Legal

Privacy Policy

Last updated: August 22, 2026

Short Version

ToDidIt is built and operated by Andpixels LLC (doing business as &Pixels), based in Austin, Texas. We collect only what we need to run a task manager: your email, your tasks, and your projects. Your data is stored on Supabase, scoped to your account by row-level security. We use a small set of analytics tools to understand how the product is used, and we give you clear controls to turn them off. We do not sell or share your personal information. You can export or delete everything you have created at any time. This summary is provided for convenience; the binding terms are in the full sections below.

1. Who We Are

ToDidIt is a product of Andpixels LLC, doing business as &Pixels (“we,” “us,” or “our”).

Andpixels LLC
5900 Balcones Drive, Ste. 165
Austin, TX 78731
United States

For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR, Andpixels LLC is the data controller responsible for your personal data.

2. What We Collect

We collect only the information necessary to provide and improve ToDidIt. Here is what that includes and where it comes from.

2.1 Information You Provide

  • Account information: the email address you use to create or log into your account, plus your display name and avatar URL if you sign up or log in with Google.
  • Content you create: projects, tasks, and their associated metadata, including names, descriptions, due dates, priorities, and phases.
  • Billing information: if you purchase a paid plan, we collect your name and billing address. Payment card details are collected and processed directly by Stripe; they are never transmitted to or stored on our servers. Stripe provides us with a truncated card number (last four digits), card brand, expiration date, and billing postal code for your records.
  • Connected integrations: if you connect Slack, we store an encrypted access token for your Slack workspace, your Slack workspace and user IDs, and the email address on your Slack profile so we can match it to your ToDidIt account. Disconnecting Slack removes all stored Slack data.
  • Push notification subscriptions: if you enable push notifications, we store the endpoint your browser provides and the encryption keys needed to send messages to that device. Disabling push notifications deletes this data.
  • Calendar feed links: if you create a calendar subscribe link, we store the secret token that makes it work. Anyone holding that link can read the tasks it exposes. The link is unlisted and revocable at any time from your account settings.
  • Passkey credentials: if you register a passkey, we store the public key credential and a credential identifier generated during registration. See Section 7.3 for details.

2.2 Information Collected Automatically

  • Usage data: pages viewed, actions taken within the product, and standard server log data, including your IP address, browser user agent, and request timestamps.
  • Device information: browser type, operating system, screen resolution, and language preference.
  • Cookies and similar technologies: see Section 4.

3. How We Use Your Information

We use the information we collect for the purposes described below. Where the GDPR applies, we have identified the legal basis for each purpose.

3.1 Provide and Operate ToDidIt

Authenticate your account, store and display your tasks and projects, process payments for paid plans, deliver push notifications you have enabled, and process your connected integrations.

Legal basis (GDPR): performance of our contract with you (Article 6(1)(b)).

3.2 Improve the Product

Analyze usage patterns, identify and fix bugs, and evaluate potential new features.

Legal basis (GDPR): legitimate interest in improving our service (Article 6(1)(f)). You may object at any time; see Section 13.

3.3 Communicate With You: Transactional

Send login codes, account-related notices, security alerts, and service updates necessary to operate your account.

Legal basis (GDPR): performance of our contract with you (Article 6(1)(b)); legitimate interest in keeping you informed about your account (Article 6(1)(f)).

3.4 Communicate With You: Marketing

Send product announcements, feature updates, newsletters, and tips for using ToDidIt.

Legal basis (GDPR): consent (Article 6(1)(a)) for users in the EEA, UK, and Switzerland; legitimate interest with opt-out (Article 6(1)(f)) elsewhere. See Section 8 for how to opt out.

3.5 Maintain Security and Prevent Abuse

Monitor for unauthorized access, investigate suspicious activity, and enforce our Terms of Service.

Legal basis (GDPR): legitimate interest in protecting our service and users (Article 6(1)(f)).

3.6 Comply With Legal Obligations

Respond to lawful requests from public authorities and maintain records required by applicable law.

Legal basis (GDPR): legal obligation (Article 6(1)(c)).

We do not sell your personal information. We do not share your personal information with third parties for their own marketing purposes. We do not use your personal information for automated decision-making or profiling that produces legal or similarly significant effects.

4. Cookies and Similar Technologies

ToDidIt uses only first-party cookies. We do not place any third-party advertising cookies on the site.

4.1 Strictly Necessary and Functional Cookies

  • Auth session cookie: keeps you signed in. Duration: 400 days, renewed each time your session refreshes. Strictly necessary.
  • Theme preference cookie: remembers your light or dark mode choice. Duration: 1 year. Functional.
  • Analytics choice cookie: records whether you have accepted or declined analytics so we do not ask again. Duration: 1 year. Functional.

Because these cookies are strictly necessary or functional, they do not require consent under applicable law.

4.2 Analytics Cookies

Analytics cookies are set by the tools described in Section 5and load only in accordance with the consent rules described there. Duration varies by provider; see each provider’s cookie policy for details. Ahrefs Web Analytics sets no cookies.

5. Analytics

We use the following third-party analytics services to understand how ToDidIt is used and to improve the product:

  • Google Analytics 4: page views and aggregated usage metrics. Privacy policy: policies.google.com/privacy
  • Microsoft Clarity: session replays and heatmaps to identify usability problems. Clarity masks text typed into form fields before recording reaches us. Clarity loads only if you actively consent; it is never enabled by default. Privacy policy: privacy.microsoft.com/privacystatement
  • PostHog:product event tracking (for example, “project created” or “task completed”). Privacy policy: posthog.com/privacy
  • Ahrefs Web Analytics: page views and traffic sources. Ahrefs is cookieless: it sets no cookie and stores nothing on your device. Privacy policy: ahrefs.com/legal/privacy-policy

5.1 How Consent Works

Inside the European Economic Area, the United Kingdom, and Switzerland, no analytics tools load until you actively agree. Elsewhere, analytics load by default, and you may turn them off at any time using the control on any ToDidIt page or from your account settings. Your choice takes effect immediately; turning analytics off stops collection and removes analytics cookies.

Analytics on this site

Page views and basic usage are being measured. Turning this off stops it immediately and removes the cookies.

5.2 Global Privacy Control

We honor the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, analytics remain off without any action on your part. We do not rely on the older “Do Not Track” header, which browsers no longer send consistently.

6. Integrations

Integrations are activated only when you choose to connect them and apply only to the workspace you connect.

6.1 Slack

When you connect Slack, we read only the messages you explicitly act on, such as turning a message into a task or drafting a project from a thread. We post into channels you have subscribed to notifications. We do not passively read or store channel history.

Before posting to a channel, we verify that every human member of the channel is authorized to see the underlying task. If any member is not authorized, the post is skipped.

Disconnecting Slack removes all stored tokens and Slack-related data from your account.

6.2 Calendar Apps

The calendar subscribe feed is read-only and one-way. Calendar providers such as Google Calendar and Apple Calendar fetch the feed on their own schedule. Nothing they do writes data back to ToDidIt.

7. Authentication Providers

7.1 Google OAuth

When you create an account or log in with Google, we receive your email address, display name, and profile picture URL from Google’s OAuth response. We do not request or access any other Google data (such as your contacts, calendar, or Drive files).

7.2 Email Code

When you create an account or log in with email, we send an 8-digit verification code to the address you provide. That address is stored as your account identifier. The code is single-use, expires after a short period, and is not retained after use or expiration.

7.3 Passkeys

You may register a passkey (a FIDO2/WebAuthn credential) as a way to sign in without a password or code. When you register a passkey, your device generates a public-private key pair. We store only the public key and a credential identifier on our servers. The private key never leaves your device and is never accessible to us.

When you sign in with a passkey, your device uses the private key to sign a challenge we send. We verify the signature against the stored public key. No shared secret is transmitted during this process.

You can remove a registered passkey from your account settings at any time, which deletes the stored public key and credential identifier from our servers.

8. Marketing Communications

We may send you product announcements, feature updates, newsletters, and tips for using ToDidIt. In the EEA, UK, and Switzerland, we send marketing emails only with your prior consent. Elsewhere, we may send marketing emails based on our legitimate interest in keeping you informed about the product, subject to your right to opt out.

Every marketing email includes an unsubscribe link at the bottom. You can also manage your email preferences from your account settings at any time. Opting out of marketing does not affect transactional emails necessary to operate your account, such as login codes, security alerts, and account confirmations.

9. How We Share Your Information

We do not sell your personal information. We share it only in the following limited circumstances.

9.1 Service Providers

We use the following third-party service providers who process data on our behalf and under our instructions:

  • Supabase (hosted on AWS): database hosting and authentication. Processes account data and content you create.
  • Vercel: application hosting and deployment. Processes server logs and request data.
  • Stripe:payment processing. Processes billing information and payment card details for paid plans. Stripe’s privacy policy: stripe.com/privacy
  • MailerSend: transactional email delivery, including login codes, account notifications, and security alerts. Processes email addresses and message content. Privacy policy: mailersend.com/legal/privacy-policy
  • MailerLite: marketing email delivery, including newsletters and product announcements. Processes email addresses, subscription preferences, and engagement metrics (opens and clicks). Privacy policy: mailerlite.com/legal/privacy-policy
  • Google Analytics 4: usage analytics. Processes anonymized usage data and IP addresses.
  • Microsoft Clarity: session replay and heatmaps. Processes anonymized interaction data.
  • PostHog: product event analytics. Processes product event data.
  • Ahrefs: web analytics. Processes page view and referrer data.

Each provider is bound by a data processing agreement and may process your data only as necessary to provide their service to us.

9.2 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or enforceable governmental request, or where we believe in good faith that disclosure is reasonably necessary to protect our rights or property, your safety or the safety of others, investigate fraud, or respond to a lawful government request.

9.3 Business Transfers

If Andpixels LLC is involved in a merger, acquisition, reorganization, or sale of all or a portion of its assets, your personal information may be transferred as part of that transaction. We will notify you by email or by a prominent notice on ToDidIt before your information becomes subject to a different privacy policy.

9.4 With Your Consent

We may share your information in circumstances not described above if you give us your explicit consent to do so.

10. International Data Transfers

ToDidIt is operated from the United States. If you access ToDidIt from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.

For users in the European Economic Area, the United Kingdom, and Switzerland, we rely on the following safeguards for international transfers of personal data:

  • Standard Contractual Clauses (“SCCs”) approved by the European Commission, incorporated into our data processing agreements with sub-processors.
  • Where applicable, certification of our sub-processors under the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework.

If you would like more information about the specific safeguards applied to any transfer, contact us at todidit.com/contact.

11. Data Security

We implement technical and organizational measures designed to protect your personal information, including:

  • All data in transit between your browser and ToDidIt is encrypted using TLS (HTTPS).
  • Data at rest in our database is encrypted.
  • Row-level security policies on the database ensure that every query is scoped to the authenticated user. No account can read or write another account’s data.
  • Slack integration access tokens are encrypted at rest.
  • Payment card details are collected and processed by Stripe and never stored on our servers.
  • Passkey private keys never leave your device and are never transmitted to or stored on our servers.
  • Our infrastructure providers (Supabase on AWS, and Vercel) maintain SOC 2 Type II compliance.
  • Access to production systems is restricted to authorized personnel and protected by multi-factor authentication.

No method of electronic transmission or storage is completely secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security. If we become aware of a security breach that affects your personal data, we will notify you and any applicable regulatory authority in accordance with applicable law.

12. Data Retention

We retain your information only as long as necessary for the purposes described in this policy or as required by law.

  • Account and content data: retained for as long as your account exists.
  • Billing and transaction records: retained for as long as your account exists and for a reasonable period thereafter as required for tax, accounting, and legal compliance purposes.
  • Data following account deletion: permanently removed from production systems within 30 days of deletion. Backups containing deleted data are purged on their normal rotation cycle, not to exceed 90 days.
  • Server logs: retained for up to 90 days for operational and security purposes, then deleted.
  • Analytics data:governed by each analytics provider’s own retention settings.
  • Slack integration data: removed immediately when you disconnect the integration.
  • Push notification subscriptions: removed immediately when you turn off push notifications.
  • Passkey credentials: removed immediately when you delete the passkey from your account settings, or upon account deletion.

13. Your Rights

13.1 All Users

Regardless of where you are located, you may at any time:

  • Export your dataas a JSON file from the user menu (“Export Data”).
  • Delete a project from its settings page, which permanently deletes all tasks within that project.
  • Delete your account from your profile page. Deletion is immediate and permanent: it removes your workspaces, projects, tasks, comments, and any connected integrations, subject to the retention periods in Section 12.

13.2 Users in the European Economic Area, United Kingdom, and Switzerland

Under the GDPR and UK GDPR, you have the following additional rights with respect to your personal data:

  • Access: request confirmation of whether we process your personal data and, if so, a copy of it.
  • Rectification: ask us to correct inaccurate or incomplete personal data.
  • Erasure: ask us to delete your personal data where there is no compelling reason for continued processing.
  • Portability: receive the personal data you have provided to us in a structured, commonly used, machine-readable format, and transmit it to another controller.
  • Restriction: ask us to restrict processing of your personal data in certain circumstances (for example, while we verify its accuracy).
  • Objection: object to processing of your personal data based on legitimate interest, including for direct marketing purposes. Where you object to direct marketing, we will stop immediately.
  • Withdraw consent: where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us at todidit.com/contact. We will respond within 30 days, or within any shorter period required by applicable law. We may ask you to verify your identity before processing your request.

You also have the right to lodge a complaint with your local data protection supervisory authority.

13.3 California Residents

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), provides California residents with specific rights regarding their personal information.

  • Right to Know: you may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: you may request that we delete the personal information we have collected about you, subject to certain exceptions permitted by law.
  • Right to Correct: you may request that we correct inaccurate personal information we maintain about you.
  • Right to Opt Out of Sale or Sharing:we do not sell your personal information, and we do not “share” it (as that term is defined under the CCPA/CPRA) for cross-context behavioral advertising. There is nothing to opt out of.
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of your rights under the CCPA/CPRA.

Categories of personal information we collect, as defined by the CCPA:

  • Identifiers (email address, display name, IP address, device identifiers, Slack user ID).
  • Commercial information (billing name, billing address, transaction history, subscription plan).
  • Internet or other electronic network activity information (pages viewed, actions taken, server logs, analytics data).
  • Other information you create or provide (task content, project data, descriptions).

We collect these categories for the business purposes described in Section 3. We have not sold or shared personal information in the preceding 12 months. We do not use or disclose sensitive personal information for purposes beyond those permitted by the CCPA/CPRA.

To exercise any of these rights, contact us at todidit.com/contact. We will verify your identity before processing your request and respond within 45 days, or within any shorter period required by law. You may designate an authorized agent to submit a request on your behalf by providing us with the agent’s written authorization signed by you.

14. Children

ToDidIt is not directed at children under 13, or under 16 in the EEA and UK. We do not knowingly collect personal information from children under these ages. If you believe a child has created an account, contact us at todidit.com/contact and we will promptly delete the account and all associated data.

15. Changes to This Policy

When we update this policy, we will revise the “Last updated” date at the top. For material changes, we will notify active users by email at least 30 days before the changes take effect, unless the change is required by law, regulation, or court order, in which case it may take effect immediately. Continued use of ToDidIt after the effective date of a revised policy constitutes acceptance of the changes.

16. Contact Us

If you have questions about this privacy policy or how we handle your data, contact us at:

Andpixels LLC (dba &Pixels)
5900 Balcones Drive, Ste. 165
Austin, TX 78731
United States

todidit.com/contact