Tavo has no server. Your tasks are written to your own phone and stay there. Nothing about them — not the words, not the times, not the places, not how many you finish — is sent to us, because there is nowhere for it to be sent and nothing at the other end to receive it.
We do not collect your data, so we cannot lose it, sell it, share it, mine it, or hand it to anybody who asks. Most of the sections below exist to say that again in the specific way each question deserves.
This policy covers the Tavo app for iPhone and iPad, and the Tavo website. It does not cover Apple's services or anything else you reach from inside Tavo — those are governed by their own policies, and we link to them where they come up.
By using Tavo you accept this policy. If you don't, the app can be deleted at any time and takes everything with it.
Everything Tavo knows about you is written to the device you are holding:
This lives in the app's own storage on the device, in the area iOS reserves for Tavo and no other app can read. It is included in your encrypted iPhone backups, which are yours and not ours.
Nothing.
There is no Tavo account system, no Tavo database, no Tavo analytics, and no Tavo server of any kind. We do not know how many tasks you have, whether you opened the app today, what you called anything, or whether you are using it at all.
The only thing that ever reaches us is a message you choose to send — an email to the support address below. If you write to us we will have your email address and whatever you put in the message, and we keep it only as long as it takes to answer you.
Tavo asks for four things. Every one is optional, the app works without any of them, and each is used for exactly one purpose:
Each of these can be withdrawn at any time in the iOS Settings app under Tavo. Withdrawing one stops the feature and nothing else.
There aren't any. Tavo has no sign-in, no username and no password, because there is no Tavo server for an account to sit on. You open the app and it is yours.
There is no profile either — no name, no photo, nothing about you for Tavo to hold. The only things in the app are the ones you put there.
Premium can keep your tasks in step across the devices signed in to your Apple Account — that is the Apple Account already on your phone, not an account with us. That runs through Apple's iCloud, in your own private iCloud database, under Apple's privacy terms — not through any service of ours.
We cannot see what is in it. Apple does not give app developers access to a person's private CloudKit database, and Tavo does not ask for any.
Sync can be left off, and Tavo works exactly the same on the one device.
All purchases go through Apple's App Store. Tavo never sees your card, your billing address, or your Apple Account details — Apple handles the transaction and tells the app only whether a purchase is active.
Apple may provide us with anonymous, aggregated sales figures, in the same form every developer receives: totals by country and by day, never tied to a person.
Tavo relies on one outside service, and it is the one every iPhone app relies on:
There are no other third parties. No advertising networks, no attribution or install-tracking software development kits, no data brokers, no customer-messaging tools, no A/B testing services.
Tavo contains no analytics. Not a first-party count, not a third-party one, not an anonymised one. We do not know which features get used or which screens get seen.
Tavo contains no crash reporting. If it crashes, we find out because somebody writes to us — or because Apple's own opt-in diagnostics, which you control in iOS Settings, shows us an anonymous stack trace with nothing of yours in it.
Tavo contains no advertising and no tracking of any kind. It does not ask for permission to track, because there is nothing it would do with it.
The Tavo website is a handful of static pages. It sets no cookies, runs no analytics, and has no accounts, comment fields or forms.
It loads its typefaces from Google Fonts, which means your browser requests those font files from Google's servers and Google sees the request in the ordinary way any web request is seen. Nothing else on the page reaches out anywhere.
Whoever hosts the site keeps standard server logs — the sort every web server keeps — which may include an IP address and the page requested. We do not analyse them and do not connect them to anything.
Your data is kept for exactly as long as you keep it, because you are the one holding it. Delete a task and it goes to Trash; empty the Trash and it is gone. Delete everything from Settings and all of it is gone at once. Delete the app and the storage goes with it.
There is no retention period on our side, no backup of yours on our systems, and no ninety-day grace window in which we still have a copy — because we never had one.
Your data sits inside the app's sandbox, which iOS isolates from every other app on the device. It is protected by your device passcode, Face ID or Touch ID, and by iOS file-level encryption whenever the device is locked.
If you turn on sync, the data travels to your own iCloud over an encrypted connection and is stored under Apple's security practices.
No system is perfect, and we will not claim otherwise. What we can say is that the usual worst case for an app — a breach of the company's servers spilling everyone's data — cannot happen here, because those servers do not exist.
Your task data does not leave your device, so no international transfer of it occurs.
If you turn on sync, Apple stores it in iCloud, and Apple decides which region that is in under its own terms. That is between you and Apple.
If you are in the United Kingdom or the European Economic Area, the UK GDPR and GDPR give you rights over personal data an organisation holds about you: to be told about it, to see it, to correct it, to have it erased, to restrict or object to its use, and to take it elsewhere.
We hold no personal data about you, so there is nothing for us to show, correct, erase or export. What Tavo holds is on your device, where you already have every one of those rights directly: you can read it, change it, export it by sharing it, and destroy it, without asking anyone.
Where we do process something — an email you send to support — the lawful basis is our legitimate interest in answering you. You can ask us to delete that correspondence at any time.
The CCPA and CPRA give California residents the right to know what personal information a business collects, to have it deleted, to correct it, and to opt out of its sale or sharing.
Tavo collects no personal information, sells none, and shares none. There has been nothing to sell in the past twelve months and there is no mechanism by which there could be. Exercising any of these rights against us would return an empty answer, which we would rather tell you now than after a form.
Tavo is not directed at children under 13. It collects nothing from anybody, children included, so there is no children's data for us to hold or to delete.
Inside the app: Settings → Preferences → Delete Everything. That erases every task, list, tag and note immediately and without a recovery period. If sync is on, the deletion travels to your iCloud too.
Outside the app: deleting Tavo from your device removes its storage with it. To remove what iCloud holds, use iOS Settings → your name → iCloud → Manage Account Storage → Tavo → Delete Data.
If this policy changes, the date at the top changes with it, and the new version appears here and in the app at the same time. We will not quietly reduce what is promised here; if Tavo ever gains a server, an account system or anything that collects data, that will be described plainly and before it ships.
Questions about this policy, or about anything Tavo does with your data: tavosupport@gmail.com
Tavo is made by Aspen Koch, an independent developer.
Written to describe what Tavo actually does, in plain language rather than boilerplate. It has not been reviewed by a lawyer.