How your data is protected
Encrypted in transit and at rest, with row-level security on every table so you can only ever reach your own rows.
By ToDidIt Product TeamUpdated
Everything is encrypted in transit and at rest.
Every table enforces access in the database rather than in application code. You can only ever read your own rows and the rows of workspaces you belong to, and project-level access is enforced the same way.
This matters because it holds no matter which door a request comes through: the app, search, an export, or the API. There is no code path that can forget to apply the check.
AI features only run when you trigger them. Nothing is sent to a model in the background, and there is no ambient analysis of your tasks.
The Privacy page has the complete policy, including sub-processors and retention.
The parts of this that are your side of the line, in the order that matters. Everything above is what the platform does; this is what you control.
Add a passkey.
Open Security settingsIt replaces the password with the thing that already unlocks your device, which removes the whole class of problem where a password gets reused or phished.
Add an authenticator app if you sign in from shared machines.
A passkey covers the device it lives on. A six-digit code covers everywhere else. Keep the recovery codes somewhere other than the phone running the app.
Check who is in your workspaces.
Open WorkspacesAccess is enforced in the database, but only against the list you set. A contractor who finished in March is still a member until someone removes them.
Review anything you shared by link.
A share link works for whoever holds it, which is the point of it and the reason to retire the ones you no longer need.
Take an export.
Security includes still having your work. An export is the copy that does not depend on this account continuing to exist.
Similar readings
Everything below is in the Happiness Center.
Roles and project access
Owner, Admin, Member, and Guest, plus a per-person list of which projects they can see. Enforced in the database, not just the interface.
Passkeys and two-factor
Sign in with a passkey or add an authenticator app with one-time recovery codes. The second factor is enforced on the server, on every plan.
Exporting your data
A JSON archive of your whole account, from Settings or the account menu. No paywall, on any plan, and re-importable.
How do you handle our data?
Encrypted, with row-level security on every table.