01
Scope
OpenTodo is currently available only to authorized testers. This notice covers the iPhone app, its preproduction and production test backends, and the support needed to operate them. It does not replace the separate Moonwake Labs website privacy notice.
02
Information we handle
We process Firebase account identifiers and profile details supplied by Google or Sign in with Apple; your todos, notes, list organization, chat prompts and replies; voice recordings and transcripts when you use voice input; images you choose to submit; subscription product, eligibility, transaction-state, and app-account identifiers; and security and operational records such as IP address, timestamps, request status, and opaque job identifiers.
OpenTodo does not use advertising trackers or sell personal information. Apple payment credentials and private keys are not stored in the app database.
03
How we use information
We use account information to authenticate and isolate each account; content to provide todo, search, voice, image, and AI-assistance features; StoreKit records to determine trial and subscription access; and limited operational records to secure, diagnose, and improve the test service.
04
Service providers
OpenTodo relies on Apple for Sign in with Apple and Sandbox subscriptions, Google Firebase for authentication, Cloudflare for network delivery and protection, Amazon Web Services for application hosting, databases, backups, logs, and deletion-journal storage, DeepSeek for language-model processing, and DeepInfra for speech transcription. These providers process only the information needed for their role and may operate in different regions.
Do not place information in a test account that you would not want sent to the selected AI or speech provider. Provider retention and content-use terms remain part of the private-test review before any public release.
05
Retention
Account content remains until you delete it or the private test is reset. Application logs are retained for up to 14 days, load-balancer logs for up to 30 days, automated database backups for up to 7 days, approved prechange recovery points for up to 14 days, and decommission recovery points for up to 30 days. Minimal immutable deletion-journal records are retained for 60 days so deleted accounts cannot reappear from a supported backup.
Unbound or detached terminal StoreKit projections may be retained for up to 180 days while the retention decision is reviewed. They cannot grant access after account deletion.
06
Account deletion
You can initiate deletion inside OpenTodo under Settings and Account. Deletion removes the Firebase account and app content, clears account-scoped device state, and detaches StoreKit ownership. It does not cancel an Apple subscription; manage that separately in App Store settings. Provider revocation is best effort, and the app supplies manual help if its result is uncertain.
Backups remain quarantined until the deletion journal is replayed, and expire on the schedule above. A short-lived cryptographic fence prevents a stale identity token from recreating a deleted account.
07
Your choices
You can choose text instead of voice, avoid submitting images, manage or cancel the Apple Sandbox subscription, sign out, or delete the account. Because this is private testing, you may also ask us to stop using your test account.
08
Contact
Moonwake Labs LLC
[email protected]
(650) 820-5663