Privacy policy
This privacy policy explains which personal data we process when you visit or use TIO.
1. Controller and contact
The controller is Andreas Siemer, Sanddornweg 11, 59071 Hamm, Germany. You can send privacy inquiries to info@tio.do. Additional contact details are available in the imprint.
2. Scope and local processing
This policy covers the TIO website and web app, including its installed PWA version. Local task planning does not require a TIO account.
Tasks, notes, dates, tags, recurring tasks and settings are generally processed on your device. TIO does not operate a central task server for these contents. Enabled integrations, external content and messages you send can transfer data to others, as explained below.
3. Website delivery and connection data
When you access the website or app, check for updates or test connectivity, the contacted server infrastructure receives technical data, particularly your IP address, request time, requested address and connection information sent by your browser. This supports delivery, troubleshooting and operational security.
The website and web app are hosted by OVHcloud. OVHcloud receives the connection data needed to deliver and operate the service. These checks do not transmit task or note contents. Information on data protection at OVHcloud: https://www.ovhcloud.com/en/terms-and-conditions/privacy-policy/
4. Device storage, cookies and offline use
TIO uses Local Storage for planning data, settings, calendar information and some authentication tokens. Session Storage holds temporary authentication information; IndexedDB may store a file handle for a selected local calendar file. Service workers and browser caches store app files for offline use.
The application itself uses no analytics or advertising trackers or marketing cookies. Connected services may use their own cookies and storage technologies. Storage access strictly necessary for an explicitly requested function falls under section 25(2)(2) TDDDG; other access requires consent. Without necessary device storage, saving and offline use are unreliable.
5. Optional Dropbox synchronization
When you connect Dropbox, TIO uploads planning data to a file in your Dropbox account and reads it back. This includes tasks and notes, imported calendar entries and selected settings such as tags, automatic links, recurring timers, views and Google calendar selection.
Synchronization can run automatically after connection. Information about other people in imported events may therefore also be stored in Dropbox. The synchronization file is compressed; this is not end-to-end encryption.
You sign in with Dropbox. TIO keeps the tokens needed for the connection on your device. Disconnect in TIO and, if necessary, revoke the app permission in your Dropbox account. Disconnecting does not delete previously uploaded files or their versions. More information: https://www.dropbox.com/privacy
5a. Optional Google Drive synchronization
As an alternative to Dropbox, you can connect Google Drive. Only one synchronization provider is active at a time. TIO stores the same planning data, including imported events, in a compressed file in the private application data folder of your Google account. This folder is not visible in the normal Drive file list. TIO requests access only to this application data folder, not your other Drive files.
You sign in with Google. The access token is stored on your device; reconnection is required after it expires. Compression is not end-to-end encryption. TIO can restore available file versions; their retention depends on Google Drive. Disconnecting or switching providers does not delete cloud files. You can manage application data and permissions in your Google account. More information: https://policies.google.com/privacy
6. Google Calendar and Microsoft 365
After authorization, the optional calendar integrations retrieve calendar and event data and profile information needed for account display directly from Google or Microsoft. Depending on the event, this may include titles, times, descriptions, locations, organizers and attendees. Requested calendar permissions provide read access; TIO does not write events to the source calendars through these integrations.
Imported events are processed locally and may become part of your Dropbox or Google Drive file when synchronization is enabled. Connected calendars may refresh automatically. Google access tokens are stored locally; Microsoft authentication uses Session Storage in particular.
You can disconnect in TIO and revoke authorization with the provider. Previously imported data and backups must be deleted separately. The providers’ privacy notices also apply: https://policies.google.com/privacy and https://privacy.microsoft.com/privacystatement
TIO’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy. Google data is used for the calendar and synchronization features you enable, not for advertising or training general-purpose AI models. If cloud synchronization is enabled, imported Google events are stored with your selected provider, Dropbox or Google Drive, as part of your planning data.
7. External scripts and content
For Google features, TIO loads libraries from apis.google.com and accounts.google.com. The Microsoft integration loads its authentication library from alcdn.msauth.net, with jsDelivr or unpkg as fallback sources if loading fails. The optional mobile debug console loads a script from unpkg.com. Loading these resources already transmits your IP address and technical request data to the source, even before sign-in is completed.
If your Markdown notes contain external images, displaying them may connect directly to the image provider. Opening external links sends connection data to the destination. Further processing depends on those services and their privacy notices.
8. Local files and notifications
Imported task and calendar files are read on your device. In supported browsers, TIO can repeatedly read a selected calendar file using the file permission you grant. Imported events may then be synchronized like other planning data. Export files are stored in your chosen location and may contain personal data.
If you allow notifications, TIO passes reminder contents to your browser or operating system. Task titles may appear on the lock screen depending on device settings. You can change permissions in browser or system settings.
9. Feedback and communication
When you email info@tio.do, we process your sender address, message and any contents you include to handle your inquiry. The feedback feature opens an email draft containing the TIO version and settings that differ from defaults. Review these details before sending; you send the message yourself through your email application.
Messages are processed through the email providers involved. Only include information needed for your inquiry and remove confidential data from descriptions or attachments.
10. Legal bases and international processing
Requested functions rely on Article 6(1)(b) GDPR. Operational security and general inquiries rely on Article 6(1)(f), with secure operation and responding to inquiries as our interests. Where consent is required, Article 6(1)(a) applies.
Dropbox, Google, Microsoft and external script sources may process data outside the European Economic Area, particularly in the USA. Google, Microsoft and Dropbox state in their privacy information that they participate in the EU-US Data Privacy Framework. Transfers to appropriately certified US companies are covered by the European Commission’s adequacy decision under Article 45 GDPR. For other transfers, the providers refer in particular to standard contractual clauses under Article 46 GDPR. These statements do not automatically apply to arbitrary external image or script providers.
Details about transfer mechanisms and obtaining copies of safeguards are available from Google at https://policies.google.com/privacy/frameworks, Microsoft at https://privacy.microsoft.com/privacystatement and Dropbox at https://www.dropbox.com/privacy. The contractual arrangements for your connected account depend on the service and, where relevant, your organization’s account.
11. Retention, deletion and security
Local planning data remains until you delete it or your browser or operating system removes it. Temporary session data may be removed when a browser session ends. Where needed, also remove website data, offline caches, file permissions and downloaded exports.
Deleting local data does not remove Dropbox or Google Drive files, source calendars or emails. Disconnect active synchronization before a complete cleanup to prevent data from being imported again. Copies held by third parties follow their deletion and retention procedures.
We retain inquiries as long as needed to handle them, subject to statutory retention obligations. Technical logs must be limited to the period necessary for operation and security.
Web connections to tio.do and integrated APIs use HTTPS. Local data and exports are not generally encrypted. Local token encryption does not replace device protection because its key is also stored on the device. Secure your device and consider any backups made by your operating system.
12. Your rights
Subject to GDPR conditions, you have rights of access, rectification, erasure, restriction and portability. You may withdraw consent prospectively and object to legitimate-interest processing on grounds relating to your situation.
You may complain to a supervisory authority, particularly where you live, work or suspect an infringement. Contact info@tio.do for privacy requests. We cannot directly access data stored solely on your device.
TIO makes no automated decisions with legal or similarly significant effects.
13. Changes
We update this policy when the application or its data processing changes. The date above indicates the revision of this version.
Do you have questions about privacy or want to share feedback? Send us a message via the imprint or directly from the app.