AllDone Privacy Policy
Effective Date: September 14, 2026
AllDone (“AllDone,” “we,” “us,” or “our”) is a task-management application operated by TakkTakk LLC, a Nevada limited liability company. This Privacy Policy explains how we collect, use, store, disclose, and protect information when you use AllDone, including when you connect AllDone to third-party services such as Google, Microsoft, or Folk CRM.
By using AllDone, you acknowledge the practices described in this Privacy Policy.
1. Information We Collect
Account and Profile Information
When you create or access an AllDone account, we may receive and store information such as:
- Your name;
- Email address;
- User or account identifiers supplied by an authentication provider;
- Display name and profile or avatar information;
- Authentication and session information;
- Information about accounts and services you connect to AllDone; and
- Account settings and preferences.
AllDone may allow you to sign in using third-party authentication providers such as Google or Microsoft. We do not receive or store your Google or Microsoft password.
Information You Provide to AllDone
We collect information that you choose to create, enter, import, or store in AllDone, which may include:
- Tasks and subtasks;
- Task names and descriptions;
- Rich-text notes;
- Due dates and availability dates;
- Tags;
- Contact information or text associated with tasks;
- URLs and links;
- Domains and domain names;
- Domain avatar images;
- Task hierarchy, ordering, completion status, and workspace placement;
- Repeating or scheduled task blueprint information; and
- Preferences and other information associated with your use of AllDone.
Information you enter into AllDone may contain information about other people. You are responsible for ensuring that you have the right to provide such information to AllDone.
Information From Connected Services
If you choose to connect a supported third-party service, AllDone receives information necessary to provide the functionality you authorize.
Currently supported connected services may include Google Tasks, Microsoft To Do, and Folk CRM.
Depending on the service and settings you select, AllDone may receive and store task lists, tasks, subtasks or checklist items, notes, dates, completion status, hierarchy, provider identifiers, links, and other information associated with supported task records.
AllDone does not currently access Gmail messages, Outlook email messages, Google Calendar events, Outlook Calendar events, Google Drive documents, OneDrive documents, Google Contacts, or Microsoft address-book contacts through these integrations.
Technical and Operational Information
We and our infrastructure providers may process technical information associated with your use of AllDone, such as IP address, browser and request information, authentication and session records, synchronization timestamps and cursors, queue and retry status, deletion records, and limited diagnostic, security, and operational information.
AllDone does not currently use dedicated behavioral advertising or usage-analytics platforms. We maintain limited operational information necessary to operate, secure, troubleshoot, and monitor the service.
2. How We Use Information
We use information to:
- Create, authenticate, and maintain your AllDone account;
- Provide task-management functionality;
- Store and organize tasks, subtasks, domains, notes, links, schedules, and preferences;
- Connect AllDone to services you authorize;
- Synchronize information with connected task services;
- Import information from connected services when you request it;
- Send changes to connected services when required by your selected synchronization settings;
- Maintain and restore synchronization operations;
- Diagnose errors and technical problems;
- Provide customer support;
- Protect AllDone and its users against fraud, abuse, security threats, and unauthorized access;
- Maintain, improve, and operate AllDone; and
- Comply with applicable legal obligations.
We do not sell your personal information.
We do not use information obtained from your connected Google or Microsoft accounts for targeted advertising.
3. Google User Data
If you choose to connect your Google account to Google Tasks functionality, AllDone requests authorization to access Google Tasks. Google authentication may also be used separately as a method for signing into your AllDone account.
Google Tasks authorization allows AllDone to read and, where necessary to provide functionality you select, create, modify, complete, reopen, organize, reorder, or delete Google Tasks.
AllDone may request offline access so that authorized task synchronization can continue while you are not actively using AllDone.
How AllDone Uses Google User Data
Google user data is used only to provide or improve user-facing functionality that you request or authorize, including:
- Identifying your connected Google account;
- Displaying and managing the connection;
- Importing authorized Google Tasks information;
- Synchronizing tasks between Google Tasks and AllDone;
- Creating or modifying Google Tasks in response to authorized synchronization or user actions;
- Reflecting task completion, hierarchy, and ordering changes; and
- Deleting Google Tasks when you explicitly select functionality that requires deletion, including AllDone's task-ingestion functionality.
AllDone does not use Google Tasks authorization to access Gmail, Google Drive, Google Calendar, or Google Contacts.
Storage of Google User Data
When Google Tasks synchronization is enabled, authorized task information may be stored in AllDone so that AllDone can provide task-management and synchronization functionality.
AllDone may also temporarily stage task information on its servers while completing synchronization operations or recovering from interrupted synchronization. Temporary synchronization staging is subject to scheduled cleanup.
Google OAuth credentials necessary to maintain an authorized connection may be retained while the connection remains active. Durable provider refresh tokens are stored using encrypted secret storage and are accessible only through restricted server-side processes.
Google Limited Use Disclosure
AllDone's use and transfer of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including its Limited Use requirements.
AllDone does not sell Google user data.
AllDone does not use Google user data for advertising.
AllDone does not use Google user data to train generalized artificial-intelligence or machine-learning models.
AllDone does not transfer Google user data to data brokers or use Google user data to create advertising profiles.
Human Access to Google User Data
AllDone personnel will not access Google user data except:
- With the user's explicit consent to access specific information for support;
- When necessary to investigate security incidents, fraud, abuse, or technical problems where access is permitted by Google's applicable policies;
- When required by applicable law; or
- For permitted internal operations where the information has been aggregated and anonymized as required by Google's applicable policies.
We do not permit general employee or contractor access to Google user data.
4. Microsoft User Data
If you connect a Microsoft account, AllDone currently uses Microsoft authorization for Microsoft Sign-In and Microsoft To Do functionality.
With your authorization, AllDone may access Microsoft To Do task lists, tasks, and supported checklist items.
Depending on your synchronization settings, AllDone may read, create, modify, complete, synchronize, or delete supported Microsoft To Do task information.
AllDone does not currently use Microsoft authorization to access your Outlook mailbox, Outlook Calendar events, OneDrive files, or Microsoft address-book contacts.
Microsoft authorization credentials required to maintain an authorized connection may be securely retained while your connection remains active.
5. Connected-Service Synchronization
For supported task sources, AllDone may offer different connection modes.
Two-Way Synchronization
When two-way synchronization is enabled, AllDone may periodically exchange supported task information and changes with the connected service.
Synchronization may occur while you are not actively using AllDone. AllDone uses scheduled synchronization processes as well as synchronization triggered by user activity.
Ingest
If you select an ingest option, AllDone may import eligible tasks from the connected service into AllDone and request deletion of the corresponding source tasks.
Once an imported task has been converted into a native AllDone task, it may be retained independently of the original connection.
Deleting or disconnecting the connection later does not restore source tasks that were previously deleted through an ingest operation.
No Task Synchronization
If you disable task synchronization, AllDone stops synchronizing that task source. Disabling synchronization is different from disconnecting the account and does not necessarily delete existing imported information or authorization credentials.
6. Artificial Intelligence
AllDone does not currently transmit user data to OpenAI or another artificial-intelligence provider as part of the application's operation.
AllDone does not currently provide an integrated AI conversation service or maintain AI conversation histories.
AllDone does not use user information to train artificial-intelligence models.
AllDone may provide text or prompts that users can copy and independently use with an external AI service. If you voluntarily submit information to an external AI service yourself, your interaction with that service is governed by that provider's terms and privacy practices, not this Privacy Policy.
If AllDone introduces integrated AI functionality in the future that materially changes how personal information is processed, we will update our disclosures as appropriate. AllDone will not use user data to train AI models without explicit user consent.
7. How We Share Information
We may disclose information to service providers that process information on our behalf and are necessary to operate AllDone.
Current infrastructure and service providers include services used for application hosting, database storage, authentication, server-side processing, credential storage, Google authentication and Google Tasks, Microsoft authentication and Microsoft To Do, and connected services such as Folk CRM when selected by the user.
Our primary application infrastructure currently includes Netlify for frontend hosting and Supabase for database, authentication, server, realtime, and credential-storage functionality.
When you choose to connect a third-party service, we may exchange information with that service as necessary to perform the functionality you request.
Except as subject to additional restrictions applicable to Google user data described in Section 3, we may also access or disclose information:
- At your direction or with your consent;
- When reasonably necessary to provide support you request;
- When required by applicable law or valid legal process; or
- When reasonably necessary to investigate fraud, abuse, security incidents, or threats to AllDone or its users.
We do not operate a public-sharing or cross-user collaboration feature that makes your AllDone task information available to other AllDone users.
8. Sale of Personal Information and Advertising
AllDone does not sell personal information.
AllDone does not sell Google user data, Microsoft user data, task content, or other personally identifiable information to third parties.
AllDone does not currently use personal information or connected-account information for targeted advertising.
AllDone does not currently include advertising SDKs or dedicated advertising trackers.
9. Data Storage and Retention
We retain account information and user-created information while necessary to operate your account and provide AllDone.
Completed tasks may remain in AllDone until deleted or until the associated account or data is deleted. Completing a task, removing it from a workspace, or disabling synchronization does not necessarily delete the underlying task record.
Provider-linked task information generally remains until it is deleted, the associated connection is disconnected, or the AllDone account is deleted, as applicable.
Tasks imported and converted into native AllDone tasks may remain after the source connection is disconnected.
Temporary synchronization staging information is subject to scheduled cleanup. AllDone currently uses a seven-day age threshold for certain synchronization staging information.
OAuth credentials may be retained while necessary to maintain an authorized connection and may become invalid earlier if revoked or expired by the provider.
AllDone accounts may become eligible for deletion after 12 consecutive months without user activity. Before deleting an account for inactivity, we intend to provide at least 30 days' advance notice and an opportunity to prevent deletion by returning to the account. Background synchronization does not constitute user activity for this purpose.
Our infrastructure providers may maintain operational logs, security records, or backups according to their own retention systems. We are continuing to verify the precise retention periods applicable to provider-managed infrastructure records.
10. Account Deletion
You may request deletion of your AllDone account from within AllDone or by contacting us at dhf@takktakk.co.
When an account-deletion request is accepted, access to the account is blocked and deletion may proceed through background processes with automatic retries where necessary.
Account deletion is designed to remove account-owned information, including tasks and subtasks, domains, blueprints, preferences, provider connections, associated synchronization information, stored provider credentials, and associated AllDone authentication identities, sessions, and refresh tokens.
We may temporarily retain limited deletion-request records for operational, recovery, security, or compliance purposes. Account/login identifiers associated with completed deletion requests are scheduled for removal after 30 days, and remaining deletion receipts after 90 days.
Account deletion does not delete your Google, Microsoft, Folk, or other third-party account.
It also does not necessarily delete information that remains independently in those third-party services, restore information previously deleted from those services through an ingest operation, or automatically revoke authorization grants maintained by the third-party provider.
You may separately revoke AllDone's authorization through the applicable provider.
11. Disconnecting a Google or Microsoft Account
You may disconnect supported external accounts through AllDone, subject to restrictions necessary to maintain at least one valid login method for your account.
Disconnecting a provider generally removes:
- The AllDone provider connection;
- Associated server-side provider credentials;
- Provider-linked local task records;
- Connection-specific synchronization information; and
- The corresponding linked sign-in membership, where applicable.
Tasks previously ingested and converted into native AllDone tasks may remain because they are no longer dependent on the source connection.
Disconnecting an account does not delete your Google or Microsoft account and does not necessarily revoke the authorization grant maintained by Google or Microsoft. You may revoke that authorization directly through your Google or Microsoft account settings.
Information may also remain temporarily in infrastructure logs, backups, or already-active browser sessions where immediate deletion is not technically available.
12. Security
We use administrative and technical safeguards intended to protect information processed by AllDone.
Current safeguards include measures such as:
- HTTPS for production service endpoints;
- Account-scoped database access controls;
- PostgreSQL Row Level Security;
- Restricted server-side operations;
- Encrypted secret storage for durable provider refresh tokens;
- Restricted synchronization endpoints;
- Separation between ordinary authenticated access and privileged server processes;
- Sanitization of rich-text content;
- Restrictions on sensitive information included in application operational logs; and
- Security and isolation checks.
No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
AllDone should not be considered an end-to-end encrypted service because authorized server components must be able to process task information to provide the service.
13. Browser Storage and Similar Technologies
AllDone uses browser storage and related technologies necessary to provide core functionality, including maintaining authentication sessions and supporting account connections.
We do not currently use dedicated behavioral advertising trackers or advertising SDKs.
Third-party infrastructure and authentication providers may use cookies or similar technologies as necessary to provide their services.
14. Children
AllDone is not intended for children under 13 years of age, and we do not knowingly collect personal information from children under 13.
If we learn that a child under 13 has provided personal information to AllDone, we may take steps to delete the account and associated information.
If you believe a child under 13 has provided personal information to AllDone, please contact us at dhf@takktakk.co.
Users who are at least 13 but under 18 should use AllDone only in accordance with applicable law and any applicable consent or supervision requirements.
15. Business Transactions
If TakkTakk LLC is involved in a merger, acquisition, reorganization, sale of assets, or similar business transaction, personal information may be transferred as permitted by applicable law and applicable third-party platform requirements.
Google user data will not be transferred as part of a merger, acquisition, or sale of assets without the user's explicit prior consent where required by the Google Workspace API User Data and Developer Policy.
Any Google user data will continue to be handled in accordance with Google's applicable Limited Use requirements.
16. Your Choices and Controls
Depending on the functionality you use, you may:
- Edit or delete tasks and other information within AllDone;
- Change synchronization settings for supported task sources;
- Disconnect supported external accounts;
- Revoke AllDone's authorization through Google, Microsoft, or another connected provider;
- Delete your AllDone account; and
- Contact us regarding your personal information.
Changing synchronization settings, disconnecting a service, revoking authorization, deleting individual information, and deleting your AllDone account are distinct actions and may have different effects.
17. Third-Party Services
AllDone may contain links to websites or services operated by third parties.
This Privacy Policy does not govern third-party services. Your use of Google, Microsoft, Folk CRM, or another external service is also subject to that provider's applicable privacy policy and terms.
If you follow a user-provided link or voluntarily transfer information to another service, that service may collect information independently of AllDone.
18. Changes to This Privacy Policy
We may update this Privacy Policy as AllDone changes, as our data practices change, or as necessary to comply with legal or platform requirements.
If we make material changes, we may provide notice through AllDone, by email, on our website, or through another appropriate method.
The effective date at the top of this Privacy Policy indicates when the current version became effective.
19. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or AllDone's privacy practices, contact:
TakkTakk LLC
Nevada, United States
Email: dhf@takktakk.co
Website:
https://alldone.yolo.industries
The current version of this Privacy Policy is available at: