Todo Privacy Policy
Last updated 7 October 2026.
Todo is a to-do app for iPhone, published by Nucleus. It can be used without an account, in which case it transmits no data to Nucleus except a problem report that you choose to submit. If you choose to sign in with Nucleus ID, your tasks and lists are synchronised with your account.
- Without an account, your lists, tasks and settings are stored on your device only and are never transmitted to Nucleus.
- Signing in with Nucleus ID is optional. If you sign in, your tasks and lists are stored in your account so that your devices remain synchronised.
- Your device’s location is watched by iOS only, to remind you when you arrive at or leave a place. A place you attach to a task is part of that task: it stays on the device, and is synchronised with your account only if you sign in.
- Todo contains no analytics, advertising, tracking or third-party components.
- Backups you export are saved only to the location you choose and are never transmitted to Nucleus.
- A problem report is transmitted only when you compose and submit it yourself.
- Todo is published by Nucleus, operated by Jan Kocanda, Czech Republic, who is the data controller. Enquiries: [email protected].
Data on your device
Your lists, tasks, subtasks, tags, reminders, focus sessions, statistics and settings are stored on your device. Widgets, Siri and Shortcuts read the same data on the device.
If you enable the app lock, Face ID is handled by iOS. Todo receives only the result of the check and never your biometric data.
A backup you export is a file containing your lists and tasks. It is saved only to the location you choose, and is not transmitted to Nucleus.
Nucleus ID and synchronisation
If you sign in with Nucleus ID, Todo receives your handle and display name, and stores your tasks and lists in your account on our server in the Czech Republic, so that every device you sign in on has the same data.
Nothing else is transmitted. Todo does not receive your email address. You may sign out, disconnect Todo or delete the data it stored at any time, and its access ends accordingly.
Your Nucleus ID itself is covered by the Nucleus privacy policy. You may delete your account and all data stored with it on this page.
Legal basis: performance of the service you requested (GDPR Art. 6(1)(b)).
Location
Todo requests access to your location only if you add a reminder for a place or use your current location for one. The places you choose are registered with iOS, which notifies Todo when you arrive at or leave one. Todo does not record where you are or where you have been.
A place attached to a task (its name, address and coordinates, including a place set from your current location at that moment) is stored with the task. If you sign in with Nucleus ID, it is synchronised with your account like the rest of the task. It is never transmitted to anyone else.
When you search for a place, or pin one on the map, Apple Maps looks up the place or its address, and the query or coordinates are sent to Apple under its own privacy policy. Todo transmits no other data to Apple.
Problem reports
A report can be submitted from Settings → Report a problem, or by shaking the device (this can be disabled). No report is transmitted until you select Send.
A report contains the title and description you enter, any screenshots you attach, an email address if you provide one, and the app version, device model, iOS version and language. Todo includes no other data. In particular, none of your lists or tasks are included.
Screenshots may display your tasks or other personal details. You are responsible for reviewing them before attaching them to a report.
Reports are stored on our server in the Czech Republic and are accessible only to the Nucleus team. They are used solely to investigate the reported problem and to reply to you. They are not sent by email, disclosed to third parties or used for any other purpose, and are deleted automatically after 6 months.
Legal basis: our legitimate interest in resolving reported problems and responding to you (GDPR Art. 6(1)(f)).