Legal

Privacy Policy

1. Who we are

gtd_done is a task and calendar application operated by Lincolne Ventures Limited, registered at 55 Melrose Avenue, London, England, SW19 8BU. This policy covers the website at gtd-done.com, the application, the public booking pages, and the email addresses the app accepts mail on.

For privacy questions, write to privacy@gtd-done.com. We are the data controller for the personal data described here.

2. What we collect

Account data

Your name, email address and password. Our authentication provider stores the password as a hash. We never see it. We also record your plan, your trial dates and the date you signed up.

Task and project content

Everything you type into the app. Task titles, notes, initiatives, sizes, energy levels, due dates, priorities and your completion history. Notes support Markdown and we store them as you wrote them.

Files you attach

Files you upload to a task or initiative, and files that arrive as attachments on inbound email, are stored with our backend host. Attachments are limited to 10 MB per file. We do not open, scan or index the contents beyond storing the file and its name, type and size.

Inbound email

Each task and initiative can have its own address on inbound.gtd-done.com. When you email one of those addresses, the message body becomes a note on that object and the attachments are stored against it. The sender address is checked against your account before anything is written. Mail that fails the check is dropped.

Calendar links

When gtd_done schedules a task, we store the Google Calendar event ID against that task so the two stay linked. We store the ID, not the event.

Timezone sync history

When you confirm a timezone sync, we record each calendar we touched. That record holds the Google account email, the calendar ID, the calendar name, the timezone before the change, the timezone after it, whether the write succeeded, and the time. The record exists so you can undo the change and so you can see what happened.

Booking submissions

Your booking links are public. Anyone holding the link can submit a name, an email address, an optional note and, where you allow it, the email addresses of other guests. We keep a record of each booking so they can move or cancel it themselves. That record holds the visitor's name and email, the time, and the calendar event ID. See section 5.

Sharing and collaboration records

If you share your free/busy with another gtd_done user, invite someone to a workspace, add a delegate, or invite someone to a shared booking link, we store that relationship and the email address you entered.

Connected Basecamp accounts

Basecamp is optional and does nothing unless you connect your own Basecamp account. If you do, we store the Basecamp account and API address, the project and schedule you chose, and the access tokens that let us act there. We also keep a record of each Basecamp entry we have already imported, so nothing is imported twice. That record holds its Basecamp id and project, the meeting's start and end time, and the task and calendar event we created from it. Disconnecting Basecamp deletes the connection and its tokens.

Analytics and server logs

Our analytics provider records product analytics and session replays, as described in section 7. Our host and our database provider keep standard server logs, which include IP addresses, for security and debugging.

3. Why we process it

We process account data, task content, files and calendar links to run the service you signed up for. The legal basis is performance of a contract.

We process analytics, session replays and server logs to keep the service running, to debug faults, and to answer your support questions with an accurate picture of what happened. The legal basis is legitimate interest, balanced against the masking described in section 7.

We process booking submissions to create the meeting the visitor asked for, and to let them move or cancel it afterwards. The legal basis is legitimate interest, and the visitor supplies the data knowing what it is for.

We process Google data only for the purposes in section 4, and only after you grant consent on Google's own screen.

4. Google user data

When you connect your Google account, gtd_done requests access to the following Google data. Google's consent screen shows you exactly what is being requested, and you can decline or revoke at any time.

Calendar events — calendar.events

We read your calendar events so gtd_done can show your day and week. We create calendar events when you schedule a task, and update or delete those events when you reschedule or remove the task. We store the Google Calendar event ID against the task in our database so the two stay linked. We do not store the contents of your calendar events on our servers. We do not create, delete or rename your calendars.

Availability — calendar.freebusy

We query your free/busy information to find open time when auto-scheduling a task, and to show real availability on your booking links. Free/busy returns only when you are busy, with no event titles, attendees or details, and we do not store it.

Contacts — contacts.readonly — and Other contacts — contacts.other.readonly

We read your contacts, and the "Other contacts" Google records from people you have corresponded with, for one purpose. They populate the participant autocomplete when you add people to a meeting or task. This data is requested from Google at the moment you type in the participant field, held only in temporary memory for the duration of that request, and is never written to our database, never exported, never shared with third parties, and never used for marketing, outreach, profiling or contact enrichment.

Your calendar list — calendar.calendarlist.readonly

When you open the timezone sync screen, we list the calendars on your connected Google accounts so you can choose which to update, and so we can show each calendar's current timezone. We only offer calendars you own. Calendars other people have shared with you are not listed and cannot be changed by gtd_done.

Calendar timezone — calendar.calendars

When you explicitly confirm a timezone sync, we write the timeZone property on the calendars you selected. That is the only calendar property gtd_done ever writes. We record the previous timezone of each calendar so you can undo the change. That record contains the calendar's ID, name, and the before and after timezone values. Nothing happens without your confirmation, and you choose which calendars are included.

Account identifiers — openid, email

We store your Google account email address and the OAuth tokens that let gtd_done act on your behalf. We do not request access to Gmail, Google Drive, or any other Google service.

Connected Basecamp accounts — optional, off unless you connect it

Basecamp is a separate integration that does nothing at all unless you connect your own Basecamp account and turn it on. If you have not, none of what follows happens and no Google data of yours reaches Basecamp.

With the availability mirror switched on, gtd_done writes your busy blocks into the Basecamp schedule you chose, so your team can see when you are unavailable. Only the start and end time of each block is sent. Those times come from Google free/busy, which returns no event detail in the first place. Each Basecamp entry carries your gtd_done display name and a fixed note saying the details live in gtd_done. No event title, description, location, attendee, meeting link or contact from your Google Calendar is ever sent to Basecamp.

The import runs in the other direction. Basecamp schedule entries you are on become tasks in gtd_done and events on your own Google Calendar. We deliberately do not copy the Basecamp participant list into the Google event, so gtd_done never invites anybody on your behalf. Turning the mirror off, or disconnecting Basecamp, stops both.

Sharing

We do not sell Google user data. We do not share it with third parties, with one exception that you switch on or off yourself. If you connect Basecamp and turn on the availability mirror, the start and end times of your busy blocks go to your own Basecamp account, as described above. Google user data is not used to train any machine learning or AI model.

Retention and deletion

Disconnecting your Google account in gtd_done Settings revokes our access with Google and deletes the stored tokens and account record. Deleting your gtd_done account removes all associated data. Calendar events gtd_done created remain in your own Google Calendar and are yours to keep or delete.

AI and machine learning

gtd_done does not use artificial intelligence or machine learning models, and it integrates with no third-party AI or ML service. No data received from Google APIs, whether raw, aggregated, anonymised or derived, is transferred to any AI or ML provider, or used to create, train or improve any model. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

Limited Use

gtd_done's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data about people who are not users

Three parts of gtd_done handle personal data belonging to people who never signed up.

Booking links

A visitor booking time with you supplies their name, their email address, an optional note of up to 2,000 characters, and any guest email addresses you permit. We pass all of it to Google Calendar as the event you and they now share, and Google emails the invitation to everyone on it. An automated-abuse check runs on the booking form before the submission reaches us.

We keep a short record of the booking itself so the visitor can change or cancel it without going through you. That record holds their name and email address, the meeting time and length, and the Google Calendar event ID. The note they wrote and any guest addresses are not kept. Those go to Google only. The link they manage the booking with is stored as a one-way hash, so the record cannot be used to reach their booking. Google Calendar remains the authoritative copy of the meeting. We re-read it from Google whenever the visitor opens their booking. We keep the record while the meeting stands, and it goes when you delete the booking link or your account.

Meeting participants

Email addresses you pick in the participant field are written to the Google Calendar event as attendees. Google then sends those people an invitation. Add someone to a meeting and they will hear about it from Google.

Invitations

Inviting someone to a workspace, a shared booking link, or an account stores the email address you entered and sends mail to it. We keep the address until the invitation is used or you delete it.

If you are one of these people and you want your data removed, write to privacy@gtd-done.com.

6. Processors and third parties

We do not sell personal data. We share it only with the providers that run the service, in these categories:

We will tell you which companies these are, and where each one is established, if you ask at privacy@gtd-done.com.

7. Cookies and analytics

We set a cookie to keep you signed in. Removing it signs you out. We use no advertising cookies and run no advertising trackers.

If you are in the UK or the EU, we ask before any analytics run. Analytics start switched off, set no cookie and send nothing until you accept, and you choose usage analytics and session replay separately. Declining leaves both off. Change your mind at any time from the Cookies link in the site footer, or under Settings, Account. Outside the UK and EU, analytics run by default and the same controls turn them off.

We use analytics and monitoring tools to improve performance and to support users. They measure which parts of the app get used, which is how we find and fix faults and answer your support questions accurately. When you report a problem, your own session shows us what happened rather than leaving us to guess at it. Our analytics provider runs on infrastructure inside the EU. Our configuration masks the text and attributes of every element it captures, so the words in your tasks stay in your browser and never reach the provider. Our authentication provider puts access and recovery tokens in the URL, and we strip those from every event property before it is sent.

Our analytics provider also records session replays. A replay reconstructs the shape of the page along with your clicks, scrolling and movement through the app. Every element of text and every form input is masked in your browser before the recording is sent, so your task titles, your notes and anything you type are blanked out and never reach the provider. What a replay shows is where you clicked, not what you wrote.

Replays are linked to your account. We identify you to the provider by your user ID and email address so we can find your sessions when you report a problem, which is what makes the support use above work. A replay is therefore not anonymous, even though its contents are masked. Replays are stored on infrastructure inside the EU and age out on the provider's retention schedule. Ask us at privacy@gtd-done.com and we will delete yours.

This page and the terms page load no analytics at all.

8. Retention and deletion

We keep your account data and content for as long as your account exists. Delete a task, a note or a file in the app and it goes from the database.

Disconnecting a Google account deletes the stored tokens and the account record, and revokes our access at Google. Deleting your gtd_done account removes your profile, tasks, notes, files, booking links, booking records, sharing records and timezone sync history. Server logs at our providers age out on their own schedules. Ask for deletion at privacy@gtd-done.com and we will action it within 30 days.

9. Security

Traffic runs over TLS. The database enforces Row Level Security, so every query is scoped to the authenticated user and a user cannot read another user's rows. Backend functions validate input at the boundary and check that the caller has rights on the object before writing. Files live in private storage buckets and are served through short-lived signed URLs. Passwords are hashed by our authentication provider.

Google OAuth tokens are stored in our database as ordinary text columns, protected by access controls and Row Level Security rather than by encryption at rest. We are stating this plainly because it is true today. When we encrypt those columns, we will update this page and say so.

No system is perfectly secure. If you find a vulnerability, write to privacy@gtd-done.com.

10. Your rights

You can read and correct most of your data inside the app. Beyond that you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to processing we base on legitimate interest. Where processing rests on consent, you can withdraw it, and disconnecting Google in Settings does exactly that.

Write to privacy@gtd-done.com to exercise any of these. We answer within 30 days. If you are unhappy with our answer, you can complain to your data protection authority. In the UK that is the Information Commissioner's Office at ico.org.uk.

11. Children

gtd_done is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has an account, write to privacy@gtd-done.com and we will delete it.

12. International transfers

Our providers operate across several countries, so your data may be processed outside the country you live in. Where we transfer personal data out of the UK or EEA, we rely on the receiving provider's Standard Contractual Clauses or an adequacy decision. Our analytics provider processes data inside the EU.

13. Changes to this policy

We update this page when the app changes what it does with data. The effective date at the top shows the current version. For changes that affect how we use your data, we will email you before they take effect.

14. Contact

Privacy: privacy@gtd-done.com
Support: support@gtd-done.com
Post: Lincolne Ventures Limited, 55 Melrose Avenue, London, England, SW19 8BU