Privacy Policy
Last updated September 18, 2026
This Privacy Policy explains how TextTodo collects, uses, stores, and deletes information when you use its conversational task, reminder, and optional Google Calendar features through iMessage. TextTodo is currently available only through iMessage and does not support SMS.
Privacy at a glance
- TextTodo does not sell your personal information.
- TextTodo does not use your information to train AI models. Its configured Gemini and Codex services do not use your content to train general-purpose AI models.
- Messages are processed only to provide, maintain, support, secure, and improve the reliability of TextTodo.
- TextTodo's owner may occasionally review recent messages for support, troubleshooting, abuse prevention, and response-quality checks. This access is protected and logged.
- You can delete your TextTodo data by sending
/delete_my_data.
Information we process
- Messaging information: the phone number or email address you use for iMessage, incoming commands and supported interactions, TextTodo replies, reply-to associations, timezone, and limited delivery information such as a provider message identifier, send method, delivery status, timestamps, and bounded error category needed to send reliable responses and understand a reply or Like.
- Task information: task titles, active, completed, or removed status, completion or removal time, deadlines, private notes, recurring-task rules, reminders, referenced occurrence and lead times, recurring message settings you explicitly choose, and limited markers recording which in-product help tips have already been shown. Removing a task hides it from active lists but retains it as removed until you delete your account. TextTodo uses Central Time until you provide a timezone. Legacy saved setup requests are cleared immediately after a reviewed repair, successful replay, or reported terminal failure.
- Conversation context: the latest 20 conversation messages, used to understand follow-up requests such as “move that to Friday.” Reminder creation and content-change times also help interpret corrections. Bot text enters this context after delivery is confirmed; successfully dispatched reactions are represented as reactions. Older context is deleted as newer messages are saved. A reset timestamp prevents delayed delivery updates from restoring cleared context.
- Google account connection: an opaque Google account identifier, an encrypted OAuth refresh token, and synchronization metadata. TextTodo does not store your Google password.
- Linked calendar-event information: event identifiers, titles, start and end times, status, and synchronization metadata only for events created through TextTodo or events for which you explicitly request a TextTodo reminder.
- Planning information: day-plan previews, selected tasks or user-supplied schedule-block titles, proposed or supplied block times, conflict markers, confirmation status, and resulting Google event identifiers.
- Reliability and website information: limited model-usage, latency, tool, error, delivery, and feature-usage information used to understand whether TextTodo works correctly. TextTodo also keeps anonymous daily totals of task and reminder creations; those totals contain no user identifier, contact information, task or reminder text, or message content. Website measurements may include the page, link placement, broad device class, and sanitized campaign label, but not message or task text, contact information, OAuth credentials, full URLs, or a persistent visitor identifier. Hidden model reasoning is not collected.
AI processing and model training
TextTodo uses Google’s Gemini API to understand requests and compose responses. Gemini may receive your current request, limited recent conversation context, and the task, reminder, timezone, or planning information needed to respond. Day-planning requests may include relevant task details, your constraints, and Calendar busy times, but not unrelated Calendar event titles.
TextTodo does not train AI models with your information. TextTodo uses the paid Gemini API, under which Google does not use prompts or responses to improve its models. Owner-initiated OpenAI Codex reviews use an account configuration where model training is disabled. Google and OpenAI may still process or retain limited information for safety, abuse prevention, legal compliance, and service operation under their applicable terms.
Limited owner access
TextTodo’s owner may occasionally review retained messages to answer support requests, diagnose failures, prevent abuse, and improve response reliability. The owner can also see the full iMessage identifier associated with an account, meaning the phone number or email address used to message TextTodo. Administrative access is authenticated, limited, and logged.
For a quality review, the owner may use OpenAI Codex through a read-only interface that replaces the iMessage identifier with an anonymous reference and excludes credentials, Google tokens, and hidden model reasoning. This interface does not create another TextTodo database archive, but the resulting review conversation follows OpenAI’s account and retention controls. A short-lived diagnostic snapshot may include one user's identifier and up to seven days of retained activity; it expires within one hour and can be retrieved only once.
How Google Calendar data is used
Google Calendar access is optional. When connected, TextTodo uses the Google Calendar API to show your requested agenda, calculate availability, preview a requested day plan around existing events, and create, update, or delete one-time events in your primary calendar. A day-plan preview changes Google Calendar only after you confirm it. TextTodo maintains an event text reminder only when you explicitly request one.
Agenda and availability information is fetched from Google when needed. TextTodo does not copy your entire calendar into its database. Calendar information is not used for advertising, profiling, or AI-model training, and is not manually reviewed except as permitted by the Google API Services User Data Policy.
Service providers
TextTodo relies on Google for Gemini and Google Calendar, OpenAI for owner-initiated Codex quality reviews, Supabase for database hosting, Vercel for application hosting and job delivery, Apple for iMessage, and BlueBubbles for the connection to Apple Messages. These providers process information only as needed for their described role and under their applicable terms. Your use of iMessage remains subject to Apple’s terms and privacy practices.
Data sharing and sale
TextTodo does not sell your personal information or Google user data. It does not share Google user data for advertising. Data is disclosed only to service providers needed to deliver the requested features, when you direct us to do so, or when required by law.
How TextTodo protects sensitive Google user data
TextTodo treats Google Calendar information and OAuth credentials as sensitive data and uses safeguards designed to protect them against unauthorized access, use, alteration, loss, or disclosure.
- Connections to TextTodo, Google, and the hosted database use HTTPS/TLS.
- The database is encrypted at rest, and Google refresh tokens receive additional AES-256-GCM encryption with a key kept separately from the database.
- Credentials and temporary Google access tokens are restricted to server-side processes and are not persistently exposed to users or application logs.
- Administrative access is password-protected, rate-limited, uses short-lived secure sessions, and is logged.
- TextTodo requests only the Google permissions needed for its Calendar features and deletes connection information when you disconnect or delete your account.
Retention
- Latest 20 conversation messages: until displaced by newer messages or you delete your account.
- Outbound reply references: TextTodo message text for seven days; the minimal user, chat, message identifier, reference type, and linked task identifiers for 30 days so replies and Likes can be resolved.
- Account, task, reminder, timezone, and preference information: while your account is active or until you delete it.
- Google connection and linked-event information: until you disconnect Google Calendar or delete your account.
- Message-delivery jobs, provider delivery status and identifiers, completed setup metadata, planning previews, and detailed reliability diagnostics: seven days. Queued setup-request text is cleared sooner after replay or a reported terminal failure.
- Diagnostic snapshots: up to one hour, or less if retrieved or revoked.
- Sanitized product measurements: 90 days.
- Anonymous daily task/reminder creation and reminder-send totals: retained as cumulative aggregate measurements. They contain no user identifier or content and cannot be linked back to an account.
- Expired administrator sessions: 30 days.
- Administrator authentication and access records without message bodies: one year.
Information may be retained longer only when reasonably necessary to comply with law, resolve a dispute, address security or abuse, or enforce an agreement.
Your choices and deletion
You may disconnect Google Calendar by messaging “Disconnect Google Calendar.” This revokes access when possible and deletes the stored Google connection, linked event metadata, and linked TextTodo calendar reminders.
You may send /delete_my_data to delete your TextTodo user record, tasks, reminders, conversation history, durable inbound message text, connected Google Calendar information, and user-linked product and diagnostic records. Only the minimal information needed to deliver the deletion acknowledgement remains until delivery is finalized. Anonymous daily creation and reminder-send totals cannot be linked back to an account and remain as aggregate measurements. Security access records without message bodies may remain for their stated retention period. You may also revoke TextTodo directly from your Google Account permissions. Information retained independently by a service provider is controlled by that provider.
Google API Services User Data Policy
TextTodo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Children
TextTodo is not directed to children under 13, or under the minimum age required to manage a Google Account in their country. Users must be legally able to consent to these practices or use the service with authorization from a parent or guardian.
Changes
We may update this policy as the service changes. The current version and its effective date will remain available on this page.
Contact
Questions or deletion requests may be sent to trytexttodo@gmail.com.