1. Who We Are
The personal information handler for ToDone is Gui Zou, an individual developer.
Privacy contact: it_quinna@163.com
Website: https://locklock.ltd
This Policy applies to the ToDone apps, accounts, cloud sync, and ToDone legal pages on locklock.ltd.
2. Information We Process
2.1 Local Tasks and Preferences
Tasks, notes, projects, areas, checklists, tags, reminders, recurring rules, ordering, completion and deletion events, app settings, and statistics you create are stored in a local database on your device. When you are signed out, this content is not uploaded to ToDone servers by default.
ToDone may create encrypted rolling backups on your device. The macOS widget stores a limited number of Today task titles and identifiers in the system App Group, and local notifications provide task titles and identifiers to the operating system for scheduling.
2.2 Account Information
When you create or sign in to an account, we process your email address, a system-generated user ID, nickname, and registration time. The current client uses email verification codes and does not require a ToDone password.
A verification code remains valid in server memory for no more than 10 minutes and is removed after successful verification. The email delivery provider processes the recipient address, subject, and verification-code message.
2.3 Cloud Sync Content
After you sign in and use cloud sync, tasks, notes, projects, areas, checklists, tags, reminders, recurring rules, ordering, completion and deletion states, and task-event times are sent to our servers for synchronization and recovery across devices.
To handle conflicts and incremental sync, we also process client update times, sync watermarks, change sequence numbers, deletion markers, and necessary entity relationships.
2.4 Device and Technical Information
To distinguish sync devices, protect accounts, and maintain the service, we process an app-specific device identifier, platform type, sync capabilities, last sync time, token expiration time, request IP address, request time, access path, response status, and request duration.
Where available, the app-specific device identifier is derived from a platform device identifier using a ToDone-specific SHA-256 process. Otherwise, ToDone generates a random installation identifier. We do not use this identifier for advertising tracking.
2.5 Support Communications
When you contact us by email, we process your email address, message, attachments, and subsequent correspondence to respond to your question, handle an account request, or resolve a dispute.
2.6 Processing We Do Not Currently Perform
The current ToDone client does not integrate advertising SDKs, targeted advertising, third-party user profiling, Firebase Analytics, Crashlytics, Sentry, or similar behavioral tracking services. We do not sell personal information.
The shared backend contains an intelligent bill-processing API that the ToDone client does not currently call. If ToDone later adds an AI feature that sends user content to a third-party model, we will update this Policy before enabling the feature and provide a separate, clear notice before content is sent.
3. Purposes of Processing
We process information only to the extent necessary to:
- provide local task management, reminders, statistics, and backup features;
- send sign-in codes, create accounts, and maintain authenticated sessions;
- provide cloud sync, conflict handling, cross-device recovery, and safe sync-data cleanup;
- prevent API abuse, unauthorized access, and other security risks;
- diagnose failures, maintain stability, and respond to support requests; and
- comply with applicable law and handle requests to exercise data rights.
4. Device Permissions
ToDone requests notification permission when you enable reminders or daily summaries. Notifications are scheduled locally by the operating system. The current implementation does not use APNs or FCM remote push tokens. You can turn off notification permission at any time in system settings.
The current core task-management features do not require access to contacts, precise location, the camera, the microphone, or advertising identifiers.
5. Storage Location and Service Providers
ToDone currently hosts its APIs and database on Tencent Cloud infrastructure located in mainland China and uses NetEase 163 Mail SMTP to send email verification codes. Service providers process information only as necessary to provide infrastructure, network, or email delivery services.
- Tencent Cloud Computing (Beijing) Co., Ltd.: processes server, database, network connection, and related operational data.
- NetEase 163 Mail: processes recipient addresses, subjects, and message bodies necessary to deliver verification-code emails.
- Apple, Microsoft, Google, and other platform providers: process platform data under their own policies when you download ToDone from their stores or use operating-system notifications, backups, or related features.
Nothing in this Policy authorizes these service providers to use ToDone business content for advertising profiles.
6. Security Measures
- The local business database is encrypted with SQLCipher. JWTs and database keys are stored in Keychain, Keystore, or equivalent platform secure storage.
- Public production environments use HTTPS/TLS to transmit account, verification-code, and sync data.
- The server uses JWT authentication, user-level data isolation, and transactional sync locks to restrict access between accounts.
- Authorization credentials in access logs are redacted by default at the edge, and operational access is limited on a need-to-use basis.
ToDone is not an end-to-end encrypted or zero-knowledge service. The server must process readable business fields and database keys to provide sync. No system can guarantee absolute security. If a security incident may affect users' rights and interests, we will take remedial and notification measures as required by applicable law.
7. Retention and Deletion
- Verification codes: remain valid for no more than 10 minutes and are deleted after successful use. Unused entries are cleared when overwritten, checked, or when the service restarts.
- Account and cloud sync data: retained while the account remains active and deleted from the online business database after successful account deletion.
- Sync devices and task events: retained with the account for multi-device sync, statistics, and safe cleanup, and deleted when the account is deleted.
- Soft-deleted content: retains a deletion state so that deletion can sync to other devices. Related cloud records may remain until system cleanup or account deletion.
- Local Trash: permanently deleted from the active database after 30 days by default. You may change the retention period in settings.
- Local rolling backups: ToDone keeps up to 14 recent copies on the device and removes older copies on a rolling basis. Account deletion, uninstalling, or a web deletion request cannot guarantee deletion of copies you made, system backups, or copies on other devices.
- Access logs: normally retained on a rolling basis for no more than 30 days. They may be retained longer where necessary to investigate a security incident or meet a legal obligation.
- Server disaster-recovery backups: retained on a rolling basis for no more than 30 days, used only for disaster recovery, and not used to restore a deleted account to ordinary service.
- Support email: normally retained for no more than 12 months after an issue is closed, unless a longer period is necessary for a legal obligation or dispute.
8. Disclosure, Transfer, and Public Release
Except for the service providers identified in this Policy, your authorization, completion of a feature you request, or an express legal requirement, we do not provide personal information to other parties.
Where necessary to respond to a lawful request from a court or government authority, or to protect users and the public, we disclose information only within the lawful and necessary scope. If a merger, transfer, or change of operator occurs, we will identify the recipient and require it to remain bound by this Policy and applicable law.
9. Your Rights
Subject to applicable law, you may request access to, a copy of, correction, supplementation, or deletion of personal information; withdraw an authorization; restrict processing; delete your account; or request an explanation of our practices and submit a complaint.
- Use the app to update your nickname, manage notification permission, sign out, or delete your account.
- See the Account Deletion page for an off-app request method.
- Email it_quinna@163.com for other requests.
To protect your account, we may verify your control of the registered email address or account, but we will not ask for your email password or ToDone verification code. We normally respond within 15 business days.
10. Children
ToDone does not intentionally offer account services to children under 14 and does not collect age information for the purpose of identifying children. If we learn that we processed a child's personal information without appropriate parental or guardian consent, we will delete it or take other necessary measures. A parent or guardian may contact us through the privacy email address.
11. Legal Pages, Cookies, and Third-Party Links
ToDone legal pages on locklock.ltd do not use third-party analytics scripts, advertising, third-party fonts, or cookies. A page may link to an email client, app store, or service-provider website. Third-party pages are governed by their own privacy policies.
12. Changes to This Policy
We display the latest version and effective date on this page. We will notify you of material changes through the app, website, or registered email address. If the purposes, methods, or categories of personal information processing materially change, we will provide a new notice and obtain consent where required by applicable law.
13. Contact Us
Personal information handler: Gui Zou, individual developer
Location: Shenzhen, Guangdong, China
Privacy contact: it_quinna@163.com
Website: https://locklock.ltd