Privacy policy
Last updated: September 30, 2026
This policy explains what personal data MyTaskLists processes when you use the web app (mytasklists.online/app) or the iOS and Android apps, why we use it, who we share it with and how you stay in control of it. We wrote it to be understood without a lawyer. If anything is unclear, write to us at privacidad@mytasklists.online. The Spanish version (Política de privacidad) prevails in case of discrepancy.
1. Summary
- We only ask for what is needed to give you an account and let you share lists.
- We do not sell your data, we show no ads and we do not track you across other apps or websites.
- What you write in a list is only seen by the people you share it with.
- Web analytics use no cookies and do not identify you. The newsletter is optional and you can leave with one click.
- You can access, correct, export or delete your data whenever you want.
2. Who is responsible
The controller of your data is MyTaskListsOnline, which operates the MyTaskLists service (“MyTaskLists”, “we”, “us” in this policy). Address: Cuernavaca, Morelos, México. For any privacy matter, write to privacidad@mytasklists.online.
This policy applies equally to the website, the web app and the iOS and Android apps: they all use the same account and the same server.
3. What data we process
Data you give us
- Account
- Name, email address, WhatsApp number (required when you sign up with email; optional if you sign in with Google or Apple) and password. Your password is never stored as is: we only keep a cryptographic hash that cannot be reversed.
- Preferences
- Language, whether you want to receive alerts and, if you turn it on, two-step verification (2FA).
- List content
- List names, descriptions, items, their recurrence, whether they were bought and the order you put them in. We recommend not writing sensitive data (health, financial, etc.) in your lists.
- Invitations
- The email address of the person you invite to a list. By doing so you confirm you have a reason to share it with us (for example, it is someone in your household who wants to use the list with you).
- Messages
- Whatever you write to us if you contact us by email.
Data we receive when you sign in with Google or Apple
If you choose “Continue with Google” we receive your name, email, whether Google verified it, your profile picture and an identifier for your Google account. With “Continue with Apple” we receive an identifier, your email (it can be a private Apple relay address if you choose so) and, the first time, your name. We never receive your Google or Apple password, and we do not access your contacts, emails, files or calendar.
Data generated when you use the service
- List activity
- Who added, bought, edited or removed each item and when. It powers the history and alerts shown to list members, and internal service metrics.
- Alerts
- The alerts we send you inside the app and whether you have read them.
- Devices
- If you allow notifications in the mobile app: your device's push token, the platform (iOS or Android), the device name and when it last connected.
- Technical data
- IP address, browser or device type, app version, date and time of each request and the date of your last sign-in. We use it to keep the service running, protect accounts (for example, by limiting sign-in attempts) and detect errors.
We do not process your location, contacts, photos, microphone or camera, nor any payment data: the service has no purchases.
4. Why we use it and on what basis
| Purpose | Data | Basis |
|---|---|---|
| Create and keep your account, sign you in and recover access | Account, Google or Apple data, technical data | Performance of the contract (the terms of service) |
| Store your lists, share them and sync them in real time | Content, invitations, activity | Performance of the contract |
| Send you alerts (in-app and push notifications) | Alerts, devices, preferences | Performance of the contract and your consent to push notifications, which you can withdraw at any time |
| Service emails: confirm your email, reset your password, invitations | Email, name, language | Performance of the contract |
| Protect the service and accounts: 2FA, attempt limits, abuse and fraud prevention | Technical data, account | Legitimate interest in keeping the service secure |
| Understand how the service is used to improve it (aggregate metrics) | Activity, cookieless analytics | Legitimate interest |
| Newsletter | Your consent (confirmed by email) | |
| Handle your requests and comply with legal obligations | Whatever each case requires | Legal obligation |
We make no automated decisions with legal effects on you and build no advertising profiles. We do not use your data or your list content to train artificial intelligence models.
6. iOS and Android apps: permissions
- Notifications: the app asks for permission the first time. If you allow it, we register your device token to send you alerts. You can revoke it anytime in your phone settings or turn alerts off in the app; when you sign out, the device stops receiving them.
- Internet: needed to sync your lists.
- The app does not request access to your location, contacts, photos, camera or microphone, and includes no advertising or tracking SDKs. On iOS we do not track you as defined by App Tracking Transparency.
- Your session is stored in the system's secure storage (iOS Keychain and Android Keystore) and erased when you sign out.
8. Analytics
To know which pages are visited and improve the site we use Umami, hosted on our own infrastructure. Umami uses no cookies, does not store your IP address and cannot identify you or follow you across sites: we only get aggregate figures (page views, country, browser and device type, referring site). It runs on the landing page and the web app; the mobile apps include no analytics. If you block the script, the site works just the same.
10. Security
We apply reasonable technical and organizational measures, including:
- Encryption in transit with HTTPS (TLS) on the website, the API and real-time sync.
- Passwords stored with bcrypt and 2FA secrets encrypted with AES-256-GCM.
- Optional two-step verification and single-use recovery codes.
- Short-lived sessions that are renewed and revoked when you change your password or sign out.
- Attempt limits against brute-force attacks and restricted server access.
- Encrypted backups.
No system is infallible. If we detect an incident affecting your data that poses a risk to you, we will notify you and the authorities when the law requires it.
11. How long we keep it
- Account, lists and activity: for as long as you keep your account.
- Shared lists: if you are a member of someone else's list, deleting your account removes you from it, the items you added are kept without an author and the alerts carrying your name are deleted; the list still belongs to whoever created it.
- Sessions: up to 30 days without use, or until you sign out.
- Single-use links: the email confirmation link expires after 24 hours and the password reset link after one hour.
- Invitations: until they are accepted, declined or expire.
- Notification tokens: until you sign out on the device or the token stops being valid.
- Technical logs and security counters: the minimum time needed for security and diagnostics.
- Newsletter: until you unsubscribe.
- Backups: deleted data may remain in them until it is overwritten in the normal rotation cycle.
We may keep data longer only if the law requires it or to handle an ongoing claim.
12. Your rights
Depending on the law where you live, you can:
- Access your data and learn how we process it.
- Correct inaccurate data (you can change your name, WhatsApp and language yourself in “My account”).
- Delete your data or close your account.
- Object to processing or ask us to restrict it.
- Receive a copy of your data in a structured format (portability).
- Withdraw your consent (notifications, newsletter) at any time, without affecting prior processing.
In Mexico these are known as ARCO rights (Access, Rectification, Cancellation and Opposition). If you live in the European Economic Area or the United Kingdom, the GDPR and the UK GDPR protect you. If you live in California, you have the right to know what data we process and to ask us to delete it; we do not sell or share your data for cross-context behavioral advertising.
To exercise them, write to privacidad@mytasklists.online from your account email and tell us what you need. If we cannot confirm your identity, we may ask for more information. We reply within 20 business days at most (one month in the European Union, extendable as the law allows). It is free, and we will not treat you differently for exercising your rights. If you are not satisfied, you can complain to the data protection authority in your country.
13. Deleting your account
You can delete your account yourself, at any time:
- In the iOS or Android app: My account → Delete account.
- In the web app: My account → Delete account.
We will ask for your password (and your two-step verification code, if enabled) to confirm it is you. Deletion is immediate: we delete your account, the lists you created (also for the people you shared them with), your alerts, your devices and the invitations sent to your email, remove you from other people's lists and sign you out on every device. In those lists, the items you added are kept without your name. We send you a confirmation email. Deleting the app from your phone does not delete your account.
If you signed in with Apple on an iPhone or iPad, the app will ask you to confirm with Apple to remove MyTaskLists' access to your Apple ID. You can also do it from your Apple ID settings and, if you signed in with Google, from your Google account's security page.
If you can no longer sign in, write to privacidad@mytasklists.online from the account email, with the subject “Delete my account”, and we will delete it within 30 days.
14. International transfers
Our servers and some providers (for example, push notification providers) may be located outside your country, including the United States. When your data leaves your country we only use providers offering appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission or the EU-U.S. Data Privacy Framework, and only to provide the service.
15. Children
MyTaskLists is not directed to children under 16 and we do not knowingly collect their data. If you are a parent or guardian and believe a child gave us data, write to us and we will delete it.
16. Changes to this policy
If we change this policy we will update the date above. If the change is significant, we will let you know by email or in the app before it takes effect.
17. Contact
For privacy questions, requests or complaints: privacidad@mytasklists.online.