Privacy Policy

Last updated: May 16, 2026

This Privacy Policy explains how Dowiem Sp. z o.o. ("we", "us", or "our") collects, uses, and protects your personal data when you use Vector ToDo (the "Service"), available at vectortodo.com, app.vectortodo.com, and notes.vectortodo.com.

We are committed to protecting your privacy in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC, and the Google API Services User Data Policy (including the Limited Use requirements).

1. Data Controller

Dowiem Sp. z o.o.
ul. Zamknięta 10/1.5, 30-554 Kraków, Poland
NIP: 6793275343
KRS: 0001055145
Email: [email protected]

For any questions about this policy or to exercise your data protection rights, please contact us at the email address above.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Email address
  • Full name
  • Password (stored as a salted bcrypt hash, never in plaintext)
  • Timezone
  • Avatar URL (if provided)

2.2 User Content

Data you create while using the Service:

  • Tasks, projects, sections, labels, and areas
  • Notes (including collaborative editing state)
  • Boards and board elements
  • Task comments
  • File attachments (up to 50 MB per file)

2.3 Collaboration Data

When you collaborate with others:

  • Workspace and company memberships
  • User roles (owner, admin, member)
  • Task assignments
  • Invite codes

2.4 Corporate Module Data

If you use corporate features:

  • Calendar events and room bookings
  • Inventory items and bookings
  • Announcements
  • Spreadsheet tables and rows

2.5 Activity and Usage Data

  • Task activity logs (e.g., created, completed, assigned, priority changed) — used for productivity reports
  • Daily productivity snapshots (aggregate metrics)
  • API audit logs: IP address, user agent, operation name, timestamp — retained for 6 months

2.6 Push Notification Data

If you enable push notifications (with your explicit consent):

  • Web Push subscription details (VAPID endpoint URL, encryption keys)
  • Apple Push Notification service (APNs) tokens (iOS app)
  • Firebase Cloud Messaging (FCM) device tokens (Android app)

2.7 Marketing Communications Data

If you opt in to receive marketing emails, we keep an audit record of your choice:

  • Your email address (already part of your account data)
  • Your preferred language (locale)
  • The date and IP address recorded when you granted or withdrew consent
  • The version of the consent text you agreed to

Marketing emails are off by default. We only send them after you explicitly opt in. You can withdraw your consent at any time from Settings → Privacy & Marketing or by clicking the unsubscribe link in any promotional email. Transactional and security emails (account verification, password reset, billing) are not affected by this setting.

2.8 AI-Processed Data

If you enable AI features by providing your own API key:

  • Task titles, descriptions, and content — sent to your chosen AI provider for auto-tagging and insights
  • Voice recordings — sent for transcription (if you use the voice input feature)
  • AI-generated results (tags, insights, transcriptions) — stored in your account

AI features are disabled by default. Data is only sent to AI providers when you explicitly enable these features and provide your own API key. The AI provider you choose (Anthropic, OpenAI, or Google) processes your data under their own privacy policy.

2.9 Technical Data

  • IP address (recorded only in API audit logs)
  • Browser storage: localStorage and IndexedDB are used for offline functionality and user preferences

3. Google User Data (Google Calendar Integration)

If you choose to connect a Google account to Vector ToDo in order to see your Google Calendar events alongside your tasks, we access certain data from your Google account through Google APIs. This section explains exactly what we access, why, and how we use it — in compliance with the Google API Services User Data Policy, including the Limited Use requirements.

3.1 OAuth Scopes Requested

When you connect your Google account, we request the following scopes:

ScopeWhy we need it
openidTo identify your Google account during the OAuth flow.
emailTo display which Google account is connected and prevent duplicate connections.
profileTo show your Google account name and avatar in the connected-accounts list.
https://www.googleapis.com/auth/calendar.readonlyTo read your calendar list and events so they can be displayed inside Vector ToDo. This scope is read-only: we cannot modify, create, or delete any events in your Google Calendar.

3.2 What Google Data We Access

  • List of your calendars (calendar name, color, and ID) — so you can pick which calendars to display.
  • Events from calendars you choose (title, start/end time, location, description, attendees, recurrence) — to render them in the Vector ToDo calendar view and surface upcoming events next to your tasks.
  • Sync tokens and webhook channels — used to receive incremental updates from Google Calendar, so we don't repeatedly download the full event list.
  • Your Google account profile (email, name, avatar, Google "sub" identifier) — to identify the connected account.

3.3 How We Use Google Data

  • Display your selected Google Calendar events alongside Vector ToDo tasks in the user interface.
  • Help you avoid double-booking by showing when your time is committed.
  • Keep the event view up to date through Google's official sync and webhook mechanisms.

3.4 How We Do NOT Use Google Data (Limited Use Disclosure)

Vector ToDo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we do not:

  • Use Google user data for serving advertisements (including retargeting, personalized, or interest-based ads).
  • Sell Google user data to any third party.
  • Transfer Google user data to third parties for advertising, marketing, credit-worthiness, lending, or similar purposes.
  • Allow humans to read Google user data, except: (a) with your explicit consent for specific items, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) when the data has been aggregated and anonymized in a manner that prevents identification.
  • Use Google user data to train or improve generalized AI/ML models. The Vector ToDo AI features (if enabled by you) only process your own task content using API keys you provide, and do not consume Google Calendar data for AI processing.

3.5 Storage and Security of Google Data

  • Your Google refresh token is encrypted using AES-256-GCM before being stored, and is never sent back to the browser or any client application.
  • Calendar events are stored on our servers in the European Union only as a working cache, so the application can render them quickly and work offline. The cache mirrors what is currently in your Google Calendar.
  • All data in transit between your browser, our servers, and Google's servers is encrypted using TLS 1.2 or higher.
  • Access to the database is restricted via row-level security: only your own account can read your own Google data.

3.6 Revoking Access and Deleting Google Data

You can disconnect your Google account at any time. There are two equivalent ways:

  • Inside Vector ToDo: open Settings → Calendars → Connected Google accounts and click Disconnect. This immediately revokes our refresh token, stops all calendar webhooks, and deletes the cached events from our servers.
  • From your Google account: go to myaccount.google.com/permissions and remove access for "Vector ToDo". The next time we try to sync, we will detect the revocation and clean up the local copy.

Deleting your Vector ToDo account also revokes Google access and erases all associated Google Calendar data from our servers.

4. Legal Basis for Processing

We process your personal data on the following legal grounds under GDPR Article 6:

Legal BasisData CategoriesPurpose
Contract performance (Art. 6(1)(b))Account data, user content, collaboration data, corporate module dataProviding the task management service you signed up for
Legitimate interest (Art. 6(1)(f))Activity logs, audit logs, daily snapshotsSecurity, debugging, service reliability, and productivity insights
Consent (Art. 6(1)(a))Google Calendar data, push notification tokens, non-essential storage, AI-processed data, marketing communicationsDelivering integrations and optional features you explicitly enable

5. Data Sharing and Third Parties

We minimize third-party data sharing. We do not:

  • Sell your personal data
  • Use advertising trackers
  • Use third-party analytics services (no Google Analytics, no Mixpanel, etc.)

The following third-party services are involved in operating the Service:

ServicePurposeData Shared
Google APIs (Google Calendar)Read calendar events to display in Vector ToDo (only if you connect a Google account)Calendar list, events, profile (covered in Section 3)
Apple Push Notification serviceDelivering push notifications to iOS devicesDevice push token, notification payload
Firebase Cloud Messaging (Google)Delivering push notifications to Android and webDevice push token, notification payload
CloudflareCDN, SSL/TLS termination, DDoS protectionIP address and request metadata (in transit)
Anthropic / OpenAI / Google AI (user-configured)AI auto-tagging, insights, voice transcriptionTask content / voice recordings — only if you enable AI features with your own API key

6. International Data Transfers

Your data is primarily stored on servers located in the European Union.

Some data may be processed outside the EU by the third-party services listed above:

  • Google APIs / Firebase: Google may process data in the US. Transfer mechanism: EU Standard Contractual Clauses (SCCs) as part of Google's Data Processing Terms.
  • Apple Push Notification service: Apple may process push tokens outside the EU. Transfer mechanism: SCCs as part of Apple's Data Processing Terms.
  • Cloudflare: May route traffic through non-EU servers. Transfer mechanism: SCCs as part of Cloudflare's Data Processing Addendum.
  • Anthropic / OpenAI / Google AI (only if you enable AI features): May process data in the US under SCCs. These transfers only occur when you explicitly enable AI features and provide your own API key.

7. Data Retention

Data CategoryRetention Period
Account dataWhile your account is active; deleted upon account deletion request
User content (tasks, projects, notes, etc.)While your account is active; soft-deleted items are permanently removed after 30 days
Google Calendar data (cached events, sync state)Until you disconnect the Google account, revoke access in Google, or delete your Vector ToDo account — whichever comes first. The encrypted refresh token is purged immediately on disconnect.
API audit logs6 months, then automatically purged
Activity logs and daily snapshotsWhile your account is active
Push notification tokensUntil you disable notifications or delete your account
File attachmentsUntil the parent task/note is permanently deleted
Marketing consent recordWhile your account is active. After withdrawal we keep the withdrawal record for 24 months for accountability under GDPR Art. 7(1).

8. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request a copy of your personal data.
  • Right to rectification (Art. 16): Correct inaccurate data. You can update your name, email, and other profile information directly in Settings.
  • Right to erasure (Art. 17): Request deletion of your account and all associated data ("right to be forgotten").
  • Right to restriction of processing (Art. 18): Request restriction of processing in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format (JSON).
  • Right to object (Art. 21): Object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)): Withdraw consent for Google integrations, marketing emails, push notifications, or other optional features at any time via Settings.
  • Right to lodge a complaint: You may file a complaint with your national Data Protection Authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl).

To exercise these rights, email us at [email protected]. We will respond within 30 days.

9. Automated Decision-Making

We do not use automated decision-making or profiling as defined by GDPR Article 22. No decisions with legal or similarly significant effects are made about you automatically.

If you enable AI features, the Service may automatically generate tags and insights for your tasks. These are assistive suggestions only and have no legal or similarly significant effect on you. You can review, modify, or delete any AI-generated content.

10. Security

We implement appropriate technical and organizational measures to protect your data:

  • Passwords are hashed using bcrypt
  • All data in transit is encrypted via TLS (HTTPS/WSS)
  • Google OAuth refresh tokens are encrypted at rest with AES-256-GCM and never exposed to clients
  • Row-level security (RLS) is enforced at the database level
  • API keys are hashed (SHA-256) before storage; only the prefix is visible
  • Content Security Policy (CSP) headers are enforced
  • Session tokens have expiration and automatic refresh

11. Children

The Service is not directed at children under the age of 16 (as per GDPR Article 8). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will be revised accordingly. Material changes will be communicated via in-app announcements or email.

We encourage you to review this policy periodically.

13. Contact

For privacy-related questions, contact us at [email protected].

© 2026 Dowiem Sp. z o.o. All rights reserved.