PRIVACY POLICY

Privacy policy

This notice covers the Zailing Todo website, iOS client, and this help site. It describes the current product behavior; third-party services also apply their own terms.

Effective September 23, 2026

Data we process

  • Account and sign-in: Name, email, salted password hash, sessions, and necessary security records. GitHub sign-in provides a GitHub user identifier and verified email. Native Sign in with Apple provides an Apple user identifier and verified email, which may be a private relay address.
  • Workspace: Projects, tasks, descriptions, statuses, tags, due dates, reminder times, and matrix classification.
  • Chat and models: Model settings, encrypted API keys, conversations, and messages. When you send a chat message, the current conversation context and selected system prompt go to your chosen model provider.
  • Bots and connections: Your DingTalk, Feishu, and WeChat connection and reminder settings. If enabled, relevant task reminders or chat content go to the selected channel. MCP access tokens are stored server-side as hashes.
  • Local demo: Unsigned demo data stays in the current browser and is not automatically synced to an account.

Use and sharing

We use this data for sign-in, task sync, calendars, chat, and the reminders you enable. Cloudflare Workers and D1 host the service and cloud data. Workers Logs retain request methods, URLs, responses, and runtime metadata for security and troubleshooting for up to seven days, depending on the Cloudflare plan. Sign-in and registration rate limits temporarily retain a SHA-256 digest of the IP address. GitHub and Apple sign-in exchange identity information with their respective providers. Chat sends the current conversation to your configured model provider after your explicit confirmation. Reminders and WeChat chat send necessary content to the relevant DingTalk, Feishu, or WeChat service. Review those providers’ privacy policies and locations.

The current project code has no advertising or third-party analytics SDK. This help site itself does not set an app account cookie or offer a message form; Cloudflare still processes network request information to deliver it.

Storage and security

Cloud account data is kept while the account is active. You can remove individual tasks, conversations, or connections in the app. See account deletion for the full-account process. Sign-in uses a site-specific HttpOnly session cookie. Passwords are stored as salted hashes; model API keys and sensitive bot settings are encrypted server-side. Traffic uses HTTPS.

The browser manages local demo data. Clearing site data clears that workspace. Third-party providers may keep content sent to them under their own policies; deleting it here does not automatically delete their copies. Account deletion does not immediately remove request metadata already written to Cloudflare logs; those logs expire under the platform retention period. After deleting a Zailing account used with Apple sign-in, revoke its authorization manually in Apple settings; Zailing does not store Apple access or refresh tokens.

Your choices

You can edit or delete tasks, projects, conversations, and models; unlink reminder channels; revoke MCP tokens; or sign out. Use the contact details below for questions about data handling or account deletion.

CONTACT

Need help?

Tell us which feature you are using, what happened, and the device/browser version. Never send passwords, API keys, or robot tokens.

huzailingcom@gmail.com