Todaili Privacy Policy

Last updated: 22 September 2026

At a glance

This summary is here to orient you. It is not a substitute for the full policy below, which is what legally applies.

We do not sell your data

We have never sold or shared personal information for advertising, and there is no advertising network, ad SDK or third-party behavioural tracker anywhere in Todaili.

Chats are deleted after 30 days

Messages and their attachments are automatically and permanently deleted 30 days after they are sent. Todaili is not a message archive.

Your address book is uploaded

If you grant contacts permission, we upload a name and one phone number per contact so we can show you who already uses Todaili. See section 3.3 — you can decline.

There is no end-to-end encryption

Your data is encrypted in transit and at rest, but not end-to-end. Todaili is technically able to access your content. See section 11.

Location is opt-in and rare

Only business owners, only when they tap “Use my current location”, and never in the background. See section 3.5.

You can delete everything

Settings → Delete Account removes your account and personal data within 30 days. See sections 12 and 14.

Contents

  1. Who we are and what this policy covers
  2. Where your information comes from
  3. The information we collect
  4. Why we use your information, and our legal bases
  5. The Todaili AI assistant
  6. What other people can see
  7. Service providers who process data for us
  8. We do not sell or advertise
  9. Where your information is stored and transferred
  10. How long we keep information
  11. How we protect information — and what we do not claim
  12. Your choices and controls
  13. Your legal rights
  14. Deleting your account
  15. Children and young people
  16. Security incidents
  17. Changes to this policy
  18. How to contact us

1. Who we are and what this policy covers

Todaili is an app for creating, managing and sharing events and tasks, chatting with other people, and booking appointments with businesses that use Todaili to manage their calendars.

This Privacy Policy is issued by Todaili Ltd. (“Todaili”, “we”, “us”, “our”). We are the controller of the personal information described here, except where section 6.4 says otherwise.

It applies to:

It does not apply to a business’s own handling of your information outside Todaili, or to any other website or service that we link to. Please read this policy together with our Terms of Use, which govern your use of Todaili.

2. Where your information comes from

We obtain personal information in four ways:

3. The information we collect

3.1 Account and profile information

We do not collect a password, an email address, a date of birth, a government identifier, or any payment-card details. We do not offer sign-in with Google, Apple or Facebook, so no social network is told that you use Todaili.

3.2 Content you create

3.3 Your contacts — please read this section

If you grant Todaili permission to read your contacts, the app uploads to our servers the display name and one phone number for every contact in your device address book — not only the people you choose to message. We use this solely to tell you which of your contacts already use Todaili, to show their saved name instead of a bare number, and to let you invite the rest. We do not use it to build profiles of people who are not Todaili users, we do not market to your contacts, and we never disclose your address book to anyone else.

This permission is optional. If you refuse it, Todaili works — you simply type phone numbers instead of picking names. You can revoke it at any time in your device settings, and you can ask us to delete the contacts we already hold (see section 13).

If you grant it, you confirm that you are entitled to share your contacts’ details with us for this purpose, as set out in our Terms of Use.

3.4 Technical and usage information

Todaili contains no third-party analytics, advertising or crash-reporting SDK — no Firebase Analytics, no Crashlytics, no Sentry, no Mixpanel, no ad network, and no session-replay tool. Usage data goes only to our own servers.

3.5 Location — business owners only

If you run a business in Todaili, you can set your business address by tapping “Use my current location” while editing your business profile. Only then does the app read your device’s location, and it asks for precise location so that the map pin lands on your actual doorstep rather than somewhere in the neighbourhood. We store the resulting address and its coordinates as part of your business profile.

Todaili never collects your location in the background, never tracks your movements, and never asks for location anywhere else in the app. Setting an address this way is always optional — you can type the address instead, or leave it blank. Clearing the address deletes the stored coordinates with it.

3.6 Cookies and local storage

Todaili uses no advertising or analytics cookies, and shows no cookie banner because none is required. The web booking app stores a small amount of information in your browser’s local and session storage, all of it strictly necessary: your chosen language, your signed-in session (managed by Firebase Authentication), the page you were heading to before signing in, and whether you have already dismissed the “get the app” prompt. Clearing your browser storage removes all of it and signs you out.

3.7 Subscription information

Where paid plans are offered, subscriptions are sold and billed by Apple through the App Store or by Google through Google Play, and we use RevenueCat to keep track of what you are entitled to. We receive the purchase record — which plan, whether it is active, and when it renews or expires. We never receive or store your payment card, bank details or billing address.

4. Why we use your information, and our legal bases

Where the EU or UK General Data Protection Regulation applies to you, the table below gives our legal basis for each purpose. Otherwise, we process your information with your consent and as necessary to provide the service you asked for.

What we do Why Legal basis (GDPR)
Create your account and verify your phone number by SMS Only a verified number can be an identity in Todaili Performance of our contract with you
Store and synchronise your events, tasks, chats and appointments across your devices This is the service itself Performance of our contract
Send reminders, chat notifications and booking confirmations Core functionality you have asked for Performance of our contract
Match your uploaded contacts against registered users To show you who already uses Todaili and let you invite the rest Your consent, given through the device permission prompt
Read your device location for a business address To place your business on the map for your members Your consent, given through the device permission prompt
Generate AI replies and event suggestions in the Todaili assistant chat To let you schedule things in ordinary language Performance of our contract; see section 5
Diagnose crashes and errors, and keep server logs To keep the service working and secure Our legitimate interest in a reliable, secure service
Measure how features are used, in aggregate To decide what to build and improve Our legitimate interest in improving our product
Detect, investigate and prevent abuse, fraud and violations of our Terms To protect users and Todaili Our legitimate interest in protecting the service; legal obligation
Manage subscriptions and entitlements To give you what you paid for and to enforce plan limits Performance of our contract; legal obligation (accounting)
Respond to your support requests To help you Performance of our contract; legitimate interest
Comply with law and respond to lawful requests Because we must Legal obligation

We do not use your personal information to make decisions about you by purely automated means that produce legal or similarly significant effects.

5. The Todaili AI assistant

Todaili includes an AI assistant chat that turns ordinary sentences such as “dentist next Tuesday at four” into a suggested event you can accept or discard.

6. What other people can see

6.1 Other Todaili users

6.2 Businesses you book with

When you join a business and book an appointment, the business owner sees your name, your profile photo, your phone number, your appointment history with them, and anything you write in a booking note or in your chat with them. They need this to run their calendar and to contact you about your appointment.

6.3 Businesses you run

Your business profile — its name, description, images, contact details and address — is shown to your members and to anyone who opens a booking link you share. Treat it as published business information.

6.4 Business owners are independent controllers

A business owner decides for themselves how to use the member and appointment information they see in Todaili, including outside the app. For that use they are an independent controller and we are not responsible for it. Their own privacy practices are a matter between you and them. Within Todaili, we process that information on their behalf as their processor, under our Terms of Use.

6.5 Other disclosures

7. Service providers who process data for us

We keep the list short on purpose. Each of these providers acts on our instructions, is bound by confidentiality and data protection obligations, and may use the data only to provide their service to us — never for their own purposes.

Provider What they process Purpose Where
Google Cloud Platform All application data — the database, uploaded media, server logs, backups Hosting and storage Israel; EU (media and backups)
Google Firebase Sign-in tokens; push notification tokens and message payload metadata Authentication and push notifications Global Google infrastructure
Google Cloud Vertex AI Messages you send to the Todaili assistant; language, country and time zone AI replies and event suggestions United States
Google Maps Platform Address text or coordinates when a business address is being set Address lookup and map images Global Google infrastructure
Twilio Your phone number and the one-time verification code Sending the SMS that verifies your number United States / Ireland
Apple, Google (app stores) Purchase and subscription records Selling and billing subscriptions Per each store’s own terms
RevenueCat Store purchase receipts and an app-specific identifier Tracking subscription entitlements United States

Requests to Google Maps are made by our servers, not by your device, so your Todaili account is not identified to Google Maps.

8. We do not sell or advertise

We have never sold personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in the California Consumer Privacy Act. Todaili contains no advertising, no ad identifiers and no ad or tracking SDK. We do not disclose your information to data brokers, and we do not use your content to build advertising profiles of you or of your contacts.

9. Where your information is stored and transferred

Israel benefits from an adequacy decision of the European Commission, which means personal data may be transferred from the European Economic Area to Israel without further safeguards. For transfers to the United States we rely on the European Commission’s Standard Contractual Clauses, or another approved transfer mechanism, as incorporated into our agreements with the relevant provider.

10. How long we keep information

Information How long we keep it
Chat messages and their attachments Automatically and permanently deleted 30 days after they are sent. This runs every hour and cannot be undone or opted out of. Do not use Todaili chat to store anything you need to keep.
Events, tasks, goals, reminders and notes Until you delete them, or until your account is deleted
Contacts uploaded from your device Until the contact is removed from your device and the app next synchronises, until you ask us to delete them, or until your account is deleted
Business profile, services and working hours Until the owner deletes them or the business is deleted
Appointments As part of the business’s booking record, until deleted by you or the business owner, or until either account is deleted
Diagnostic and error reports Up to 90 days
Server logs Typically 30 days
Usage events While your account exists; removed when it is deleted
Account record and profile Deleted within 30 days of your deletion request
Database backups A rolling window of up to 7 days, after which deleted data disappears from backups too
Records we must keep by law For the period the law requires — for example accounting records relating to a subscription

11. How we protect information — and what we do not claim

We take security seriously, and we would rather be exact than impressive:

Todaili does not provide end-to-end encryption. Messages, attachments and events are encrypted in transit and at rest, but they are not encrypted in a way that prevents us from reading them. Todaili is technically capable of accessing your content, and may do so where it is necessary to operate the service, to investigate abuse, or to comply with a lawful request. If you need end-to-end encrypted messaging, use a service that offers it.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, and we do not do so.

12. Your choices and controls

13. Your legal rights

Subject to the law that applies to you, you have the right to ask us to: give you access to the personal information we hold about you; correct information that is wrong or incomplete; delete your information; restrict or object to our processing of it, including processing based on our legitimate interests; provide your information in a portable, machine-readable format; and withdraw any consent you have given, without affecting processing already carried out.

How to exercise them. Most of this you can do yourself in the app. For anything else, email support@todaili.com from the account you wish to act on, or tell us the phone number registered to it, so that we can verify the request. We will respond within 30 days. Exercising your rights is free; we may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive, and we will explain why.

13.1 If you are in the European Economic Area or the United Kingdom

The rights above are those given to you by the GDPR and UK GDPR. You also have the right to lodge a complaint with your local supervisory authority. We would appreciate the chance to address your concern first.

13.2 If you are in Israel

You have the right under the Protection of Privacy Law, 5741-1981, to inspect information held about you and to request that it be corrected or deleted. Contact us at the address in section 18. You may also contact the Privacy Protection Authority.

13.3 If you are in California

You have the right to know what personal information we collect, use and disclose, to request its deletion or correction, and to opt out of its sale or sharing — of which there is none, as section 8 explains. We will not discriminate against you for exercising any of these rights. You may use an authorised agent; we will ask for proof of authorisation. The categories we collect, our purposes and the categories of recipient are set out in sections 3, 4 and 7. We do not knowingly collect or sell the personal information of anyone under 16.

14. Deleting your account

You can delete your account, permanently, from inside the app:

Settings → Delete Account → confirm.

When you do, we delete your account record and your personal information within 30 days, including:

Two honest limitations.

  • Messages you already sent to a chat that other people are in may remain visible to those people until the automatic 30-day deletion removes them. We cannot reach into other participants’ copies of a conversation.
  • Events you created and shared with other people may remain in their calendars, because those items are theirs to keep as much as yours.

Deletion is permanent and cannot be undone. We cannot restore a deleted account, and we cannot recover chat messages that the 30-day cleanup has already deleted.

A small amount of information may survive deletion where we are legally required to keep it, or where it is needed to resolve a dispute or enforce our agreements. It is kept only for that purpose and only for as long as necessary. Deleted data also disappears from our backups as the rolling backup window passes.

15. Children and young people

Todaili is not intended for children under 13, and you may not use it if you are under 13. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete the account and the information promptly. If you believe a child under 13 has given us personal information, contact us at support@todaili.com.

If you are in the European Economic Area or the United Kingdom and are under 16 (or under the age of digital consent in your country, where it is higher), you may use Todaili only with the consent of a parent or guardian, who must give that consent and accept our Terms of Use on your behalf. A parent or guardian may contact us at any time to review, correct or delete their child’s information.

16. Security incidents

If a security incident affects your personal information and is likely to result in a risk to your rights, we will notify you and the relevant authorities without undue delay, and within the time limits the applicable law requires. We will tell you what happened, what information was involved, and what we and you can do about it.

17. Changes to this policy

We may update this policy to reflect changes in the service, our practices, or the law. When we do, we will update the date at the top and post the updated policy here. If the change is material — for example a new category of data, a new purpose, or a new recipient — we will give you prominent notice in the app, and where the law requires it we will ask for your consent before the change applies to you.

18. How to contact us

For any question about this policy, about how we handle your information, or to exercise any of your rights:

We aim to reply promptly and in any event within 30 days.