TellDone ("we," "our," "us") is a voice-first planning application operated by Evgheni Taracanov, a private individual. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our mobile applications (iOS, iPadOS, watchOS, Android), our web application at app.telldone.app, and cloud services (collectively, the "Service").
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
If you connect a third-party productivity service (Todoist, Notion, Things, Google Tasks, Google Calendar, Apple Calendar, Apple Reminders, Microsoft To Do), we store, encrypted at rest:
You can disconnect any integration at any time in Settings → Integrations. On disconnect, we revoke the relevant OAuth token with the third party (where the third party exposes a revocation endpoint), delete the stored token from our database, and stop syncing. External items previously created from TellDone are not automatically deleted from the third-party service; you can delete them in that service if you wish.
The legal bases below are stated for the GDPR/UK GDPR; equivalent analysis applies under California, Swiss, and other comparable regimes.
| Purpose | Data used | Legal basis |
|---|---|---|
| Provide the Service | Audio, account, content | Contract performance, Art. 6(1)(b) |
| Generate productivity reports | Notes, tasks, events | Contract performance |
| Send email reports | Email, notes, tasks | Consent (opt-out via settings) |
| Multi-device sync | All content, device ID | Contract performance |
| Third-party integrations (Todoist, Notion, Google, Apple, Things, Microsoft To Do) | Items you sync, OAuth tokens | Consent (user-initiated connection per integration) |
| Sign in with Apple / Google | Apple/Google sub claim, name, email | Contract performance (account creation and authentication) |
| Quota enforcement and billing | Usage counts | Contract performance |
| Security and fraud prevention | Login attempts, device data | Legitimate interest, Art. 6(1)(f) |
| Service improvement, debugging | Anonymized error logs | Legitimate interest |
We do not:
We use the following third-party services to provide core functionality. Your data is processed under data processing agreements (DPAs) with each provider where the provider is acting as a processor on our behalf, and under the provider's own terms where the provider is an independent identity provider:
| Service | Role | Purpose | Data shared | Location |
|---|---|---|---|---|
| Soniox | Processor | Speech-to-text transcription | Audio recordings | USA |
| OpenAI | Processor | AI analysis, note structuring, embeddings, report generation | Transcripts, task and report context | USA |
| Resend | Processor | Transactional email delivery | Email address, report content | USA |
| Paddle.com Market Ltd | Merchant of Record / processor | Web subscription billing, payment processing, invoicing, refunds | Billing name and contact details, transaction data (not full card number) | UK / EU |
| Apple Inc. | Independent controller | Sign in with Apple identity provider; private email relay | Sign in with Apple identifier, name (if shared), relay email (if Hide My Email) | USA |
| Google LLC | Independent controller | Sign in with Google identity provider | Google sub claim, name, email | USA |
| Google LLC | Independent controller | Google Tasks / Google Calendar sync (when you connect them) | Task and event content you create in TellDone | USA |
| Notion Labs, Inc. | Independent controller | Notion sync (when you connect Notion via OAuth) | Page/database content for items you sync | USA |
| Doist S.L. (Todoist) | Independent controller | Todoist sync (when you connect Todoist via OAuth) | Task content for items you sync | EU |
| Cultured Code GmbH (Things) | Independent controller | Things sync (when you connect Things) | Task content for items you sync | DE |
| Microsoft Corporation | Independent controller | Microsoft To Do task sync (when you connect it) | Task content for items you sync | USA |
All third-party processors are contractually bound to process your data only as instructed by us and to maintain appropriate security measures. None of these providers use your data to train their AI models. The Apple, Google, Notion, Doist, Cultured Code, and Microsoft services listed as "independent controllers" process your data under their own privacy policies once it is in their systems; we recommend you review:
Our servers are located in Europe (Germany), within the European Economic Area. As the data controller is established in Romania (EU member state), transfers within the EEA do not require a separate transfer mechanism. Some third-party processors and identity providers (Section 3) are located in the United States. For these transfers, we rely on:
You can request a copy of the safeguards we rely on for a specific transfer (such as the relevant Standard Contractual Clauses) by emailing support@telldone.app.
| Data type | Retention period |
|---|---|
| Account data | Until account deletion |
| Audio recordings | Until you delete them or your account |
| Notes, tasks, events | Until you delete them or your account |
| Soft-deleted items (trash) | Free: 7 days · Basic: 30 days · Pro: 90 days · Ultra: 365 days |
| Reports | Until account deletion |
| OAuth integration tokens (Todoist, Notion, Google, Apple, Things, Microsoft To Do) | Until you disconnect the integration or delete your account; revoked with the provider on disconnect where technically possible |
| Sign in with Apple/Google identifiers | Until account deletion; on deletion we additionally call Apple's REST revoke endpoint to invalidate the refresh token |
| API usage logs | 12 months, then anonymized |
| Error logs | 30 days |
| Backups (encrypted) | 30 days, then deleted |
| Data exports (GDPR / CCPA) | 48 hours after generation, then deleted |
Once you confirm deletion, the request is scheduled to execute after a 7-day grace period. You can cancel the pending deletion at any time before the grace period expires. After the grace period, all personal data is permanently removed, including: database records (cascade delete), audio files from object storage, OAuth tokens (revoked with the third party where possible), Apple refresh tokens (revoked via Apple's REST API), GDPR/CCPA exports, and Redis quota counters. No human review is required.
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights:
If you are a California resident, you have the right to:
Categories of personal information collected (per CCPA/CPRA): identifiers (email, Apple/Google sub claim, device UUID); audio and electronic information (voice recordings); internet activity (usage logs); sensitive personal information (audio recordings, where they may contain sensitive content the user chooses to record).
Our website (telldone.app) uses Google Analytics 4 for basic visit statistics on the landing page, loaded only after you accept the cookie notice. We do not use advertising cookies, tracking pixels, or cross-site trackers on the website. Our mobile apps do not contain advertising SDKs, third-party analytics SDKs, or tracking SDKs (no ATT prompt is shown because we do not track users in the App Tracking Transparency sense).
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from anyone under 16. In the United States, the Service is not directed to children under 13 within the meaning of the Children's Online Privacy Protection Act ("COPPA"), and we do not knowingly collect personal information from children under 13. If we discover that we have collected data from a child under the applicable minimum age, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at support@telldone.app and we will act without undue delay.
We may update this Privacy Policy from time to time. When we make material changes (changes that materially affect the way we collect or use your data, including any change in how we use Google API user data or Sign in with Apple data), we will:
If you disagree with the changes you may close your account before the effective date and we will not enforce the changed policy against you.
TellDone's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
https://developers.google.com/terms/api-services-user-data-policy
What this means in practice:
You can revoke our access to your Google account at any time at https://myaccount.google.com/permissions, in addition to disconnecting in TellDone Settings → Integrations.
If you connect Microsoft To Do, TellDone offers an optional, strictly user-initiated two-way sync of your tasks between TellDone and your Microsoft To Do account. This integration is available on the Basic plan and above (Basic includes one integration slot; Pro and above include unlimited integrations) and is connected only after you complete Microsoft's OAuth consent flow. TellDone is an independent application that works with Microsoft To Do; we are not affiliated with, sponsored by, or endorsed by Microsoft.
Authorization uses the Microsoft identity platform (OAuth 2.0, authority login.microsoftonline.com/common) and supports both personal Microsoft accounts and work or school accounts. We request delegated permissions only (permissions that act on your behalf; we never request application-only or administrator access):
We do not use administrator ("admin consent") permissions; each user consents individually for their own account. When the integration is active, we create a dedicated task list named "TellDone" in your Microsoft To Do and write the title, description, deadline, and completion status of your TellDone tasks into that list. We poll that same "TellDone" list (using a delta query, roughly every five minutes) for completion and deletion changes and reflect them back in TellDone. We interact only with the "TellDone" list we create; we do not read your other Microsoft To Do lists. We never use data obtained from Microsoft to develop, improve, or train AI or machine-learning models, and we do not use it for advertising.
Your Microsoft OAuth access and refresh tokens are stored in our database encrypted at rest (Fernet symmetric encryption), and refresh-token rotation is persisted so the connection stays valid. Our production servers are located in the European Union (Germany).
You can disconnect Microsoft To Do at any time in TellDone Settings → Integrations. Disconnecting immediately deletes the stored tokens from our servers and stops the sync. Disconnecting in TellDone does not, by itself, revoke TellDone's authorization on Microsoft's side; to remove that grant as well, revoke TellDone's access in your Microsoft account settings at https://account.live.com/consent/Manage. Tasks previously written to the "TellDone" list are not automatically deleted from your Microsoft To Do when you disconnect; you can delete them in Microsoft To Do if you wish.
Our use of Microsoft APIs is subject to the Microsoft APIs Terms of Use; once your data is in Microsoft's systems, it is governed by the Microsoft Services Agreement and the Microsoft Privacy Statement, available at https://privacy.microsoft.com/privacystatement.
When you use Sign in with Apple, we receive only the data Apple provides:
We use this data only to create and authenticate your TellDone account and (for the email address) to send you transactional emails such as report digests, password resets, and security notices. We do not attempt to deanonymize the relay address, do not send marketing email to relay addresses, and respect your choice to disable email forwarding from your Apple ID settings.
When you delete your TellDone account, we call Apple's Sign in with Apple REST revocation endpoint to invalidate the refresh token issued to us, in addition to deleting your account data on our side. You can also revoke Apple's authorization at any time in iOS Settings → [your name] → Sign in with Apple, or at https://appleid.apple.com.
When you connect Notion via OAuth, you are taken to Notion's authorization screen where you select which workspace and which specific pages or databases TellDone may access. We can only see the resources you grant; we cannot read other content in your workspace. We use this access only to create, read, update, and delete items that correspond to your TellDone notes, tasks, or events. We never use your Notion content to train any AI model and never share it with any party other than the data processors listed in Section 3 strictly to provide the sync feature.
When you connect Todoist via OAuth, we request only the scopes needed for two-way task sync (typically data:read_write, and data:delete if you enable two-way deletion). We use this access solely to create, read, update, complete, and (if you opt in) delete tasks that correspond to your TellDone tasks. We do not use your Todoist content to train any AI model and do not share it beyond the data processors in Section 3.
You can disconnect either integration at any time in TellDone Settings → Integrations; we will revoke the OAuth token with the provider on disconnect. You can also revoke the integration directly:
The data controller for personal data processed under this Privacy Policy is Evgheni Taracanov, a private individual, operating as TellDone, contactable at:
Address: Mun. București, Sec. 3, Str. Lăcrămioarei nr. 35-37, bl. 3-4, sc. 2, et. 1, ap. 45, Romania
Email: support@telldone.app
Website: https://telldone.app
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority. The competent supervisory authority for the data controller is the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, ANSPDCP), at https://www.dataprotection.ro. Users in other EEA member states may also lodge a complaint with their local supervisory authority.
This Privacy Policy applies to the TellDone mobile applications (iOS, iPadOS, watchOS, Android), the web application at app.telldone.app, and the cloud service at api.telldone.app. It does not apply to third-party services linked from our app (Notion, Todoist, Things, Google, Apple, Microsoft, etc.), which have their own privacy policies.
This Privacy Policy applies to the TellDone mobile applications (iOS, iPadOS, watchOS, Android), the web application at app.telldone.app, and the cloud service at api.telldone.app. It does not apply to third-party services linked from our app (Notion, Todoist, Things, Google, Apple, Microsoft, etc.), which have their own privacy policies.