This summary is here to orient you. It is not a substitute for the full policy below, which is what legally applies.
We have never sold or shared personal information for advertising, and there is no advertising network, ad SDK or third-party behavioural tracker anywhere in Todaili.
Messages and their attachments are automatically and permanently deleted 30 days after they are sent. Todaili is not a message archive.
If you grant contacts permission, we upload a name and one phone number per contact so we can show you who already uses Todaili. See section 3.3 — you can decline.
Your data is encrypted in transit and at rest, but not end-to-end. Todaili is technically able to access your content. See section 11.
Only business owners, only when they tap “Use my current location”, and never in the background. See section 3.5.
Settings → Delete Account removes your account and personal data within 30 days. See sections 12 and 14.
Todaili is an app for creating, managing and sharing events and tasks, chatting with other people, and booking appointments with businesses that use Todaili to manage their calendars.
This Privacy Policy is issued by Todaili Ltd. (“Todaili”, “we”, “us”, “our”). We are the controller of the personal information described here, except where section 6.4 says otherwise.
It applies to:
It does not apply to a business’s own handling of your information outside Todaili, or to any other website or service that we link to. Please read this policy together with our Terms of Use, which govern your use of Todaili.
We obtain personal information in four ways:
We do not collect a password, an email address, a date of birth, a government identifier, or any payment-card details. We do not offer sign-in with Google, Apple or Facebook, so no social network is told that you use Todaili.
If you grant Todaili permission to read your contacts, the app uploads to our servers the display name and one phone number for every contact in your device address book — not only the people you choose to message. We use this solely to tell you which of your contacts already use Todaili, to show their saved name instead of a bare number, and to let you invite the rest. We do not use it to build profiles of people who are not Todaili users, we do not market to your contacts, and we never disclose your address book to anyone else.
This permission is optional. If you refuse it, Todaili works — you simply type phone numbers instead of picking names. You can revoke it at any time in your device settings, and you can ask us to delete the contacts we already hold (see section 13).
If you grant it, you confirm that you are entitled to share your contacts’ details with us for this purpose, as set out in our Terms of Use.
Todaili contains no third-party analytics, advertising or crash-reporting SDK — no Firebase Analytics, no Crashlytics, no Sentry, no Mixpanel, no ad network, and no session-replay tool. Usage data goes only to our own servers.
If you run a business in Todaili, you can set your business address by tapping “Use my current location” while editing your business profile. Only then does the app read your device’s location, and it asks for precise location so that the map pin lands on your actual doorstep rather than somewhere in the neighbourhood. We store the resulting address and its coordinates as part of your business profile.
Todaili never collects your location in the background, never tracks your movements, and never asks for location anywhere else in the app. Setting an address this way is always optional — you can type the address instead, or leave it blank. Clearing the address deletes the stored coordinates with it.
Todaili uses no advertising or analytics cookies, and shows no cookie banner because none is required. The web booking app stores a small amount of information in your browser’s local and session storage, all of it strictly necessary: your chosen language, your signed-in session (managed by Firebase Authentication), the page you were heading to before signing in, and whether you have already dismissed the “get the app” prompt. Clearing your browser storage removes all of it and signs you out.
Where paid plans are offered, subscriptions are sold and billed by Apple through the App Store or by Google through Google Play, and we use RevenueCat to keep track of what you are entitled to. We receive the purchase record — which plan, whether it is active, and when it renews or expires. We never receive or store your payment card, bank details or billing address.
Where the EU or UK General Data Protection Regulation applies to you, the table below gives our legal basis for each purpose. Otherwise, we process your information with your consent and as necessary to provide the service you asked for.
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create your account and verify your phone number by SMS | Only a verified number can be an identity in Todaili | Performance of our contract with you |
| Store and synchronise your events, tasks, chats and appointments across your devices | This is the service itself | Performance of our contract |
| Send reminders, chat notifications and booking confirmations | Core functionality you have asked for | Performance of our contract |
| Match your uploaded contacts against registered users | To show you who already uses Todaili and let you invite the rest | Your consent, given through the device permission prompt |
| Read your device location for a business address | To place your business on the map for your members | Your consent, given through the device permission prompt |
| Generate AI replies and event suggestions in the Todaili assistant chat | To let you schedule things in ordinary language | Performance of our contract; see section 5 |
| Diagnose crashes and errors, and keep server logs | To keep the service working and secure | Our legitimate interest in a reliable, secure service |
| Measure how features are used, in aggregate | To decide what to build and improve | Our legitimate interest in improving our product |
| Detect, investigate and prevent abuse, fraud and violations of our Terms | To protect users and Todaili | Our legitimate interest in protecting the service; legal obligation |
| Manage subscriptions and entitlements | To give you what you paid for and to enforce plan limits | Performance of our contract; legal obligation (accounting) |
| Respond to your support requests | To help you | Performance of our contract; legitimate interest |
| Comply with law and respond to lawful requests | Because we must | Legal obligation |
We do not use your personal information to make decisions about you by purely automated means that produce legal or similarly significant effects.
Todaili includes an AI assistant chat that turns ordinary sentences such as “dentist next Tuesday at four” into a suggested event you can accept or discard.
When you join a business and book an appointment, the business owner sees your name, your profile photo, your phone number, your appointment history with them, and anything you write in a booking note or in your chat with them. They need this to run their calendar and to contact you about your appointment.
Your business profile — its name, description, images, contact details and address — is shown to your members and to anyone who opens a booking link you share. Treat it as published business information.
A business owner decides for themselves how to use the member and appointment information they see in Todaili, including outside the app. For that use they are an independent controller and we are not responsible for it. Their own privacy practices are a matter between you and them. Within Todaili, we process that information on their behalf as their processor, under our Terms of Use.
We keep the list short on purpose. Each of these providers acts on our instructions, is bound by confidentiality and data protection obligations, and may use the data only to provide their service to us — never for their own purposes.
| Provider | What they process | Purpose | Where |
|---|---|---|---|
| Google Cloud Platform | All application data — the database, uploaded media, server logs, backups | Hosting and storage | Israel; EU (media and backups) |
| Google Firebase | Sign-in tokens; push notification tokens and message payload metadata | Authentication and push notifications | Global Google infrastructure |
| Google Cloud Vertex AI | Messages you send to the Todaili assistant; language, country and time zone | AI replies and event suggestions | United States |
| Google Maps Platform | Address text or coordinates when a business address is being set | Address lookup and map images | Global Google infrastructure |
| Twilio | Your phone number and the one-time verification code | Sending the SMS that verifies your number | United States / Ireland |
| Apple, Google (app stores) | Purchase and subscription records | Selling and billing subscriptions | Per each store’s own terms |
| RevenueCat | Store purchase receipts and an app-specific identifier | Tracking subscription entitlements | United States |
Requests to Google Maps are made by our servers, not by your device, so your Todaili account is not identified to Google Maps.
We have never sold personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act. Todaili contains no advertising, no ad identifiers and no ad or tracking SDK. We do not disclose your information to data brokers, and we do not use your content to build advertising profiles of you or of your contacts.
Israel benefits from an adequacy decision of the European Commission, which means personal data may be transferred from the European Economic Area to Israel without further safeguards. For transfers to the United States we rely on the European Commission’s Standard Contractual Clauses, or another approved transfer mechanism, as incorporated into our agreements with the relevant provider.
| Information | How long we keep it |
|---|---|
| Chat messages and their attachments | Automatically and permanently deleted 30 days after they are sent. This runs every hour and cannot be undone or opted out of. Do not use Todaili chat to store anything you need to keep. |
| Events, tasks, goals, reminders and notes | Until you delete them, or until your account is deleted |
| Contacts uploaded from your device | Until the contact is removed from your device and the app next synchronises, until you ask us to delete them, or until your account is deleted |
| Business profile, services and working hours | Until the owner deletes them or the business is deleted |
| Appointments | As part of the business’s booking record, until deleted by you or the business owner, or until either account is deleted |
| Diagnostic and error reports | Up to 90 days |
| Server logs | Typically 30 days |
| Usage events | While your account exists; removed when it is deleted |
| Account record and profile | Deleted within 30 days of your deletion request |
| Database backups | A rolling window of up to 7 days, after which deleted data disappears from backups too |
| Records we must keep by law | For the period the law requires — for example accounting records relating to a subscription |
We take security seriously, and we would rather be exact than impressive:
Todaili does not provide end-to-end encryption. Messages, attachments and events are encrypted in transit and at rest, but they are not encrypted in a way that prevents us from reading them. Todaili is technically capable of accessing your content, and may do so where it is necessary to operate the service, to investigate abuse, or to comply with a lawful request. If you need end-to-end encrypted messaging, use a service that offers it.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and we do not do so.
Subject to the law that applies to you, you have the right to ask us to: give you access to the personal information we hold about you; correct information that is wrong or incomplete; delete your information; restrict or object to our processing of it, including processing based on our legitimate interests; provide your information in a portable, machine-readable format; and withdraw any consent you have given, without affecting processing already carried out.
How to exercise them. Most of this you can do yourself in the app. For anything else, email support@todaili.com from the account you wish to act on, or tell us the phone number registered to it, so that we can verify the request. We will respond within 30 days. Exercising your rights is free; we may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive, and we will explain why.
The rights above are those given to you by the GDPR and UK GDPR. You also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.
You have the right under the Protection of Privacy Law, 5741-1981, to inspect information held about you and to request that it be corrected or deleted. Contact us at the address in section 18. You may also contact the Privacy Protection Authority.
You have the right to know what personal information we collect, use and disclose, to request its deletion or correction, and to opt out of its sale or sharing — of which there is none, as section 8 explains. We will not discriminate against you for exercising any of these rights. You may use an authorised agent; we will ask for proof of authorisation. The categories we collect, our purposes and the categories of recipient are set out in sections 3, 4 and 7. We do not knowingly collect or sell the personal information of anyone under 16.
You can delete your account, permanently, from inside the app:
Settings → Delete Account → confirm.
When you do, we delete your account record and your personal information within 30 days, including:
Two honest limitations.
Deletion is permanent and cannot be undone. We cannot restore a deleted account, and we cannot recover chat messages that the 30-day cleanup has already deleted.
A small amount of information may survive deletion where we are legally required to keep it, or where it is needed to resolve a dispute or enforce our agreements. It is kept only for that purpose and only for as long as necessary. Deleted data also disappears from our backups as the rolling backup window passes.
Todaili is not intended for children under 13, and you may not use it if you are under 13. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete the account and the information promptly. If you believe a child under 13 has given us personal information, contact us at support@todaili.com.
If you are in the European Economic Area or the United Kingdom and are under 16 (or under the age of digital consent in your country, where it is higher), you may use Todaili only with the consent of a parent or guardian, who must give that consent and accept our Terms of Use on your behalf. A parent or guardian may contact us at any time to review, correct or delete their child’s information.
If a security incident affects your personal information and is likely to result in a risk to your rights, we will notify you and the relevant authorities without undue delay, and within the time limits the applicable law requires. We will tell you what happened, what information was involved, and what we and you can do about it.
We may update this policy to reflect changes in the service, our practices, or the law. When we do, we will update the date at the top and post the updated policy here. If the change is material — for example a new category of data, a new purpose, or a new recipient — we will give you prominent notice in the app, and where the law requires it we will ask for your consent before the change applies to you.
For any question about this policy, about how we handle your information, or to exercise any of your rights:
We aim to reply promptly and in any event within 30 days.