Privacy Policy
Last updated: June 2026
This Privacy Policy describes how Done ("Done," "we," "us") handles information when you use the Done app and the Done Cloud service.
1. Who we are
Done is a task manager for iPhone, iPad, and Mac. This policy is provided by the developer of Done ("Done," "we," "us"). Your use of Done is also governed by our Terms of Service. Questions: support@done-os.app.
2. What we handle
Your content
Tasks, lists, steps, due dates, recurrence, and focus notes are created and stored on your device.
If you enable Done Cloud (our optional sync service), this content is encrypted on your device using AES-256-GCM authenticated encryption before it leaves your device, and only the encrypted result is sent to our cloud. The encryption key is generated on your device. We never receive it in usable form. Your devices share it with each other through Apple's iCloud Keychain (which Apple itself cannot read), and a copy is escrowed on our servers only in a scrambled form that can be unlocked solely by your recovery code. As a result, we cannot read, decrypt, or recover the contents of your tasks, lists, or notes, and neither can anyone who might access our servers.
Account information (only if you use Done Cloud)
Done Cloud uses Sign in with Apple to identify your account. Through it we receive:
- a unique Apple account identifier, and
- the email address associated with your Apple Account, or, if you choose Hide My Email, an anonymous Apple relay address instead.
On first sign-in, Apple may also offer to share your name; if you do, we do not store it on our servers. We use account information solely to authenticate you and sync your encrypted data to the right account. We do not use it for marketing.
You can use Done on a single device without signing in or enabling Done Cloud; in that case no account information is collected at all.
Activity metadata
Because syncing requires it, our servers can see a small amount of non-content information about your encrypted records: how many items you have, which type of record changed, the time a record was last changed or deleted, and the approximate size of the encrypted data. Our servers cannot see the words in your tasks, lists, or notes, who they are about, or what they say. This metadata is used only to operate sync.
Subscription information
Done is offered as a paid subscription. Purchases are processed by Apple through the App Store. We never receive or store your payment card or billing details. We use RevenueCat to manage subscription status (for example, whether your subscription is active or in a free trial). RevenueCat receives app and device identifiers and purchase events needed to manage your entitlement; it does not receive your task content.
Diagnostics
Done includes no third-party analytics, advertising, or tracking SDKs. If you have opted into sharing diagnostics with developers in your device settings, Apple may share crash and performance diagnostics with us through App Store Connect. These do not include your content and are not used to identify you.
3. What we do not do
- We do not sell or rent your information.
- We do not show ads or use advertising identifiers.
- We do not track you across other apps or websites.
- We do not read your task content. By design, we cannot.
4. Service providers
We rely on a small number of trusted providers strictly to operate the app:
- Apple: Sign in with Apple, iCloud Keychain, App Store payments. Handles account identifier/email, your encryption key (Apple-encrypted in iCloud Keychain; Apple cannot read it either), and payment processing.
- Supabase: Hosts Done Cloud. Handles your encrypted content and account identifier, activity metadata, and a copy of your encryption key wrapped with your recovery code (unreadable without that code). Cannot read your content.
- RevenueCat: Subscription management. Handles app/device identifiers and purchase events. No task content.
We do not use data brokers, advertising networks, or analytics vendors.
5. Where your data is stored
Done Cloud data is stored on servers located in the United States. If you use Done from outside the United States, your encrypted data and account identifier will be processed there.
6. How your information is protected
- End-to-end encryption. Your content is encrypted on your device with a key we never receive in usable form. Our servers hold only ciphertext.
- Strict access controls. Each account's records are isolated at the database level so that one account can never access another's data.
- Encrypted in transit. All connections use TLS.
- Apple-grade key handling. Your encryption key syncs between your own Apple devices through iCloud Keychain, which is itself end-to-end encrypted by Apple.
Because Done Cloud is end-to-end encrypted, your data is tied to your Apple Account and a one-time recovery code that Done generates automatically and shows you in Settings. If you change devices while signed in to the same Apple Account, your data restores automatically. However, if you permanently lose access to your Apple Account and have not saved your recovery code, we cannot recover your data for you because we cannot read it. This is the same trade-off that protects your privacy.
7. Your choices and controls
- Edit or delete any item at any time. Deleted items sit in Trash and are permanently removed after 30 days.
- Turn off sync by signing out of Done Cloud; your data stays on your device.
- Delete your account. In Settings, Account, Delete Account, you can permanently erase all of your Done Cloud data and your account identity from our systems. This is immediate and irreversible.
- Remove everything by deleting the app from your devices.
8. Your privacy rights
Wherever you live, we give everyone the same core rights:
- Know / access: ask what account information and activity metadata we hold about you.
- Delete: erase your account and all associated data yourself in Settings, Account, Delete Account, or by contacting us.
- No sale, no ad tracking: we do not sell or share your personal information, and we do not use it for cross-context behavioral advertising. We will not discriminate against you for exercising any right.
If you are in the EU/UK, our legal basis for processing the limited account information above is performing our contract with you (providing sync) and our legitimate interest in operating and securing the service. To exercise any right, email support@done-os.app.
9. Children's privacy
Done is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect information from children. If you believe a child has provided information, contact support@done-os.app.
10. Changes to this policy
We may update this policy as Done evolves. We will revise the "Last updated" date above, and significant changes will be communicated in-app or by other reasonable means. Continued use after an update means you accept the revised policy.
11. Contact
Questions or requests about your privacy: support@done-os.app.
