Privacy Policy
Last updated 2026-09-05. This describes TodoZen's current behavior, including its web app, API, MCP endpoint, PWA and browser extension.
TodoZen is a product of Aperca LLC, which operates the service and is responsible for the data practices described here.
What we store
TodoZen stores account details (name, email, password hash and sessions); personal and shared workspaces and their memberships; tasks, goals, tags, journal entries, habits and check-offs; sharing grants and recipient email addresses; preferences, notifications and delivery state; push subscriptions; and security metadata for API keys, idempotent requests and private calendar feeds.
Plaintext passwords, API keys and calendar-feed tokens are not stored. Passwords are hashed, and tokens are shown once or returned to the requesting client while only a digest is retained.
Location suggestions
When you enter a task location with location suggestions enabled, the text you type is sent to the open Photon geocoding service to display address and place suggestions. TodoZen does not access, request, or track your device's GPS coordinates or background location.
How we use it
We use this information to authenticate you, operate and secure the service, synchronize the clients you connect, deliver the features you request, send enabled notifications, diagnose failures and enforce rate limits. TodoZen has no ads and does not sell personal data.
Collaboration and sharing
Content is private by default. Other people can see it only when you deliberately add them to a shared workspace or grant a specific task, journal entry or habit to an email address. Shared workspaces contain tasks, goals and habits but no journal. A record grant is read-only, does not move the record from its workspace and can be revoked.
A grant may be addressed to someone who does not yet have a TodoZen account. We store the normalized recipient address, send the same notice either way and let the grant wait until that address signs in. The create response never tells the sender whether an account already exists for that mailbox.
Connected clients and credentials
The REST API and MCP endpoint use revocable API keys. Every key issued by the current service can read and write TodoZen data, so treat it like a password, set an expiry when appropriate and revoke it when a client no longer needs access. API and MCP clients receive only the data allowed by the authenticated account and selected workspace.
The browser extension stores the key and server origin in the current Chrome profile's local extension storage and sends the key only to the configured TodoZen server over HTTPS. Its toolbar popup retrieves Today tasks (and optional habits when enabled); the side panel retrieves planning and journal data only when you open those surfaces. Theme settings synchronize with the account. It does not receive your password or browser session, inspect browsing history, automatically read pages, run ads, or send extension analytics. If you explicitly choose “Add selection to TodoZen,” Chrome passes the selected text to the extension and it is sent to TodoZen as the task you asked to create; no other page content is read.
TodoZen's use of information received through the extension follows the Chrome Web Store User Data Policy, including its Limited Use requirements. Extension data is used only to provide and secure requested features, except when disclosure is required for security or law or you explicitly ask for support.
Email and push notifications
Resend processes the address and message needed for password resets, workspace invitations, sharing notices and any email notifications you enable. Marketing email is not sent. In-app notifications are enabled by default; email and web push are opt-in. A browser push service receives the device endpoint and an encrypted payload needed to deliver a push notification.
Profile pictures
When object storage is configured and you choose a profile picture, the browser crops and re-encodes it to a WebP image before uploading it directly to Cloudflare R2 through a short-lived URL limited to that object and size. TodoZen stores the resulting asset URL. The previous image is removed when you replace or clear it, and account deletion attempts to remove the current object.
Analytics and error monitoring
Product analytics require consent and contain only closed, structural events — for example that a task was created and whether it had a due date, never its title, notes or journal content. TodoZen works fully if you decline. Sentry is used for error monitoring when configured; known credentials and content fields are scrubbed before a report leaves the process.
Infrastructure and service providers
The application, database and operational logs run on Railway. Cloudflare R2 stores profile pictures when configured. Resend sends email, Sentry receives scrubbed error reports when configured, Photon provides public geocoding for task location suggestions, and the browser's push service delivers encrypted push messages. TodoZen does not use an external AI provider for tasks, journal entries or tags. These providers receive only the information needed for their part of the service.
Retention, export and deletion
Soft-deleted tasks remain recoverable for 30 days and then become eligible for an opportunistic hard-delete sweep. Notifications are retained for 90 days. Other live content remains until you delete it or the account. Revoked API-key and sharing rows may be retained as security and audit history while the account exists.
Export downloads the portable content of the active workspace: preferences, tags, tasks, goals, journal entries, habits and your habit check-offs. It intentionally excludes credentials, sessions, memberships, sharing grants, notifications, workspace identifiers and task assignees.
Account deletion immediately removes the account's database rows, memberships, credentials, notifications and workspaces it owns, including the content in those workspaces, and attempts to remove its profile-picture object. Workspaces owned by someone else remain. Copies may persist temporarily in provider backups until those backups expire under their disaster-recovery schedule; they are not used to restore an individually deleted account.
Browser storage and offline caching
TodoZen uses cookies for sessions, theme choices and analytics consent, and local storage for items such as an unsaved journal draft, the active workspace, activation-coach state and dismissed prompts. A service worker caches public shell assets and the offline fallback screen in the browser cache storage so you see a clear, actionable offline screen instead of a blank browser error. Private workspace data, tasks and personal journals are never stored in the service worker cache. Clearing browser or extension storage removes those local copies but does not delete server data.
Contact
Questions, support requests and privacy requests can be emailed to support@apercallc.com. Do not include passwords, API keys or private content that is not necessary to resolve your request.