Tinstodo
Terms Contact Sign In

Privacy Policy

Effective date: July 1, 2026  ·  Last updated: July 1, 2026

Tinstodo ("we," "us," or "our") operates the Tinstodo task management application (the "Service") available at tinstodo.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read it carefully. By creating an account or using the Service, you agree to the practices described in this policy.

1. Information We Collect

Account information

  • First name and last name
  • Email address (required for account creation and communication)
  • Password (stored as a BCrypt hash — we never store your plain-text password)
  • Timezone preference (used to send reminders at the correct local time)

Task and usage data

  • Tasks you create, including their title, description, due date, priority, category, and completion status
  • Email reminder preferences you set on individual tasks
  • Categories you create to organise your tasks

Technical information

  • IP address (logged by our hosting infrastructure for security purposes)
  • Browser type and version (detected from standard HTTP headers)
  • Device timezone (detected automatically via your browser to ensure reminders arrive at the right time)
  • Session cookies required to keep you logged in during a browsing session

What we do NOT collect

  • We do not collect payment information (Tinstodo is currently free)
  • We do not collect precise GPS location
  • We do not use third-party advertising trackers or analytics SDKs

2. How We Use Your Information

  • Provide the Service. To create and manage your account, display your tasks, and operate the application.
  • Email reminders. To send reminder emails for tasks you have chosen to be reminded about, at the time and in the timezone you specified.
  • Account communications. To send verification emails when you register and password-reset emails when you request them.
  • Security. To detect and prevent abuse, brute-force login attempts, and other malicious activity.
  • Service improvements. To understand how the application is used so we can fix bugs and improve features.
  • Legal compliance. To comply with applicable laws and respond to lawful requests from public authorities.

We do not sell your personal information. We do not use your task content to train AI models.

3. Email Reminders

When you set a reminder on a task, we store that preference and send you one reminder email per task at the configured time. You can disable reminders at any time by editing the task and selecting "No reminder." Reminder emails are sent through Brevo (formerly Sendinblue), our transactional email provider. Brevo processes your email address solely to deliver messages on our behalf and is bound by a data processing agreement.

4. Data Storage and Security

Your data is stored in a managed MySQL database hosted on Aiven, a cloud database provider. The application itself runs on Render, a cloud application platform. Both providers maintain industry-standard security controls including encryption at rest and in transit.

We implement the following security measures in the application:

  • Passwords are hashed using BCrypt with a cost factor of 12
  • All data is transmitted over HTTPS (TLS)
  • Session cookies are HTTP-only and, in production, marked Secure
  • CSRF protection is enabled on all state-changing requests
  • Input validation is performed on all user-submitted data
  • Rate limiting is applied to login, registration, and password-reset endpoints
  • Each user can only access their own tasks and categories

While we take reasonable precautions, no internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security.

5. Third-Party Services

Tinstodo uses the following third-party services. Each operates under its own privacy policy.

  • Aiven — managed MySQL database hosting (aiven.io/privacy)
  • Render — application hosting (render.com/privacy)
  • Brevo — transactional email delivery (brevo.com/legal/privacypolicy)
  • Google Fonts — the Inter typeface is loaded from Google's CDN, which may log your IP address (policies.google.com/privacy)

We do not use Google Analytics, Facebook Pixel, or any other advertising or behavioural tracking service.

6. Children's Privacy

Tinstodo is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@tinstodo.com. We will promptly delete any such information and terminate the associated account in accordance with applicable law, including the Children's Online Privacy Protection Act (COPPA).

By creating an account, you represent that you are at least 13 years old.

7. Your Rights

You have the right to:

  • Access — view the personal information we hold about you
  • Correction — ask us to correct inaccurate information
  • Deletion — delete your account and all associated data at any time from Account Settings
  • Portability — request a copy of your data in a machine-readable format
  • Opt-out of non-essential email — you can disable reminder emails per task at any time

To exercise any of these rights, you may use the in-app Account Settings page or contact us support@tinstodo.com.

8. Data Retention

We retain your account data for as long as your account is active. If you delete your account, all associated data — including your tasks, categories, and personal information — is permanently removed from our primary database immediately. Residual copies in automated backups are purged on the backup rotation schedule (typically within 30 days).

9. Account Deletion

You can permanently delete your account at any time by going to Account Settings → Danger Zone → Delete Account. Deletion is irreversible and removes all tasks, categories, and personal data associated with your account. You will be required to enter your current password to confirm the action.

10. Cookies

We use one essential session cookie (JSESSIONID) to keep you authenticated while you use the application. This cookie is deleted when you sign out or when your session expires (after 30 minutes of inactivity). We do not use advertising or tracking cookies.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If changes are material, we will notify you by email. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

12. Contact

If you have any questions about this Privacy Policy, please contact us:

Email: support@tinstodo.com
General support: support@tinstodo.com
Website: tinstodo.com

© 2026 Tinstodo. All rights reserved.
Privacy Policy Terms of Service IP Policy Contact