Privacy Policy

Last Updated: November 22, 2025

Introduction

AT Todo (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we handle your information when you use our decentralized todo application.

The Short Version

What is AT Protocol?

AT Todo is built on the AT Protocol (the protocol behind Bluesky), which means:

Data Storage

Data Stored in Your AT Protocol Repository

The following data is stored in your personal AT Protocol repository, not on AT Todo servers:

Important: Per the AT Protocol specification, this data is stored as public records. Anyone with your AT Protocol DID can access this data through AT Protocol APIs.

Data Stored on AT Todo Servers

We store minimal data on our servers to provide the service:

We do not store: - Your password (authentication is handled by your AT Protocol provider) - The content of your tasks or lists - Your browsing history - Any tracking or analytics data

How We Use Your Information

We use your information solely to:

  1. Provide the service - Read and write tasks/lists to your AT Protocol repository
  2. Send notifications - Deliver push notifications about due tasks (if you enable them)
  3. Process payments - Handle Gold Star subscriptions (via Stripe)
  4. Communicate with supporters - Send subscription-related emails only

We never: - Sell your data to third parties - Use your data for advertising - Track you across other websites - Share your data except as required by law

Third-Party Services

AT Todo uses the following third-party services:

AT Protocol Network

Stripe (Payment Processing)

Web Push Services

Cookies and Local Storage

We use:

We do not use: - Tracking cookies - Third-party advertising cookies - Analytics cookies

Your Rights

Because your data lives in your AT Protocol repository, you have complete control:

To delete your AT Todo account: 1. Delete all tasks and lists in the app (or via AT Protocol APIs) 2. Disable push notifications in Settings 3. Revoke AT Todo’s OAuth access in your AT Protocol provider’s settings

Data Security

We take security seriously:

Children’s Privacy

AT Todo is not directed to children under 13. We do not knowingly collect information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

International Users

AT Todo is operated from the United States. If you access AT Todo from outside the US, your data may be transferred to and processed in the US. By using AT Todo, you consent to this transfer.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by: - Updating the “Last Updated” date at the top of this policy - Posting a notice in the app (for material changes)

Continued use of AT Todo after changes constitutes acceptance of the updated policy.

Data Retention

Your AT Protocol Repository is Public

Important: The AT Protocol specification defines repository records as public by default. This means:

Contact Us

If you have questions about this Privacy Policy or how we handle your data:

Open Source

AT Todo is open source. You can review our code to see exactly how we handle your data:


Summary: We store your tasks in your AT Protocol repository (public by default), keep minimal data on our servers (push subscriptions, supporter status), and never sell or track your data. You own and control everything.