Privacy Policy

Effective date: 6 October 2026 · Last updated: 29 September 2026

TellDone is a product of Kesterly Ltd, a company registered in England and Wales under company number 17359915, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Kesterly Ltd provides and operates the Service and is the data controller for the personal data described in this policy. We are registered with the UK Information Commissioner’s Office under registration reference ZC206782.

This Privacy Policy explains how we collect, use, store and protect your personal data when you use our mobile applications (iOS, watchOS), our web application at app.telldone.app, our cloud service at api.telldone.app, our API and MCP endpoints, and our website at telldone.app (together, the “Service”).

We are established in the United Kingdom, so the UK GDPR and the Data Protection Act 2018 are the law we work to. Where we mention other regimes — California, for example — that is stated separately and does not change the UK analysis.

By using the Service you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.


1. Data we collect

1.1 Account data

1.2 Voice recordings

People who are not TellDone users. A recording, a transcript or a note may contain personal data about someone who has no account with us and never agreed to anything: their words, and sometimes their name if it was spoken. We do not use that data to build a profile of them, we do not contact them, and we do not attempt to identify them beyond storing what was said. Responsibility for where and whom you record remains yours — see the acceptable-use section of the Terms of Service. If you believe a recording held by one of our users contains your personal data, contact us at legal@kesterly.com.

Sensitive content. We do not ask you for health, political, religious, biometric or other special category information, we do not analyse your recordings in order to derive any of it, and no feature of the Service is built on it. Because you decide what to record, a recording may nonetheless contain such content. If you would rather it did not reach our processors, do not record it.

1.3 Content generated from your recordings

Where the AI infers the name of a person mentioned in a recording — a meeting attendee, for example — that name is stored as part of the note. That is personal data about someone who may not be a TellDone user; see the paragraph above.

1.4 Device data

1.5 Usage, diagnostic and connection data

Retention for each of these is in section 5. Our apps contain no third-party analytics SDKs, no advertising SDKs, no tracking SDKs and no crash-reporting SDKs, and we do not fingerprint devices. The web app contains no third-party analytics or error-tracking service either. The only third-party measurement anywhere in the Service is the Google Analytics tag on our website, described in section 8.1.

1.6 Integration data

If you connect Todoist, Notion or Microsoft To Do, the authorisation happens on our servers and we store, encrypted at column level before it is written to the database:

The content we send to or receive from these services is limited to the fields you create in TellDone (title, notes, due date, tags, completion status). We do not pull arbitrary content from your Notion workspace or your Todoist account, and with Microsoft To Do we interact only with the dedicated “TellDone” list we create, not your other lists.

You can disconnect any integration at any time in Settings → Integrations. Disconnecting always deletes our stored copy of the token from our database and stops the sync. What it does at the provider’s end depends on the provider, and the differences matter:

Deleting your whole account revokes less than disconnecting does, not more. Account deletion removes our copies of all three tokens but makes no revocation call to any of them — not even to Todoist. The only revocation attempted on that path is for Sign in with Apple (see section 5.1).

So the rule to work from is this: revocation at the provider happens for Todoist when you disconnect it. For Notion and Microsoft To Do, and for every provider when you delete your account, you should also revoke TellDone’s access in that provider’s own settings — Notion: Settings → My connections; Todoist: Settings → Integrations → Connected apps; Microsoft: https://account.live.com/consent/Manage.

Items previously created in the third-party service are not deleted automatically; you can delete them there if you wish.

Two integrations work differently, because they run on your device rather than on our servers.

1.7 Billing data

Subscriptions are sold as in-app purchases through the Apple App Store. Apple takes the payment and holds your payment details; we never see your card number. We receive the transaction receipt and the entitlement information we need to activate your plan, and we record which plan your account is on and when it renews or lapses.

Where we grant access to a paid plan without charge — a promotional grant, or a manual grant we make ourselves — we record the grant against your account. No payment data is involved.

1.8 Whether you have to give us this data

None of this is required of you by law. What follows is what the Service needs in order to work, and what happens if you withhold it.

Data Required? If you do not provide it
Email address Required to hold an account with us — it is how we identify you and reach you We cannot create or maintain an account
Password Required unless you use Sign in with Apple or Sign in with Google You cannot sign in with an email and password
Display name Optional Nothing; the Service addresses you less personally
Voice recordings You choose what to record The Service has nothing to transcribe or structure
Locale and time zone Taken from your device Scheduling, date interpretation and speech-to-text routing become less accurate
Device identifier Generated by the app; needed for sync and per-device sign-in Multi-device sync and per-device session revocation cannot work
Push notification token Optional, and controlled by your device’s notification permission You receive no push notifications
Integration authorisations Entirely optional That integration does not sync

2. How we use your data, and our legal bases for it

The legal bases below are stated under the UK GDPR. Where another regime applies to you — California, for example — see section 7.2.

Purpose Data used Legal basis
Provide the Service: transcribe your recordings, structure them into notes, tasks and events, and store them for you Audio, transcripts, account data, generated content Performance of our contract with you, Art. 6(1)(b)
Generate productivity reports Notes, tasks, events Performance of our contract with you
Send you report emails Email address, report content Consent — you can turn report emails off in Settings at any time
Send you transactional and security email (password reset, security notices, account notices) Email address Performance of our contract with you
Send push notifications Device push token, the title of the note, task or event concerned Performance of our contract with you (and your device’s notification permission)
Sync across your devices All content, device identifier Performance of our contract with you
Third-party integrations you connect (Todoist, Notion, Microsoft To Do) The items you sync; the OAuth tokens we hold for that integration Consent — you initiate each connection separately and can disconnect it
Sign in with Apple / Sign in with Google Apple or Google sub claim, name, email Performance of our contract with you (account creation and authentication)
Enforce plan quotas and activate what you have paid for Usage counts, receipt and entitlement data Performance of our contract with you
Answer your support requests The content of your message and the account it concerns Performance of our contract with you
Security and fraud prevention Sign-in attempts, IP addresses, device data, rate-limiting counters Legitimate interests, Art. 6(1)(f) — our interest in protecting the Service and the people who use it from abuse, unauthorised access and fraudulent use, and in keeping accounts secure
Diagnosing faults and improving the Service Error logs, diagnostic bundles, analytics events Legitimate interests, Art. 6(1)(f) — our interest in keeping the Service working, finding out why something failed, and making it better
Backups, so that we can restore the Service after a failure Everything we store Legitimate interests, Art. 6(1)(f) — our interest in not losing your data
Meeting a legal obligation that applies to us — for example responding to a valid legal request Whatever the obligation requires Legal obligation, Art. 6(1)(c)

You can object to any processing we base on legitimate interests, and you can withdraw consent at any time without affecting what we did lawfully before you withdrew it. See section 7.

2.1 What we do not do

2.2 AI models and training

Our own commitment is unqualified: we do not use your audio, your transcripts, your notes or any other content you create in TellDone to train, fine-tune or evaluate any AI model, and we do not give anyone else your content for that purpose. No feature of the Service depends on doing so, and no setting anywhere turns it on.

Your content is sent to the AI providers listed in section 3 for one reason only: so that they can return a result — a transcript, a structured note, a report — which we pass back to you. They act as our processors and we instruct them to use your content only to produce that result.


3. Third parties who process your data

Where a provider below acts as our processor, we instruct it to process your data only to provide the function described and to keep it secure. Where a provider is an independent controller, your data is governed by that provider’s own privacy policy once it reaches their systems.

Provider Role What it receives Where it is processed
netcup GmbH Processor Hosting of the application, database and object storage — all account data, voice recordings, transcripts and generated content Nuremberg, Germany
Hetzner Online GmbH Processor Encrypted off-site backups of the database and object storage Germany
Soniox Processor Speech-to-text: your voice recordings and the resulting transcript Routed by your time zone — the EU endpoint for Europe, Africa, the Middle East and West Asia, the US endpoint for the Americas. EU is the default
Fireworks AI Processor AI analysis — the first provider in our processing chain: transcripts and note, task and event text, for note structuring, smart context, follow-ups, questions about your notes, day planning, edit classification, your profile summary and speaker separation United States
Mistral AI Processor The same content, when the first provider is unavailable European Union
OpenAI Processor The same content, when the first two are unavailable; and all report generation United States
Anthropic Processor Configured as a further fallback for report generation. No plan currently routes to it, so it receives nothing today. It is listed so that this section stays accurate if that changes United States
Resend Processor Transactional and report email: your email address and the full body of the email — for a report email, that is the report itself Resend, Inc. is established in the United States
Apple (Apple Push Notification service) Processor Your device push token and the notification content, which can include the title of a note, task or event Apple infrastructure
Telegram Message delivery If you send us a support request through the in-app support desk, the text of that request is delivered to our support chat over Telegram Telegram infrastructure
Google Processor Hosting of our support mailbox: an email you send to support@telldone.app is received there Google infrastructure
Twilio Inc. Processor Our published telephone line: if you call or text the number in section 14, Twilio carries that call or message and receives your telephone number and the associated call or message details United States
Google Independent controller Sign in with Google: we verify the identity token you present. We request only openid, email and profile and no other Google scope on our servers United States
Apple Independent controller Sign in with Apple: we verify the identity token you present; private email relay if you use Hide My Email United States
Doist S.L. (Todoist) Independent controller Task content for the items you choose to sync, if you connect Todoist European Union
Notion Labs, Inc. Independent controller Page and database content for the items you choose to sync, if you connect Notion United States
Microsoft Corporation Independent controller Task content in the dedicated “TellDone” list, if you connect Microsoft To Do United States

We also use an operational alerting service (ntfy.sh) to tell us when something on our servers breaks. By design those alerts carry no user content.

If you connect an external AI client through the User MCP endpoint (see Terms of Service section 23), that client is not our processor. It acts on your instruction and under credentials you issued: we transmit only the responses to the specific tool calls it makes, and what the client’s vendor does with those responses is governed by that vendor’s own privacy policy. We never send your account contents to such a client in bulk, and we never share them with the vendor for any purpose beyond completing your request. You can revoke a client’s access at any time in Settings → Integrations → AI Agents.

The providers listed as independent controllers process your data under their own privacy policies once it is in their systems. We recommend you review:


4. Sending data outside the United Kingdom

We are established in the United Kingdom, so sending your personal data to an organisation outside the UK is a restricted transfer and needs a lawful route.

Our own servers are in Germany. The application, the database and the object storage that holds your recordings run on hardware in Nuremberg; our backups are held in Germany too. Germany is in the European Economic Area, and the EEA is covered by the UK’s adequacy regulations, so no further safeguard is needed for those transfers.

Speech-to-text is routed by your time zone. If your time zone is in Europe, Africa, the Middle East or West Asia, your audio goes to the European endpoint. If it is in the Americas, it goes to the United States endpoint. Where we cannot tell, the European endpoint is used.

Language processing is not routed by your location. The first provider in our chain is in the United States, the second is in the European Union and the third is in the United States, and reports are generated in the United States. Which one handles a given request depends on availability, not on where you are.

For transfers to the United States, the following providers listed in section 3 hold an active certification under the UK Extension to the EU–US Data Privacy Framework, which UK law recognises as providing adequate protection: Google, Microsoft Corporation, Resend, Twilio Inc. and Notion Labs, Inc. We check their status against the official Data Privacy Framework list periodically (last checked 29 September 2026).

If you want to know what covers a particular transfer, write to legal@kesterly.com and we will tell you.


5. How long we keep your data

Data How long we keep it
Account data (email, name, locale, sign-in identifiers) Until your account is deleted
Voice recordings While your account exists. Deleting a note does not delete its recording; recordings are deleted when you delete your account
Notes, transcripts, tasks, events, reports, tags Until you delete them or your account. A deleted item goes to trash and is then permanently removed after the window for your plan: Free 7 days · Basic 30 days · Pro 90 days · Ultra 365 days
OAuth tokens for integrations we hold (Todoist, Notion, Microsoft To Do) Until you disconnect the integration or delete your account. Deleting our copy is not the same as cancelling the permission you gave the provider: disconnecting Todoist also asks Todoist to revoke it (best-effort), while Notion and Microsoft To Do are never revoked by us, and account deletion revokes none of the three. Section 1.6 says where to remove each one yourself
Sign in with Apple / Sign in with Google identifiers Until account deletion. On deletion we make one attempt to revoke the refresh token Apple issued to us; the attempt is not retried and deletion proceeds whatever its outcome
API usage ledger 180 days
Analytics events (not linked to your account) 548 days
Diagnostic bundles (linked to your account) 90 days
MCP usage log 90 days
Voice messages sent to support 90 days
Security event identifiers received from Apple and Google 48 hours
Web server access logs, including IP addresses 14 days
Other server logs System logs are capped by size (4 GB) rather than by time; at current volume that holds roughly two months of entries. There is no fixed time limit
Backups Kept on a rolling schedule — 7 daily, 4 weekly and 6 monthly snapshots. Data you have deleted can remain inside a backup snapshot for up to about six months before that snapshot expires
Data exports you generate Your export file is available for 48 hours; it is deleted at the next daily cleanup after it expires, so within about 72 hours of generation at the latest. The download link is the only way to reach the file, and deleting your account removes any export files immediately, regardless of expiry
Billing records Deleted with your account — we keep nothing after that

5.1 Deleting your account

You can delete your account from the app. When you confirm, the deletion is scheduled and runs after a 7-day grace period; you can cancel it at any point before the grace period expires, and we email you to confirm the request.

When it runs, the deletion works in this order, deliberately:

  1. Your voice recordings, your export files and your usage counters are purged from object storage and cache first. If any part of that fails, the whole run aborts and nothing else is deleted — so we never end up with database rows pointing at files that are gone, or files left behind with no record of who they belong to.
  2. Your records are then deleted from the database. Twenty-six tables are cleared by cascade from your user record, including your notes, transcripts, tasks, events, reports, tags, integration tokens, device registrations, analytics and billing records.
  3. Two records survive with your identifier removed: the deletion request itself, and the record of any data-export job you ran. Neither identifies you afterwards.
  4. We make one attempt to revoke the Sign in with Apple refresh token issued to us. The attempt is not retried; if it fails the failure is logged and deletion proceeds anyway.

No human review is involved at any stage.

Two things deletion does not do, because they are not ours to finish. Deleting your TellDone account does not cancel the permission you gave to Todoist, Notion or Microsoft. We delete our copies of those tokens, but we make no revocation call to any of the three on this path — not even to Todoist, which we do call when you disconnect it individually — so the authorisation stays active in your account with that provider until you remove it there. Section 1.6 says where, and it is worth doing before or after deleting your account. And the Sign in with Apple revocation above is an attempt, not a guarantee — you can always review or remove that authorisation yourself at https://appleid.apple.com.

The one thing deletion cannot reach immediately is our backups. Backup snapshots expire on the rolling schedule above, so data from a deleted account can persist inside a snapshot for up to about six months. We do not restore deleted accounts from backups, and a snapshot containing your data is deleted when it expires.


6. Security


7. Your rights

7.1 Under the UK GDPR

7.2 Under the CCPA / CPRA (California residents)

If you are a California resident you have the right to: know what personal information we collect, its sources, the purposes and the categories of recipients; delete your personal information, subject to exceptions permitted by law; correct inaccurate personal information; opt out of the “sale” of personal information (we do not sell it, and never have); opt out of “sharing” for cross-context behavioural advertising (we do not share it for that); limit the use of sensitive personal information (we use it only as reasonably necessary to provide the Service you asked for); and not be discriminated against for exercising any of these rights.

Categories collected, in CCPA terms: identifiers (email, Apple or Google sub claim, device UUID, IP address); audio and electronic information (voice recordings); internet activity (usage logs); and sensitive personal information (voice recordings, to the extent you choose to record sensitive content).

7.3 How to exercise your rights

7.4 Automated decision-making and profiling

We do not make decisions about you that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing. We do not profile you, and we do not build inferences about you for anyone else’s purposes.

The Service is nonetheless highly automated, and you should know exactly what that means: your recordings are transcribed, structured into notes, tasks and events, and summarised into reports by AI, with no human in the loop; and if you ask us to delete your account, that deletion is carried out automatically without human review. These are the features you asked for. They are not decisions taken about you in the sense above.


8. What is stored on your device, and what we read from it

This section covers everything the Service stores on, or reads from, your device — cookies, browser storage and the equivalent in the apps.

8.1 Our website, telldone.app

The website itself sets no cookies, contains no forms and collects nothing from you. Support from the website is an email link, not a form.

Before you consent, the site loads nothing from a third party: fonts and every other asset are served from our own servers, so the pages do not contact any third-party content delivery network. Every page carries a notice with Accept and Decline, and until you choose, no analytics tag is loaded. If you decline, your choice is remembered and the tag is never loaded.

What is stored Type Purpose When it is written How long it lasts
cookie-consent Browser local storage Records whether you accepted or declined analytics, so we do not ask again and so your refusal is honoured When you click Accept or Decline Until you clear your browser storage
theme Browser local storage Remembers whether you chose the light or dark appearance When your appearance preference is stored Until you clear your browser storage
_ga, _ga_* Cookies set by Google Google Analytics 4 (measurement ID G-TFMR5XEXBC) — visit statistics only. We do not use advertising cookies, tracking pixels or cross-site trackers Only after you click Accept Set and expired by Google, under Google’s own retention

8.2 The web app, app.telldone.app

TellDone’s own web-app code does not read or write first-party cookies. What it keeps, it keeps in your browser’s local storage and IndexedDB, on your device, and uses to run the app; the table below lists all of it. The third-party sign-in providers described at the end of this section may use storage of their own, which is theirs and not ours.

The web app collects no behavioural usage analytics — no stream of clicks, screens or page views, and no third-party analytics or error-tracking service of any kind. When technical diagnostics are enabled, it may send us a limited report when a specific error occurs; that is described below and is the only thing of this sort it sends.

What is stored Where Purpose How long it lasts
access_token, refresh_token Local storage Your TellDone sign-in tokens, so you stay signed in. They are never put in a cookie Removed from this browser when you sign out. The access token is valid for up to 7 days, the refresh token for 90 days; using the refresh token renews the 90 days, so signing in stays active while you use the app, and after about 90 days of not using it you are signed out
lp.auth Local storage A cached copy of your account details — identity, email, plan, preferences and entitlements — so the app can open and show your workspace before it reaches the network Removed when you sign out
telldone:auth-session Local storage A random marker for the current sign-in, renewed each time you sign in Removed when you sign out
device_id Local storage A random identifier for this browser, sent with changes you make and with diagnostic reports so we can tell devices apart. It is not removed when you sign out — clearing your browser storage removes it Until you clear your browser storage
locale, content_locale, theme, colorTheme, density, detailPanelWidth, settingsTab Local storage Your interface preferences: language, appearance, layout density and which panel you had open Until you clear your browser storage
hasSeenOnboardingTour, hasSeenWelcome, hasAskedMic, pendingAutoRecord Local storage Remembers that you have seen the introduction and been asked for microphone permission, so you are not asked twice Until you clear your browser storage
recorder:pendingAudioIds:<account>, recorder:successfulRunsCount Local storage Keeps track of recordings that have not finished uploading, and counts successful runs so the app can spot a recorder that is failing The pending list expires after 24 hours
Detail-view markers per item Local storage Remembers how you had a note, task or event displayed Until you clear your browser storage
telldone:diagnostics-enabled Local storage Records whether you have turned technical diagnostics off Until you clear your browser storage
Offline upload queue IndexedDB If a recording cannot be uploaded — you are offline, or the upload fails — the app keeps it on your device so it is not lost, and retries. See below Removed as soon as the upload succeeds or you deal with it yourself. Otherwise it becomes eligible for clearing once it is more than 30 days old, and is cleared the next time the app opens the queue

Signing out. Signing out removes the tokens above from this browser and revokes the refresh token, so nothing new can be obtained with it. It does not cancel an access credential that was already issued: that one remains valid until it expires, which can be up to 7 days. Section 6 explains why.

Recordings waiting on your device. The offline queue is the one item here worth reading twice. When an upload cannot complete, the entry the app stores on your device can contain the audio recording itself, or the text you typed, together with the file name, the time and time zone you recorded at, and what it is attached to.

Most of the time you will see it: when an upload has failed for good or run out of retries, the recording stays visible in the app with Retry and Dismiss, and it waits there until you choose one. What is not visible is the tail. An entry that is never dealt with becomes eligible for clearing once it is more than 30 days old — but that clearing happens when the app next opens the queue, not on a timer. So if you record while offline and never come back to the app, the recording stays on your device: past 30 days it is eligible to go, and it goes the next time the app looks. Entries left over from an older version of the app, which are not attached to any account, are held aside and cleared the same way.

All of this is storage on your own device rather than ours. We describe it because it is your recording and you should know where it is.

Technical diagnostics. When a recording, an upload or the live connection fails, the app can send us a report of that failure. It is triggered by errors only — never by what you click or look at — and it is first-party: the report goes to our own servers and to no one else. It contains the kind of error, the platform, the time, the type and identifier of the item involved if there is one, a short summary and technical context, and it carries your sign-in token and the device_id above, so the report is linked to your account. It is on by default, and you can turn it off in Settings → Data and privacy. That choice is stored in the browser you make it in and does not carry over to other browsers or devices. Retention is in section 5, with the other diagnostic bundles.

When you contact support from the web app, the message you send carries the screen you sent it from, your time zone and your browser’s user-agent string, so we can reproduce the problem. If you send a voice or file message, we receive what you attach.

The one third party the web app contacts without you asking it to. On the sign-in screen, the Sign in with Google button loads a script from Google in order to draw itself. That happens before you have signed in and without you clicking anything, so where that button is shown, Google receives your IP address and the usual network metadata simply because the sign-in page loaded. Sign in with Apple behaves differently: its script loads only at the moment you choose Apple sign-in. Any cookies Google or Apple set at that point are theirs, governed by their privacy policies; TellDone does not read or write them.

Everything else the web app reaches, you start yourself: connecting Todoist, Notion or Microsoft To Do takes you through that provider’s own authorisation pages; a link you open — whether it is one you exported, or one of ours to help or legal pages — goes where it says it goes. Apart from the sign-in script above and the destinations you choose, the web app talks only to our own servers, and its fonts and icons are served from our own servers.

8.3 The iPhone and Apple Watch apps

The apps contain no advertising SDKs, no third-party analytics SDKs, no tracking SDKs and no crash-reporting SDKs. They have exactly three third-party components: a library that converts your recording to OGG Opus on the device, a local database library, and Google’s sign-in library. Only the last of those talks to anyone, and only to Google, when you use Sign in with Google. No App Tracking Transparency prompt is shown, because there is nothing to ask you about: we do not track you across other companies’ apps or websites, and the app contains no code for it.

What the apps ask permission for, and only when it is needed:

The apps do not ask for your location, contacts, photos, camera or health data at all.

What is kept on your device. A local cache of your notes, tasks and events in the app’s own private storage; your recordings in the app’s shared container so the Watch app and extensions can reach them; and your sign-in tokens in the iOS Keychain.

What leaves your device goes to our own servers and nowhere else — your recordings and transcripts, and your notes, tasks and events as they sync. Alongside those, the apps send two small streams:


9. Children

You must be at least 16 years old to create a TellDone account, and we do not knowingly collect personal data from anyone under 16.

Sixteen is our own contractual requirement, not the legal minimum. Under UK data protection law, where an online service relies on consent, a child of 13 or over can give that consent themselves. We set the bar at 16 because we do not offer parental-consent account creation.

In the United States, the Service is not directed to children under 13 within the meaning of the Children’s Online Privacy Protection Act (“COPPA”), and we do not knowingly collect personal information from children under 13.

If we discover that we hold data about someone below our minimum age, we delete it promptly. If you believe a child has given us personal data, contact us at legal@kesterly.com and we will act without undue delay.


10. Changes to this policy

We may update this Privacy Policy. When we make a material change — one that materially affects how we collect or use your data, including any change in how we use Google API user data or Sign in with Apple data — we will:

If you disagree with a change, you may close your account before the effective date.


11. Google API Services (Limited Use)

TellDone’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What this means in practice:

You can revoke our access to your Google account at any time at https://myaccount.google.com/permissions.


11A. Microsoft To Do (Microsoft Graph)

If you connect Microsoft To Do, TellDone offers an optional, strictly user-initiated two-way sync of your tasks between TellDone and your Microsoft To Do account. This integration is available on the Basic plan and above (Basic includes one integration slot; Pro and above include unlimited integrations) and is connected only after you complete Microsoft’s OAuth consent flow. TellDone is an independent application that works with Microsoft To Do; we are not affiliated with, sponsored by, or endorsed by Microsoft.

Authorisation uses the Microsoft identity platform (OAuth 2.0, authority login.microsoftonline.com/common) and supports both personal Microsoft accounts and work or school accounts. We request delegated permissions only — permissions that act on your behalf; we never request application-only or administrator access:

We do not use administrator (“admin consent”) permissions; each user consents individually for their own account. When the integration is active, we create a dedicated task list named “TellDone” in your Microsoft To Do and write the title, description, deadline and completion status of your TellDone tasks into that list. We poll that same “TellDone” list — using a delta query, roughly every five minutes — for completion and deletion changes and reflect them back in TellDone. We interact only with the “TellDone” list we create; we do not read your other Microsoft To Do lists. We never use data obtained from Microsoft to develop, improve or train AI or machine-learning models, and we do not use it for advertising.

Your Microsoft OAuth access and refresh tokens are stored in our database encrypted at column level (Fernet symmetric encryption). Our production servers are in Germany.

You can disconnect Microsoft To Do at any time in TellDone Settings → Integrations. Disconnecting immediately deletes the stored tokens from our servers and stops the sync. Disconnecting in TellDone does not, by itself, revoke TellDone’s authorisation on Microsoft’s side; to remove that grant as well, revoke TellDone’s access in your Microsoft account settings at https://account.live.com/consent/Manage. Tasks previously written to the “TellDone” list are not deleted from your Microsoft To Do when you disconnect; you can delete them there if you wish.

Our use of Microsoft APIs is subject to the Microsoft APIs Terms of Use; once your data is in Microsoft’s systems it is governed by the Microsoft Services Agreement and the Microsoft Privacy Statement, at https://privacy.microsoft.com/privacystatement.


12. Sign in with Apple

When you use Sign in with Apple, we receive only what Apple provides:

We use this only to create and authenticate your TellDone account and, for the email address, to send you transactional email such as report digests, password resets and security notices. We do not attempt to deanonymise the relay address, do not send marketing email to relay addresses, and respect your choice to disable email forwarding in your Apple ID settings.

When you delete your TellDone account we attempt to revoke the refresh token Apple issued to us, using Apple’s Sign in with Apple REST revocation endpoint. The attempt is made once and is not retried; if it fails, the failure is logged and your account deletion goes ahead anyway. So treat it as an attempt rather than a guarantee, and revoke Apple’s authorisation yourself if you want to be certain — at any time in iOS Settings → [your name] → Sign in with Apple, or at https://appleid.apple.com.


13. Notion and Todoist

When you connect Notion via OAuth, you are taken to Notion’s authorisation screen where you select which workspace and which specific pages or databases TellDone may access. We can only see the resources you grant; we cannot read other content in your workspace. We use this access only to create, read, update and delete items that correspond to your TellDone notes, tasks or events. We never use your Notion content to train any AI model, and never share it with any party other than the processors listed in section 3, strictly to provide the sync.

When you connect Todoist via OAuth, we request exactly two scopes: data:read_write and data:delete. We use this access solely to create, read, update, complete and — if you opt in — delete tasks that correspond to your TellDone tasks. We do not use your Todoist content to train any AI model and do not share it beyond the processors in section 3.

You can disconnect either integration at any time in TellDone Settings → Integrations, which deletes our stored copy of the token and stops the sync. When you disconnect Todoist we also ask Todoist to revoke the token, on a best-effort basis. Notion has no way for us to do that, so disconnecting does not cancel the permission you granted inside Notion — remove our access yourself in Notion → Settings → My connections. And on either integration, if you delete your whole TellDone account rather than disconnecting, no revocation call is made at all; remove our access in the provider’s settings (Todoist — Settings → Integrations → Connected apps). Section 1.6 sets this out in full.


14. Who we are, how to reach us, and how to complain

The data controller for personal data processed under this Privacy Policy is:

TellDone is a product of Kesterly Ltd.

Data Protection Officer. We have not designated a Data Protection Officer. Data protection questions and requests go to legal@kesterly.com and are handled by the company.

Complaining to us

If you think we have got something wrong, tell us first: legal@kesterly.com. You have the right to complain directly to us about how we handle your personal data, under section 164A of the Data Protection Act 2018.

We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to look into it, and tell you the outcome without undue delay.

Complaining to the Information Commissioner

You can also complain to the UK’s data protection regulator, under section 165 of the Data Protection Act 2018:

You do not have to complain to us first, though it is usually quicker.


This Privacy Policy applies to the TellDone mobile applications (iOS, watchOS), the web application at app.telldone.app, the cloud service at api.telldone.app including our MCP endpoint, and the website at telldone.app. It does not apply to third-party services linked from our app or website — Notion, Todoist, Google, Apple, Microsoft and others — which have their own privacy policies.