Privacy Policy

Last updated: 16 July 2026

This policy says what ToDoing stores, where it lives, who can see it, and what your rights are. Short version: your plan data belongs to your team, it's hosted in the EU, we run no advertising trackers, and the third parties that ever see task text are Anthropic, to generate the AI features on paid plans, and Resend, which delivers the weekly digest email those features produce.

1. What we store

2. Where it lives

All workspace data is stored with Supabase (Postgres) in the EU (London, eu-west-2). Workspaces are isolated from each other at the database level (row-level security per organisation). The app is served via Vercel. Transactional email (invitations, leave notifications, the weekly digest) is delivered by Resend. We may use Sentry for error monitoring; when enabled it receives technical crash reports (stack traces, the page address, your user id and workspace name) so we can fix bugs, but never your task content. We take reasonable technical measures to protect your data, but no online service is completely secure, and we cannot guarantee absolute security.

3. AI features, the important disclosure

On the Enterprise plan (and during trials), five features send workspace text to Anthropic's Claude API to be processed:

This happens server-side, only to generate the output you asked for. Per Anthropic's commercial API terms, this data is not used to train their models. Free and Pro workspaces never have data sent to Anthropic.

The weekly digest is emailed. Its text is sent through Resend, our email provider, to the addresses an admin of your workspace enters in Settings. Those addresses are not checked against your membership, so an admin can send the digest to someone outside the workspace. If that matters to you, check the recipient list in Settings.

4. What we don't do

5. Cookies and analytics

Two cookies are what the product itself needs: an authentication session (Supabase Auth) and a preference for light or dark mode.

Beyond those, Google Analytics 4 runs on todoing.co and in the app, and it sets its own cookies (_ga and similar) which persist for up to two years. We use it to count visits and see which pages people arrive on. It records the page address, which can contain your workspace name, along with the usual technical details a browser sends. It does not receive your task content, and we do not run advertising or remarketing trackers.

6. Your rights (GDPR)

You can ask us to export or delete your personal data, correct it, or object to processing; email support@todoing.co and we'll act within 30 days. Workspace content is controlled by your workspace owner; deletion requests for team data go through them. The data controller is ToDoing (contact above). You may also complain to your local data-protection authority.

7. Retention and deletion

Workspace data is kept while the workspace exists. When a workspace is deleted, its content is removed from the live database immediately and from backups on their rotation schedule.

8. Changes

If this policy changes materially, workspace owners get notified by email or in-app before the change takes effect.

← Back to todoing.co