Privacy Policy

Effective date: May 10, 2026 · Last updated: July 16, 2026

TellDone (“we,” “our,” “us”) is a voice-first planning application operated by Evgheni Taracanov, a private individual. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our mobile applications (iOS, watchOS), our web application at app.telldone.app, and cloud services (collectively, the “Service”).

By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.

1. Data We Collect

1.1 Account data

1.2 Audio recordings

1.3 Generated content

1.4 Device data

1.5 Usage and diagnostic data

1.6 Integration data

If you connect Todoist, Notion, or Microsoft To Do, the authorization happens on our servers and we store, encrypted at the application layer:

You can disconnect any integration at any time in Settings → Integrations. On disconnect, we revoke the relevant OAuth token with the third party (where the third party exposes a revocation endpoint), delete the stored token from our database, and stop syncing. External items previously created from TellDone are not automatically deleted from the third-party service; you can delete them in that service if you wish.

1.7 Billing data

2. How We Use Your Data

The legal bases below are stated for the GDPR/UK GDPR; equivalent analysis applies under California, Swiss, and other comparable regimes.

PurposeData usedLegal basis
Provide the ServiceAudio, account, contentContract performance, Art. 6(1)(b)
Generate productivity reportsNotes, tasks, eventsContract performance
Send email reportsEmail, notes, tasksConsent (opt-out via settings)
Multi-device syncAll content, device IDContract performance
Third-party integrations (Todoist, Notion, Google Tasks, Apple Calendar, Apple Reminders, Things 3, Microsoft To Do, Apple Notes, Apple Journal)Items you sync; OAuth tokens only for the integrations we hold on our serversConsent (user-initiated connection per integration)
Sign in with Apple / GoogleApple/Google sub claim, name, emailContract performance (account creation and authentication)
Quota enforcement and billingUsage countsContract performance
Security and fraud preventionLogin attempts, device dataLegitimate interest, Art. 6(1)(f)
Service improvement, debuggingAnonymized error logsLegitimate interest

We do not:

3. Third-Party Data Processors

We use the following third-party services to provide core functionality. Your data is processed under data processing agreements (DPAs) with each provider where the provider is acting as a processor on our behalf, and under the provider's own terms where the provider is an independent identity provider:

ServiceRolePurposeData sharedLocation
netcup GmbHProcessorHosting of the application, database, and object storageAll account data, audio recordings, transcripts, and generated contentGermany
Hetzner Online GmbHProcessorEncrypted off-site backupsEncrypted copies of the database and audio recordingsGermany
SonioxProcessorSpeech-to-text transcriptionAudio recordingsUSA or EU, depending on where your account is registered
OpenAIProcessorAI analysis, note structuring, embeddings, report generationTranscripts, task and report contextUSA or EU
Fireworks AIProcessorAI analysis and note structuringTranscripts, task and report contextUSA or EU
Mistral AIProcessorAI analysis and note structuringTranscripts, task and report contextUSA or EU
ResendProcessorTransactional email deliveryEmail address, report contentUSA
Paddle.com Market LtdMerchant of Record / processorWeb subscription billing, payment processing, invoicing, refundsBilling name and contact details, transaction data (not full card number)UK / EU
Apple Inc.Independent controllerSign in with Apple identity provider; private email relaySign in with Apple identifier, name (if shared), relay email (if Hide My Email)USA
Google LLCIndependent controllerSign in with Google identity providerGoogle sub claim, name, emailUSA
Google LLCIndependent controllerGoogle Tasks sync (when you connect it)Task content you create in TellDoneUSA
Notion Labs, Inc.Independent controllerNotion sync (when you connect Notion via OAuth)Page/database content for items you syncUSA
Doist S.L. (Todoist)Independent controllerTodoist sync (when you connect Todoist via OAuth)Task content for items you syncEU
Cultured Code GmbH (Things)Independent controllerThings sync (when you connect Things)Task content for items you syncDE
Microsoft CorporationIndependent controllerMicrosoft To Do task sync (when you connect it)Task content for items you syncUSA

All third-party processors are contractually bound to process your data only as instructed by us and to maintain appropriate security measures. None of these providers use your data to train their AI models. The Apple, Google, Notion, Doist, Cultured Code, and Microsoft services listed as “independent controllers” process your data under their own privacy policies once it is in their systems; we recommend you review:

If you connect an external AI client through the User MCP endpoint (see Terms of Service Section 23), that client is not our processor. It acts on your instruction and under credentials you issued: we transmit only the responses to the specific tool calls it makes, and what the client's vendor does with those responses is governed by that vendor's own privacy policy. We never send your account contents to such a client in bulk, and we never share them with the vendor for any purpose beyond completing your request. You can revoke a client's access at any time in Settings → Integrations → AI Agents.

4. International Data Transfers

Our servers are located in Europe (Germany), within the European Economic Area. As the data controller is established in Romania (EU member state), transfers within the EEA do not require a separate transfer mechanism. Some third-party processors and identity providers (Section 3) are located in the United States. Speech-to-text runs in the United States or in the EU depending on where your account is registered; language processing currently runs in the United States or the EU and does not yet follow your registration. For these transfers, we rely on:

You can request a copy of the safeguards we rely on for a specific transfer (such as the relevant Standard Contractual Clauses) by emailing support@telldone.app.

5. Data Retention

Data typeRetention period
Account dataUntil account deletion
Audio recordingsUntil you delete them or your account
Notes, tasks, eventsUntil you delete them or your account
Soft-deleted items (trash)Free: 7 days · Basic: 30 days · Pro: 90 days · Ultra: 365 days
ReportsUntil account deletion
OAuth integration tokens we hold (Todoist, Notion, Microsoft To Do)Until you disconnect the integration or delete your account; revoked with the provider on disconnect where technically possible. Google Tasks and Things 3 authorize on your device and we never receive those tokens; Apple Calendar and Apple Reminders use an iOS permission and involve no token at all
Sign in with Apple/Google identifiersUntil account deletion; on deletion we additionally attempt to revoke the Apple refresh token via Apple's REST endpoint, and deletion proceeds regardless of the outcome
API usage logs12 months, then anonymized
Error logs30 days
Backups (encrypted)Rotated continuously; a deleted account's data can persist in a monthly backup snapshot for up to 6 months
Data exports (GDPR / CCPA)48 hours after generation, then deleted

Once you confirm deletion, the request is scheduled to execute after a 7-day grace period. You can cancel the pending deletion at any time before the grace period expires. After the grace period, all personal data is permanently removed, including: database records (cascade delete), audio files from object storage, OAuth tokens (revoked with the third party where possible), Apple refresh tokens (revoked via Apple's REST API), GDPR/CCPA exports, and Redis quota counters. No human review is required.

6. Data Security

7. Your Rights

7.1 Under GDPR / UK GDPR (European Users)

If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights:

7.2 Under CCPA / CPRA (California Residents)

If you are a California resident, you have the right to:

Categories of personal information collected (per CCPA/CPRA): identifiers (email, Apple/Google sub claim, device UUID); audio and electronic information (voice recordings); internet activity (usage logs); sensitive personal information (audio recordings, where they may contain sensitive content the user chooses to record).

7.3 How to exercise your rights

8. Cookies and Tracking

Our website (telldone.app). Google Analytics 4 for basic visit statistics, loaded only after you accept the cookie notice. We do not use advertising cookies, tracking pixels, or cross-site trackers. Fonts and other assets are served from our own servers — the pages do not contact third-party content delivery networks.

The web app (app.telldone.app). Sends no usage analytics at all. It sends technical error reports — a failed recording, a failed upload, a dropped connection. You can turn these off in Settings → Data and privacy; the setting applies to that browser and does not carry over to other browsers or devices.

The iPhone and Apple Watch apps. They contain no advertising SDKs, third-party analytics SDKs, or tracking SDKs, and no App Tracking Transparency prompt is shown because we do not track you in that sense. The apps send two separate streams:

9. Children's Privacy

The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from anyone under 16. In the United States, the Service is not directed to children under 13 within the meaning of the Children's Online Privacy Protection Act (“COPPA”), and we do not knowingly collect personal information from children under 13. If we discover that we have collected data from a child under the applicable minimum age, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at support@telldone.app and we will act without undue delay.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes (changes that materially affect the way we collect or use your data, including any change in how we use Google API user data or Sign in with Apple data), we will:

If you disagree with the changes you may close your account before the effective date and we will not enforce the changed policy against you.

11. Google API Services (Limited Use)

TellDone's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

https://developers.google.com/terms/api-services-user-data-policy

What this means in practice:

You can revoke our access to your Google account at any time at https://myaccount.google.com/permissions, in addition to disconnecting in TellDone Settings → Integrations.

11A. Microsoft To Do Integration (Microsoft Graph)

If you connect Microsoft To Do, TellDone offers an optional, strictly user-initiated two-way sync of your tasks between TellDone and your Microsoft To Do account. This integration is available on the Basic plan and above (Basic includes one integration slot; Pro and above include unlimited integrations) and is connected only after you complete Microsoft's OAuth consent flow. TellDone is an independent application that works with Microsoft To Do; we are not affiliated with, sponsored by, or endorsed by Microsoft.

Authorization uses the Microsoft identity platform (OAuth 2.0, authority login.microsoftonline.com/common) and supports both personal Microsoft accounts and work or school accounts. We request delegated permissions only (permissions that act on your behalf; we never request application-only or administrator access):

We do not use administrator (“admin consent”) permissions; each user consents individually for their own account. When the integration is active, we create a dedicated task list named “TellDone” in your Microsoft To Do and write the title, description, deadline, and completion status of your TellDone tasks into that list. We poll that same “TellDone” list (using a delta query, roughly every five minutes) for completion and deletion changes and reflect them back in TellDone. We interact only with the “TellDone” list we create; we do not read your other Microsoft To Do lists. We never use data obtained from Microsoft to develop, improve, or train AI or machine-learning models, and we do not use it for advertising.

Your Microsoft OAuth access and refresh tokens are stored in our database encrypted at rest (Fernet symmetric encryption), and refresh-token rotation is persisted so the connection stays valid. Our production servers are located in the European Union (Germany).

You can disconnect Microsoft To Do at any time in TellDone Settings → Integrations. Disconnecting immediately deletes the stored tokens from our servers and stops the sync. Disconnecting in TellDone does not, by itself, revoke TellDone's authorization on Microsoft's side; to remove that grant as well, revoke TellDone's access in your Microsoft account settings at https://account.live.com/consent/Manage. Tasks previously written to the “TellDone” list are not automatically deleted from your Microsoft To Do when you disconnect; you can delete them in Microsoft To Do if you wish.

Our use of Microsoft APIs is subject to the Microsoft APIs Terms of Use; once your data is in Microsoft's systems, it is governed by the Microsoft Services Agreement and the Microsoft Privacy Statement, available at https://privacy.microsoft.com/privacystatement.

12. Sign in with Apple

When you use Sign in with Apple, we receive only the data Apple provides:

We use this data only to create and authenticate your TellDone account and (for the email address) to send you transactional emails such as report digests, password resets, and security notices. We do not attempt to deanonymize the relay address, do not send marketing email to relay addresses, and respect your choice to disable email forwarding from your Apple ID settings.

When you delete your TellDone account, we call Apple's Sign in with Apple REST revocation endpoint to invalidate the refresh token issued to us, in addition to deleting your account data on our side. You can also revoke Apple's authorization at any time in iOS Settings → [your name] → Sign in with Apple, or at https://appleid.apple.com.

13. Notion and Todoist Integrations

When you connect Notion via OAuth, you are taken to Notion's authorization screen where you select which workspace and which specific pages or databases TellDone may access. We can only see the resources you grant; we cannot read other content in your workspace. We use this access only to create, read, update, and delete items that correspond to your TellDone notes, tasks, or events. We never use your Notion content to train any AI model and never share it with any party other than the data processors listed in Section 3 strictly to provide the sync feature.

When you connect Todoist via OAuth, we request exactly two scopes: data:read_write and data:delete. We use this access solely to create, read, update, complete, and (if you opt in) delete tasks that correspond to your TellDone tasks. We do not use your Todoist content to train any AI model and do not share it beyond the data processors in Section 3.

You can disconnect either integration at any time in TellDone Settings → Integrations; we will revoke the OAuth token with the provider on disconnect. You can also revoke the integration directly:

14. Data Controller and Contact

The data controller for personal data processed under this Privacy Policy is Evgheni Taracanov, a private individual, operating as TellDone, contactable at:

Address: Mun. București, Sec. 3, Str. Lăcrămioarei nr. 35-37, bl. 3-4, sc. 2, et. 1, ap. 45, Romania
Email: support@telldone.app
Phone: +40 720 236 439
Website: https://telldone.app

If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority. The competent supervisory authority for the data controller is the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, ANSPDCP), at https://www.dataprotection.ro. Users in other EEA member states may also lodge a complaint with their local supervisory authority.

This Privacy Policy applies to the TellDone mobile applications (iOS, watchOS), the web application at app.telldone.app, and the cloud service at api.telldone.app. It does not apply to third-party services linked from our app (Notion, Todoist, Things, Google, Apple, Microsoft, etc.), which have their own privacy policies.


This Privacy Policy applies to the TellDone mobile applications (iOS, watchOS), the web application at app.telldone.app, and the cloud service at api.telldone.app. It does not apply to third-party services linked from our app (Notion, Todoist, Things, Google, Apple, Microsoft, etc.), which have their own privacy policies.