Just Todo ItJust Todo It

Privacy policy

In short

Just Todo It is a to-do app. Your tasks are yours, and this page says exactly what happens to your data: what we keep, why, for how long, and who else sees it. There is not a single advert in the app, we do not track you across other sites, and we sell nothing on.

Last updated: 3 September 2026.

Who is responsible

Fliksemblits, based in the Netherlands, is the data controller for everything Just Todo It processes (the web app on todo.fliksemblits.com and the mobile apps).

Questions, requests or complaints about your data: info@fliksemblits.nl.

What we store

KindWhat it isWhy it exists
AccountName, email address, password (as a hash only), language, time zone, and a profile picture if you add oneNo account means no personal task list, and the time zone decides what "today" is
SecurityTwo-factor secret and backup codes if you turn them on, passkeys (the public key only)Protecting your account
Your contentTasks, notes, subtasks, lists, areas, headings, tags, dates and times, repeats, reminders, and the activity log of your own changesThat is the app
AttachmentsThe images and PDFs you hang on a task yourself, with their name, type and sizeSo a task can hold what belongs to it
PlacesThe places you set up yourself for location reminders: name, coordinates and radiusSo your phone can remind you of a task when you arrive there or leave
SessionsSession token, timestamp, IP address, and the description of your browser or deviceStaying signed in, and being able to see which devices have access
NotificationsA push token per device (mobile) or a push endpoint with keys (browser), plus the device nameA reminder can only arrive if we know where to send it
ImportThe CSV file you upload yourself to move tasks overYou see the analysis first and confirm afterwards
PaymentYour Stripe customer number and the state of your subscriptionPremium on or off. Your card details go straight to Stripe and never reach us
TechnicalServer log lines: timestamp, request path, error codeTracking down failures. If you report an error code, we can find it

Where you are never reaches us. When you turn on location reminders, the app on your phone asks for location access, also in the background. Your phone then keeps track itself of whether you arrive at or leave one of your places, and shows the reminder itself. Your location is not sent to our server and is not stored anywhere; we only know the places you set up yourself.

We do not read your contacts, and have no access to your calendar, camera or files beyond what you upload yourself.

Why we are allowed to process them

  • Performance of the contract. Account, content, sessions, notifications and payment status are needed to deliver the app you signed up for.
  • Legitimate interest. Server logs and abuse protection (limits on sign-in attempts and on upload size) keep the service running and safe.
  • Consent. You only get push notifications after granting permission in your operating system, and you can switch them off again in the app. The same goes for location access on your phone: the app only asks for it when you turn on location reminders, and you switch it off again in the app or on your phone.
  • Legal obligation. Payment data belonging to an invoice is kept for as long as tax law requires.

Who else sees them

Only parties needed to run the app. They may use your data for that task alone.

PartyWhat forWhere
Hetzner Online GmbHThe server and database the app runs onGermany (EU)
LettermintEmail the app sends: verification, password reset, reminders by mailEU
StripePayments and subscriptions, if you go premiumEU and US, under the European Commission's standard contractual clauses
Google (Firebase Cloud Messaging)The delivery path of a push notification on AndroidEU and US
Expo (EAS)Passing push notifications on to Android, and fetching app updates: on launch the app asks Expo whether new app code is ready. That request carries the app version, the platform and a random install identifier, no account dataEU and US
Apple (APNs)The same, for iOS once that app existsEU and US

Our realtime server and our log server run on our own machine; no third party is involved there.

When you create a task that is only a web address, our server requests that one page once to read its title. That website sees the address and our server, not you or your account.

When you search for an address for a place on the website, our server passes your search on to the address search of the Dutch government (PDOK). PDOK sees the search and our server, not you or your account. When you search in the app on your phone, it uses your phone's own address search: on Android that is a Google service, on iOS an Apple one.

How long we keep them

DataTerm
Account and contentUntil you delete your account
Trash30 days, then gone for good
Sent reminders30 days
Expired sessionsA week after expiry
Verification and reset linksA day after expiry
Uploaded import filesAt most a day if you never finish the import
Uploaded attachmentsUntil you remove them; if the task goes to the Trash, until that is emptied
Server logsThe retention of our log server, and they contain no task content

Deleting your account and your data

You can close your account yourself, without asking us:

  1. Open Settings in the web app at todo.fliksemblits.com. In the mobile app, Settings has a button that takes you to the same page.
  2. Go to the Danger zone at the bottom.
  3. Type your email address and your password to confirm, and choose delete account permanently. You get a confirmation by email afterwards.

What happens then: your tasks, lists, areas, headings, tags, reminders, sessions, passkeys, push registrations, profile picture and account details are deleted. This is permanent and cannot be undone.

What stays for a while: backups run until they expire, and data belonging to a payment is kept for as long as tax law requires. Server logs disappear with their own retention.

Stuck, or would you rather request a copy of your data than delete it? Email info@fliksemblits.nl from your account address and we will handle it within 30 days.

Security

Traffic runs over HTTPS. Passwords are stored as a hash only, never readable. You can turn on two-factor authentication and passkeys. Sessions expire and you can revoke them yourself. If you sign in from a device we have no earlier sign-in from, we send you an email with the device, the time and the IP address of that sign-in. Server access is limited to the maintainer.

Your rights

You have the right to access, correct, delete, restrict, object to and port your data. Email info@fliksemblits.nl from your account address. If you disagree with how we handle it, you can complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in your own country.

Children

The app is not aimed at children under 16 and we do not knowingly collect their data. If you think that happened anyway, email us and we will delete the account.

Changes

If something material changes about what we process, we update this page and put the new date at the top. For a far-reaching change you will hear from us in the app or by email.