Privacy Policy
This policy explains what personal data we process when you use the Todolix app for iPhone and iPad and the website todolix.app, why we do it, and what rights you have. In short: we only process what Todolix needs to work. There are no ads, no tracking and no analytics, and the AI features only run after you have switched them on.
1. Controller
The controller responsible for processing your data is:
73 Apps UG (haftungsbeschränkt)Bahnstr. 10
50996 Köln
Germany
Email: hello@todolix.app
Phone: +49 221 71598774
For any question about your data, write to us at the email address above.
2. This website
The website is hosted on Firebase Hosting, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you open a page, your browser sends technical data such as your IP address, the date and time, the page requested, the referring page and your browser type. This data is processed to deliver the page and to protect the service against misuse, and is kept only for a short time in the hosting provider’s logs. The legal basis is our legitimate interest in a secure and working website (Art. 6(1)(f) GDPR).
The website sets no cookies, uses no analytics or tracking tools, and loads no external fonts or scripts.
3. Account and sign-in
To sync your to-dos between devices you create an account. You can sign in with Apple, Google or email. For this we use Firebase Authentication by Google. We process:
- your email address (with Sign in with Apple, this can be an anonymous relay address from Apple),
- your name, if you or the sign-in provider share it,
- a user ID, the sign-in method and the dates of sign-up and last sign-in.
With email sign-in, your password is stored by Firebase Authentication only as a secure hash; we never see it. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR).
4. Syncing your data
When you are signed in, the content you create in Todolix is stored in Google Cloud Firestore so that it is the same on all your devices. This includes your to-dos with their notes, checklists, dates, deadlines and reminders, your areas, projects, lists and tags, the birthdays you keep in Todolix, and your app settings. The database is located in Frankfurt, Germany (region europe-west3). A few server functions (Cloud Functions, also in Frankfurt) handle the AI features and Email to Todolix described below.
The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). We do not look at your content, except where you ask us to for support, and we never sell it or use it for advertising.
5. Crash reports
If the app crashes, it sends a crash report through Firebase Crashlytics by Google so we can find and fix the problem. A crash report contains where in the code the crash happened, the device model, the iOS and app version, free memory and disk space, and a random installation ID. It contains no to-dos and none of your other content.
Crash reports are switched on by default. You can switch them off at any time in the app’s Settings. The legal basis is our legitimate interest in a stable app (Art. 6(1)(f) GDPR). Crash reports are deleted after 90 days.
6. AI features
Todolix has optional features that use an AI model from OpenAI:
- the assistant, which turns what you type or say into proposed to-dos,
- suggestions in Decide, which propose where an Inbox to-do might belong,
- improving emailed to-dos, which writes a title and short summary for mails sent to Todolix.
These features are off until you explicitly switch them on in the app. Only then, and only when you use the feature, is the text involved sent through our server in Frankfurt to OpenAI: your message to the assistant (dictation is turned into text on your device first; no audio is sent) or the title and notes of the to-dos being decided on, each together with the names of your areas and projects, today’s date and your time zone; or the sender, subject and text of the mail. OpenAI processes this data on our behalf to generate the answer. According to OpenAI’s terms for its API, the data is not used to train models and is kept for at most 30 days to detect abuse.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time by switching the feature off in Settings; this does not affect processing that took place before. The AI only makes proposals: nothing is added or changed until you confirm it.
7. Email to Todolix
If you use Email to Todolix, you get personal addresses to which you can send or forward mails, which then become to-dos. Incoming mails are received by Postmark, a service of ActiveCampaign, LLC (USA), and passed to our server, which creates the to-do from the sender, subject and text. Attachments are not kept. The mail is processed only to deliver this feature (Art. 6(1)(b) GDPR). The to-do is then stored like your other data. You can switch off or delete your addresses in the app at any time.
8. Data that stays on your device
- Reminders and notifications are scheduled locally on your device. No push service is used for them.
- Contacts: if you allow access, Todolix reads birthdays from your contacts on the device to show them. Nothing from your contacts is uploaded. Only birthdays you choose to keep in Todolix are stored, and they sync like your other data.
- Import from Reminders: if you allow access, Todolix reads your Apple Reminders on the device. Only the reminders you import become to-dos in Todolix.
- Location: for reminders at a place, iOS tells Todolix when you arrive at or leave that place. Your location is used on the device only and never sent to us.
- Dictation is turned into text on your device.
- Widgets and the share sheet exchange data with the app on your device only.
You can grant or withdraw each of these permissions at any time in the iOS Settings app.
9. Purchases
Purchases in Todolix are handled entirely by Apple through the App Store. We receive no payment data, only the information from Apple that a purchase is active. Apple’s privacy policy applies to the payment.
To know whether Premium is active on all your devices, we use RevenueCat (RevenueCat, Inc., USA). RevenueCat receives from the app and from Apple the purchase and subscription status, an anonymous or account ID, the device type, app version and country, never your to-dos. The legal basis is the performance of our contract with you (Art. 6(1)(b) GDPR). The transfer to the USA is based on the EU-US Data Privacy Framework or the EU standard contractual clauses.
10. Contacting us
If you email us, we process your message and your email address to answer you (Art. 6(1)(b) or (f) GDPR). We delete the conversation when it is no longer needed, unless we are required by law to keep it.
11. Service providers
We use the following processors. Each is bound by a data processing agreement under Art. 28 GDPR:
- Google Ireland Limited (Firebase Authentication, Cloud Firestore, Cloud Functions, Crashlytics, Hosting), Ireland, with Google LLC, USA, as sub-processor;
- OpenAI (AI features, only after your consent), USA;
- ActiveCampaign, LLC (Postmark, Email to Todolix), USA.
We do not pass your data to anyone else unless we are required to by law.
12. Transfers outside the EU
Google, OpenAI and Postmark may process data in the United States. Transfers are based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework, where the provider is certified under it, and in addition on the EU standard contractual clauses (Art. 46(2)(c) GDPR).
13. Retention and deletion
We keep your account and synced data for as long as you have an account. You can delete your account at any time in the app under Settings → Account → Delete Account. This deletes your account and all data synced with it from our servers. Data stored only on your device is removed when you delete the app. Crash reports are deleted after 90 days. Where the law requires us to keep certain records, we keep them for the period required.
14. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR),
- have incorrect data corrected (Art. 16 GDPR),
- have your data deleted (Art. 17 GDPR),
- restrict processing (Art. 18 GDPR),
- receive your data in a common, machine-readable format (Art. 20 GDPR),
- withdraw your consent at any time with effect for the future (Art. 7(3) GDPR),
- object to processing based on our legitimate interests, on grounds relating to your particular situation (Art. 21 GDPR).
To use these rights, write to hello@todolix.app.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)Kavalleriestraße 2–4
40213 Düsseldorf
Germany
www.ldi.nrw.de
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. You are not required to provide personal data, but without an account Todolix cannot sync your data.
15. Security
All connections between the app, the website and our servers are encrypted (TLS). Data is stored encrypted by our providers. Access to your data in the database is limited to your own account.
16. Changes
We will update this policy when Todolix or the law changes. The current version is always available on this page.