linked product and diagnostic records. Only the minimal information needed to deliver the deletion acknowledgement remains until delivery is finalized. Security access records without message bodies may remain for their stated retention period. You may also revoke TextTodo directly from your Google Account permissions. Information retained independently by a service provider is controlled by that provider.
Google API Services User Data Policy
TextTodo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Children
TextTodo is not directed to children under 13, or under the minimum age required to manage a Google Account in their country. Users must be legally able to consent to these practices or use the service with authorization from a parent or guardian.
Changes
We may update this policy as the service changes. The current version and its effective date will remain available on this page.
Contact
Questions or deletion requests may be sent to trytexttodo@gmail.com.