1. Scope
This policy applies to the Nook Todo apps for iOS and Android and the official website at nooktodo.com.
2. App data
Tasks, categories, display names, completion history, settings and attachments are stored on the user’s device. Data shared within a household group is encrypted and synchronised between participating devices. We do not operate a central database that stores task content or names.
3. Accounts and identifiers
Nook Todo does not require an email address, phone number or third-party login. Cryptographic keys generated on the device identify the user and device.
4. Invitation links
The secret required to join a group is stored in the URL fragment after #. Standard HTTPS requests do not send that fragment to the web server. The invitation page does not display or store the group name, task content or secret.
5. Notification relay
To deliver remote notifications, Nook Todo uses a device token, an irreversible hash of the group ID, an event ID and encrypted notification data. The device token and group ID hash remain stored by the notification relay while the device is registered to receive notifications. Task content and names are encrypted on the device and are not received by the notification relay in plain text.
6. In-app purchases
When you purchase or restore the one-time upgrade, Nook Todo sends purchase proof and an irreversible identifier derived from the group ID to the purchase verification service. The proof is checked with Apple or Google, and a group-specific license is issued from the result. The purchase verification service does not retain the purchase proof or issued license.
7. Website
This website does not use advertising cookies, analytics SDKs or fingerprinting. Cloudflare may temporarily process technical information such as IP address, User-Agent and access time to provide hosting and security.
8. Sale and disclosure
We do not sell user data. We disclose user data only where needed to deliver notifications, verify purchases or comply with applicable law. Task content and names are not sent to notification providers or store operators in plain text.
9. Deleting data
You can remove locally stored data by leaving the app group and deleting app data from the device. Shared data already synchronised to another participant’s device may remain on that device. A notification device token is removed from the relay when the device leaves the group or when the notification provider reports that the token is invalid.
10. Children
Nook Todo is not directed at children and does not intentionally collect children’s personal information.
11. Changes
We may update this policy as the product or applicable law changes. Material changes will be announced on this page or in the app.
12. Contact
For questions about Nook Todo or this policy, contact [email protected].