Privacy Policy — TaskFlow Sync
Effective date: 2026-06-14 · Last updated: 2026-06-19
TaskFlow Sync ("the app") is an offline-first Android task manager. This policy explains what
data the app accesses, how it is used, and how to revoke access.
1. Data the app stores on your device
Your tasks (title, note, due date, completion state, snooze time) are saved locally on your
device using Android's SharedPreferences store as a single JSON value. The app has
no backend; we do not operate any server that stores your tasks.
2. Google account & Google Calendar (optional)
If you choose to sign in with your Google Account, the app requests the OAuth scope
https://www.googleapis.com/auth/calendar.events. This scope is used solely to create,
update, and delete calendar events that correspond to tasks you have explicitly chosen to sync.
- The app does not read calendar events it did not create.
- The app does not access other Google services (Drive, Gmail, Contacts, etc.).
- Your OAuth refresh and access tokens are stored only on your device, in the platform
secure storage provided by Google Sign-In.
3. How we protect your data
We apply the following measures to protect your data, including the sensitive Google Calendar
data accessed under the calendar.events scope:
- Encryption in transit. All communication between the app and Google's APIs
occurs over encrypted HTTPS/TLS connections. Calendar data is never transmitted over an
unencrypted channel.
- Secure credential storage. OAuth access and refresh tokens are stored only
on your device, in the platform secure storage provided by Google Sign-In, and are never
transmitted to or stored on any server we operate.
- Data minimization. The app requests the narrowest scope required
(
calendar.events rather than full calendar access) and only ever creates,
updates, or deletes calendar events that correspond to tasks you have explicitly chosen to
sync. It does not read, store, or process any other calendar data.
- No server-side storage. The app has no backend. Your sensitive data
(Google account identity and calendar events) is not collected, logged, or retained on any
server we control; it remains between your device and Google's own services.
- On-device data at rest. Task data is stored locally on your device and is
protected by the device's own operating-system sandboxing and storage protections.
- Revocation and deletion. You can revoke the app's access to your Google
data at any time (see the section below), which immediately ends all access to your
sensitive data.
4. What we do NOT do
- We do not sell your data.
- We do not share your data with third parties for advertising or analytics.
- We do not transmit your tasks to any server we operate.
- We do not use your Google user data to develop, improve, or train generalized/non-personalized
AI or machine-learning models.
5. Permissions on Android
- POST_NOTIFICATIONS — to show task reminders.
- SCHEDULE_EXACT_ALARM — to fire reminders at the exact time you set.
- RECEIVE_BOOT_COMPLETED — to restore reminders after the device reboots.
- RECORD_AUDIO (optional, only if you use voice capture).
- INTERNET (only when you opt into Google Calendar sync).
6. Revoking access & deleting your data
- To revoke the app's access to your Google Account, visit
https://myaccount.google.com/permissions
and remove "TaskFlow Sync".
- To delete all local task data, uninstall the app or use the "Clear data" option in
Android Settings → Apps → TaskFlow Sync → Storage.
7. Children
TaskFlow Sync is not directed to children under 13 and does not knowingly collect data from
them.
8. Changes to this policy
If we change this policy, the new version will be posted at this URL with a new "Last updated"
date.
9. Contact
Questions or requests: daniel.mazhbits@gmail.com