← qoro todo

개인정보처리방침

시행일: 2026년 7월 21일 · 최종 개정일: 2026년 7월 31일

한국어 · English version below ↓

qoro todo(이하 “서비스”)는 이용자의 Google 계정 하나로 캘린더 일정·할 일·가계부를 한곳에서 관리하도록 돕는 웹 애플리케이션입니다. 서비스는 개인 개발자가 운영하며, 이 방침은 서비스가 Google 사용자 데이터를 포함한 개인정보를 어떻게 처리하는지 설명합니다.

Google API Services User Data Policy 필수 고지 항목 위치

1. 접근하는 Google 사용자 데이터 (What data we access)

서비스가 요청하는 OAuth 범위(scope)와, 각 범위로 접근하는 데이터는 다음과 같습니다. 아래 목록이 전부이며 그 외의 Google 데이터에는 접근하지 않습니다.

  • openid, https://www.googleapis.com/auth/userinfo.email
    → Google 계정의 고유 식별자와 이메일 주소. 로그인 및 이용자 식별에 사용합니다.
  • https://www.googleapis.com/auth/userinfo.profile
    이름·프로필 사진 등 기본 공개 프로필. 로그인을 처리하는 인증 제공자(Supabase Auth)가 표준으로 함께 요청하는 범위입니다. 서비스는 이 정보를 별도로 저장하거나 활용하지 않습니다.
  • https://www.googleapis.com/auth/calendar.events
    → 이용자 기본 캘린더(primary)의 일정(제목, 일시, 메모 등)을 조회·생성·수정·삭제합니다. 캘린더 목록·공유 설정·다른 캘린더에는 접근하지 않으며, 그래서 더 넓은 .../auth/calendar 범위를 요청하지 않습니다.
  • https://www.googleapis.com/auth/tasks
    → 이용자 기본 할 일 목록(@default)의 할 일을 조회·생성·수정·삭제·순서 변경합니다. 할 일 작성·완료 처리가 서비스의 핵심 기능이므로 읽기 전용 범위로는 대체할 수 없습니다.
  • https://www.googleapis.com/auth/drive.appdata
    → 이용자 Drive의 앱 전용 숨김 폴더(appDataFolder)에만 접근합니다. 가계부 내역·카드·카테고리·할 일 메타데이터를 기기 간 동기화하기 위한 용도이며, 이용자의 다른 Drive 파일·폴더는 조회할 수도, 접근할 수도 없습니다.

그 밖에 서비스는 대한민국 공휴일 표시를 위해 Google이 공개한 공개 공휴일 캘린더를 읽습니다. 이는 모든 사람에게 공개된 캘린더로 이용자 개인의 데이터가 아닙니다.

서비스는 위 항목 외에 별도의 회원가입 정보, 결제 정보, 주민등록번호 등 고유식별정보, 건강·신념 등 민감정보를 수집하지 않습니다.

2. 데이터 사용 방식 (How we use it)

서비스는 접근한 Google 사용자 데이터를 오직 이용자 본인에게 요청받은 기능을 제공하기 위한 목적으로만 사용합니다.

  • 일정: 달력·일간 화면에 이용자의 일정을 표시하고, 이용자가 화면에서 추가·수정·삭제한 내용을 이용자의 Google Calendar에 반영합니다.
  • 할 일: 할 일 목록을 표시하고, 이용자의 추가·완료·순서 변경·삭제를 Google Tasks에 반영합니다.
  • 앱 데이터 폴더: 이용자가 입력한 가계부·카드·카테고리·할 일 메타데이터를 이용자 본인의 Drive 숨김 폴더에 저장하여, 다른 기기에서도 같은 내용을 보게 합니다.
  • 이메일 주소: 이용자 식별과 로그인 상태 유지, 이용자가 보낸 문의에 대한 회신에만 사용합니다.

서비스는 이용자의 개인 일정·할 일·가계부 콘텐츠를 서비스 서버에 저장하지 않습니다. 해당 콘텐츠의 정본은 이용자 본인의 Google 계정에 있으며, 서비스는 이를 표시·편집하기 위해 이용자의 브라우저에서 Google API를 호출할 뿐입니다.

첫 번째 예외는 모임캘린더입니다. 이용자가 모임캘린더에 등록한 일정(제목·일시·장소·메모)과 모임 참여 정보(모임 이름, 표시이름, 색)는 같은 모임의 다른 참여자에게 보여주기 위해 서비스 서버(Supabase)에 저장됩니다. 이 데이터는 Google 사용자 데이터가 아니라 이용자가 서비스에 직접 입력한 데이터입니다. 모임에서 나가거나 모임이 삭제되면 해당 데이터도 함께 삭제됩니다.

두 번째 예외는 일정 공유 링크입니다. 이용자가 어떤 일정에서 ‘공유 링크 생성’을 직접 누르면, 그 일정 한 건의 내용(제목·일시·장소·메모·알림·반복)이 그 시점의 사본으로 서비스 서버(Supabase)에 저장됩니다. 모임캘린더와 달리 이 사본은 Google 캘린더에서 읽어 온 일정일 수 있습니다 — 링크로 일정을 보내는 기능의 성격상 그 내용이 서버를 거치지 않을 방법이 없기 때문이며, 그 이전은 이용자가 그 버튼을 눌렀을 때에만 일어납니다.
이 사본은 링크(추측할 수 없는 32자리 무작위 주소)를 아는 사람이면 누구나 로그인 없이 볼 수 있고, 생성 후 3일이 지나면 서버에서 삭제됩니다. 링크가 열린 횟수와 그 일정을 자기 캘린더에 저장한 이용자 수도 함께 기록되며(집계용 숫자만 저장하고, 누가 열었는지는 저장하지 않습니다), 같은 3일 뒤 함께 삭제됩니다.
공유하지 않은 일정에 대해서는 이 이전이 전혀 일어나지 않습니다. 즉 Google 캘린더·할 일·Drive의 내용이 서비스 서버로 옮겨지는 경우는 이용자가 명시적으로 공유 링크를 만든 그 일정 한 건뿐입니다.

세 번째 예외는 일정 잡기(모임 시간 조율 투표)입니다. 이용자가 만든 투표의 설정(제목·후보 기간·시간대·마감)과, 링크를 받은 참가자가 직접 입력한 이름과 시간 선택이 서비스 서버(Supabase)에 저장됩니다. 참가자는 로그인 없이 참여하며, 서비스는 참가자에 대해 그 이름과 선택 외의 어떤 정보(계정·연락처 등)도 수집하지 않습니다. 이 데이터는 Google 사용자 데이터가 아니라 이용자와 참가자가 서비스에 직접 입력한 데이터이고, 링크(추측할 수 없는 32자리 무작위 주소)를 아는 사람만 볼 수 있으며, 투표 마감 후 7일이 지나면 만료되어 삭제됩니다. 만든 이용자는 그 전에도 앱에서 투표를 삭제할 수 있고, 삭제하면 참가자들의 이름·선택도 함께 삭제됩니다.

서비스는 Google 사용자 데이터를 광고·마케팅·프로파일링·신용평가·이용자 분석 판매 등 어떤 목적으로도 사용하지 않습니다.

3. 공유·이전·공개 대상 (Who we share it with)

서비스는 이용자의 개인정보와 Google 사용자 데이터를 제3자에게 판매하거나, 광고·마케팅 목적으로 제공하거나, 데이터 브로커에게 이전하지 않습니다.아래 사업자는 서비스 운영에 필수적인 기능을 수행하는 처리위탁(수탁자)이며, 위탁 목적 범위를 벗어난 이용이 계약상 금지됩니다.

  • Google LLC — 위탁 업무: 인증(OAuth) 및 캘린더·할 일·앱 데이터의 저장.
    이전되는 항목: 이용자가 서비스에서 작성·수정한 일정·할 일·앱 데이터. 이는 이용자 본인의 Google 계정으로 되돌아가는 것이며 외부 제3자에게 넘어가는 것이 아닙니다.
  • Supabase Inc. — 위탁 업무: 로그인 세션 관리, 토큰 저장, 모임캘린더·일정 공유 링크·일정 잡기 데이터 저장(데이터베이스 호스팅).
    이전되는 항목: 이메일 주소, Google 계정 식별자, 암호화된 refresh token, 이용자가 모임캘린더에 등록한 일정과 모임 참여 정보, 이용자가 공유 링크를 만든 일정의 내용 사본(3일 후 삭제), 이용자가 만든 일정 잡기 투표 설정과 참가자가 입력한 이름·시간 선택(마감 7일 후 삭제). 그 밖의 개인 일정·할 일·가계부 콘텐츠는 Supabase로 전송되지 않습니다.
  • Vercel Inc. — 위탁 업무: 웹 애플리케이션 호스팅 및 전송.
    이전되는 항목: 접속에 수반되는 표준 요청 기록(IP 주소, User-Agent, 요청 경로). Vercel은 이용자 콘텐츠를 저장하지 않으며, 요청 기록은 장애 대응·보안 목적의 일시 보관에 한합니다.

국외 이전: 위 사업자의 서버는 국외(대한민국 외 리전 포함)에 위치할 수 있으며, 위 항목은 해당 리전에서 저장·처리됩니다. 이용자는 문의처를 통해 국외 이전을 거부할 수 있으나, 이 경우 서비스 이용이 제한됩니다.

그 외의 공개는 법령에 따른 적법한 요구가 있는 경우에 한하며, 이 경우에도 요구된 최소 범위로만 대응합니다.

4. 데이터 보호 메커니즘 (How we protect it)

  • 전송 구간 암호화: 이용자 브라우저 ↔ 서비스 ↔ Google API 사이의 모든 통신은 HTTPS(TLS)로 암호화됩니다. 평문 HTTP 접속은 허용하지 않습니다.
  • 저장 시 암호화: Google이 발급한 refresh token은 데이터베이스에 저장하기 전 AES-256-GCM으로 암호화합니다. 암호화 키는 서버 환경변수로만 관리되며 저장소나 소스 코드에 포함되지 않습니다.
  • 클라이언트 미노출: 암호화된 토큰과 암호화 키는 브라우저로 전송되지 않습니다. 토큰 복호화와 갱신은 서버 측에서만 수행됩니다.
  • 접근 통제: 토큰이 저장된 테이블은 Row Level Security로 보호되며, 서버의 service_role 자격증명으로만 접근할 수 있습니다. 이 자격증명은 서버 환경에만 존재합니다.
  • 액세스 토큰 비저장: 단기 액세스 토큰은 필요한 시점에 발급받아 사용하며 데이터베이스에 영구 저장하지 않습니다.
  • 수집 최소화: 개인 일정·할 일·가계부 콘텐츠는 서비스 서버에 저장하지 않습니다. 모임캘린더 데이터는 서버에 저장되지만, Row Level Security로 해당 모임의 참여자만 읽고 쓸 수 있도록 데이터베이스 수준에서 강제하며, 일정의 수정·삭제는 그 일정을 만든 본인만 가능합니다.
  • 공유 링크의 범위 제한: 공유 링크로 저장된 일정 사본은 주소를 아는 사람만 볼 수 있습니다. 주소는 추측할 수 없는 32자리 무작위 값이고, 데이터베이스에는 이용자·익명 이용자 모두에게 직접 조회 권한이 없어 주소를 인자로 받는 함수 하나로만 읽을 수 있습니다(즉 “유효한 링크 전부”를 조회할 수 없습니다). 사본은 3일 뒤 삭제되며, 이용자는 그 전에도 앱에서 링크를 폐기할 수 있습니다.
  • 일정 잡기의 범위 제한: 일정 잡기 투표도 공유 링크와 같은 구조로 보호됩니다 — 주소는 추측할 수 없는 32자리 무작위 값이고, 이용자·익명 이용자 모두 직접 조회 권한 없이 주소를 인자로 받는 함수로만 읽을 수 있습니다. 참가자의 시간 선택 수정은 참여할 때 그 기기에만 발급되는 비밀값으로만 가능하며, 서버에는 그 비밀값의 해시만 저장됩니다.
  • 사람의 열람 금지: 운영자를 포함해 어떤 사람도 이용자의 Google 사용자 데이터를 열람하지 않습니다(보안 사고 대응, 법적 의무 이행, 이용자의 명시적 동의 등 Google 정책이 허용하는 예외 제외).
  • 기기 내 캐시: 화면 표시 속도를 위해 일부 데이터가 이용자 기기의 브라우저 저장소(IndexedDB)에 캐시로 남을 수 있습니다. 이는 이용자 기기 안에만 있으며 정본이 아닙니다.

5. 보유 기간 및 삭제 절차 (Retention & deletion)

  • 보유 기간(원칙): 이메일 주소와 암호화된 refresh token은 이용자가 Google 계정 연결을 유지하는 동안에만 보관합니다. 목적이 소멸하면 지체 없이 파기합니다.
  • 연결 해제 시: 이용자가 앱 내 메뉴에서 연결을 해제하면 즉시 저장된 암호화 토큰을 삭제하고 Google에 해당 권한 해지(revoke)를 요청합니다.
  • 일정 공유 링크: 공유 링크로 서버에 저장된 일정 사본과 그 열람·저장 집계는 생성 후 3일이 지나면 만료되어 더 이상 열람할 수 없고, 이후 이용자가 앱을 다시 열 때 서버에서 삭제됩니다. 이용자는 만료를 기다리지 않고 앱의 공유 화면에서 ‘링크 폐기’로 즉시 삭제할 수도 있습니다.
  • 일정 잡기: 서버에 저장된 투표 설정과 참가자 이름·시간 선택은 투표 마감 후 7일이 지나면 만료되어 더 이상 열람할 수 없고, 이후 만든 이용자가 앱을 다시 열 때 서버에서 삭제됩니다. 만든 이용자는 만료를 기다리지 않고 앱의 일정 잡기 화면에서 ‘삭제’로 즉시 삭제할 수도 있습니다(참가자의 이름·선택도 함께 삭제됩니다).
  • 미사용 시 자동 만료: Google 정책상 refresh token은 6개월 이상 사용되지 않으면 만료됩니다. 만료되면 서비스는 그 토큰으로 이용자의 어떤 데이터에도 접근할 수 없습니다.
  • 삭제 요청 방법: ilovz73ai@gmail.com 으로 가입 이메일 주소와 함께 삭제를 요청하시면, 접수일로부터 영업일 기준 7일 이내에 저장된 모든 정보를 파기하고 처리 결과를 회신합니다.
  • 파기 방법: 전자적 파일은 복구할 수 없는 방식으로 삭제합니다. 모임캘린더 일정은 다른 기기·다른 참여자와의 동기화를 위해 삭제 표식이 있는 빈 행만 남기고 제목·장소·메모 등 내용은 즉시 지웁니다. 서비스는 결제·거래를 취급하지 않으므로 법령에 따라 별도로 보존해야 하는 기록이 없습니다.
  • 이용자 Google 계정의 데이터: 이용자의 일정·할 일·앱 데이터 폴더 내용은 이용자 본인의 Google 계정에 남아 있으며, 이용자가 Google에서 직접 관리·삭제할 수 있습니다.
  • 권한 직접 철회: 이용자는 언제든 Google 계정 → 보안 → 타사 앱·서비스에서 qoro todo의 접근 권한을 직접 철회할 수 있습니다.
  • 기기 캐시: 브라우저 저장소 캐시는 연결 해제 시 또는 브라우저의 사이트 데이터 삭제로 제거됩니다.

6. 제한적 사용(Limited Use) 및 AI/ML 미사용 확약

qoro todo가 Google API로부터 받은 정보의 사용 및 다른 앱으로의 전송은 Google API 서비스 사용자 데이터 정책(제한적 사용(Limited Use) 요구사항 포함)을 준수합니다.

qoro todo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

구체적으로 qoro todo는:

  • 이용자에게 명시된 기능을 제공하거나 개선하는 목적 외에는 Google 사용자 데이터를 사용하지 않습니다.
  • 광고 게재 목적으로 Google 사용자 데이터를 사용하거나 이전하지 않습니다.
  • Google 사용자 데이터를 판매하거나 데이터 브로커·정보 중개자에게 이전하지 않습니다.
  • Google Workspace API에서 취득한 데이터를 일반화·비개인화(non-personalized) AI 또는 ML 모델의 개발·개선·학습에 사용하지 않으며, 그러한 목적으로 제3자에게 이전하지도 않습니다.
  • 사람이 Google 사용자 데이터를 읽지 않습니다(보안·법적 의무 준수, 이용자의 명시적 동의, 정책상 허용된 예외 제외).

7. 이용자의 권리

이용자는 자신의 개인정보에 대해 열람·정정·삭제·처리정지를 요구할 권리가 있으며, 아래 문의처로 요청할 수 있습니다. 서비스가 보관하는 정보는 이메일 주소, 암호화된 토큰, 이용자가 모임캘린더에 등록한 데이터, 이용자가 공유 링크를 만든 일정의 사본, 그리고 이용자가 만든 일정 잡기 투표와 그 참가자들이 입력한 이름·시간 선택입니다. 앱 내 연결 해제는 이메일·토큰을 즉시 삭제하고, 모임에서 나가기는 그 모임에서의 표시이름·색과 이용자가 그 모임에 올린 일정 내용을 삭제하며, 공유 화면의 링크 폐기는 그 일정 사본과 집계를 즉시 삭제하고, 일정 잡기 화면의 삭제는 그 투표와 참가자들의 이름·선택을 즉시 삭제합니다 (모임을 삭제하면 그 모임의 데이터 전부가 함께 사라지고, 공유 링크 사본은 폐기하지 않아도 3일 뒤, 일정 잡기는 삭제하지 않아도 마감 7일 뒤 만료됩니다). 남은 항목은 아래 문의처로 요청하시면 파기합니다. 만 14세 미만 아동의 개인정보는 수집하지 않습니다.

8. 문의처 및 방침 변경

  • 개인정보 보호책임자 / 운영자 문의: ilovz73ai@gmail.com
  • 서비스 주소: https://qorotodo.ooo
  • 이 방침이 변경되는 경우 시행일 전에 이 페이지에 개정 내용과 시행일을 게시합니다.

Privacy Policy

Effective date: July 21, 2026 · Last updated: July 31, 2026

English · 한국어 원문 보기 ↑

qoro todo (the “Service”) is a web application that lets a user manage calendar events, tasks, and a personal expense ledger in one place using a single Google Account. The Service is operated by an individual developer. This policy explains how the Service handles personal information, including Google user data.

Where each required disclosure appears

1. What Google user data we access

The Service requests the following OAuth scopes. This list is exhaustive; no other Google data is accessed.

  • openid, https://www.googleapis.com/auth/userinfo.email
    → Your Google Account identifier and email address, used to sign you in and identify your account.
  • https://www.googleapis.com/auth/userinfo.profile
    Basic profile information such as your name and profile picture. This scope is requested as standard by the authentication provider (Supabase Auth) that brokers the sign-in. The Service does not separately store or process it.
  • https://www.googleapis.com/auth/calendar.events
    Events on your primary calendar (title, date and time, notes). The Service reads, creates, updates, and deletes them. It never accesses your calendar list, sharing settings, or any other calendar — which is why the broader.../auth/calendar scope is not requested.
  • https://www.googleapis.com/auth/tasks
    Tasks in your default task list (@default). The Service reads, creates, updates, reorders, and deletes them. Creating and completing tasks is a core feature, so a read-only scope would not be sufficient.
  • https://www.googleapis.com/auth/drive.appdata
    → Only the application data folder (appDataFolder) hidden inside your own Google Drive. It is used to sync your expense ledger entries, payment cards, categories, and task metadata across your devices. The Service cannot list or access any other file or folder in your Drive.

In addition, the Service reads Google’s public South Korean holiday calendar to display public holidays. That calendar is publicly readable by anyone and is not personal user data.

The Service does not collect any separate registration data, payment information, government identification numbers, or sensitive categories of data such as health or beliefs.

2. How we use that data

The Service uses Google user data solely to provide the features you requested.

  • Events: displayed on the monthly and daily views; anything you add, edit, or delete in the app is written back to your Google Calendar.
  • Tasks: displayed as your to-do list; additions, completions, reordering, and deletions are written back to Google Tasks.
  • App data folder: stores the ledger, card, category, and task-metadata you enter, in your own hidden Drive folder, so the same content appears on your other devices.
  • Email address: used only to identify your account, keep you signed in, and reply to support requests you send us.

The Service does not store your personal events, tasks, or ledger content on its own servers. The system of record for that content is your own Google Account; the Service simply calls the Google APIs from your browser in order to display and edit it.

The first exception is Shared Calendars.Events you post to a shared calendar (title, time, place, note) and your membership details (calendar name, display name, colour) are stored on the Service’s servers (Supabase) so that other members of that shared calendar can see them. This is data you enter directly into the Service — it is not Google user data. Leaving or deleting a shared calendar deletes that data as well.

The second exception is event share links. When you explicitly press “Create share link” on an event, a point-in-time copyof that single event (title, time, place, note, reminder, repeat) is stored on the Service’s servers (Supabase). Unlike shared calendars, this copy may be an event read from your Google Calendar — sending an event by link cannot work without the content passing through the server — and it happens only when you press that button.
The copy is readable without signing in by anyone who knows the link (an unguessable 32-character random address), and it is deleted from the server 3 days after creation. The number of times the link was opened and the number of users who saved the event to their own calendar are recorded alongside it (counters only — we do not record who opened it), and are deleted at the same time.
No such transfer happens for events you never share. In other words, the only content that ever leaves Google Calendar, Google Tasks, or Google Drive for the Service’s servers is the single event for which you explicitly created a share link.

The third exception is “When shall we meet?” scheduling polls. The poll settings you create (title, candidate period, time band, deadline) and the name and time selections each participant enters directlyare stored on the Service’s servers (Supabase). Participants take part without signing in, and the Service collects nothing about them beyond that name and selection — no account or contact information. This is data entered directly into the Service, not Google user data; it is visible only to someone who knows the link (an unguessable 32-character random address) and is deleted once the poll has been closed for 7 days. The creator can also delete the poll at any time, which deletes the participants’ names and selections with it.

Google user data is never used for advertising, marketing, profiling, credit assessment, or resale of analytics.

3. Who we share, transfer, or disclose data to

The Service does not sell your personal information or Google user data, does not share it for advertising or marketing, and does not transfer it to data brokers. The providers below act solely as processors performing functions essential to operating the Service, and are contractually restricted to those purposes.

  • Google LLC — Purpose: authentication (OAuth) and storage of your calendar events, tasks, and app data.
    Data involved: the events, tasks, and app data you create or edit in the Service. This data returns to your own Google Account; it is not disclosed to an outside third party.
  • Supabase Inc. — Purpose: session management, token storage, shared-calendar storage, event share links, and scheduling polls (database hosting).
    Data involved: your email address, your Google Account identifier, your encrypted refresh token, any events and membership details you enter into a shared calendar, a copy of any event for which you created a share link (deleted after 3 days), and the scheduling polls you create together with the names and time selections participants enter (deleted 7 days after the poll closes). No other personal calendar, task, or ledger content is sent to Supabase.
  • Vercel Inc. — Purpose: web application hosting and delivery.
    Data involved: standard request records incidental to serving the page (IP address, user agent, request path). Vercel does not store your content; request records are retained only briefly for reliability and security purposes.

International transfer: these providers may operate servers outside the Republic of Korea, and the data listed above may be stored and processed in those regions. You may object to such transfer via the contact address below, though this will prevent use of the Service.

Any other disclosure occurs only where required by valid legal process, and then only to the minimum extent required.

4. How we protect that data

  • Encryption in transit: all traffic between your browser, the Service, and the Google APIs is encrypted with HTTPS (TLS). Plain HTTP is not served.
  • Encryption at rest: the Google refresh token is encrypted with AES-256-GCM before it is written to the database. The encryption key exists only as a server-side environment variable and is never committed to source control or storage.
  • Never exposed to the client: neither the encrypted token nor the encryption key is ever sent to the browser. Decryption and token refresh happen exclusively on the server.
  • Access control: the table holding tokens is protected by Row Level Security and is reachable only with the server-side service_role credential, which exists only in the server environment.
  • Access tokens are not persisted: short-lived access tokens are obtained on demand and are never stored in the database.
  • Data minimization as a control: personal calendar, task, and ledger content is not stored on the Service’s servers. Shared-calendar data is stored, and is protected by Row Level Security scoped to the members of that shared calendar; only the member who created an event can edit or delete it.
  • Share links are scoped to the link: an event copy created by a share link is visible only to someone who knows the address. The address is an unguessable 32-character random value, and neither signed-in nor anonymous clients hold any direct read privilege on that table — it is reachable only through a single function that takes the address as an argument, so “every live link” cannot be enumerated. The copy is deleted after 3 days, and you can revoke it sooner from the app.
  • Scheduling polls are scoped the same way: a poll is readable only through a single function that takes its unguessable 32-character address as an argument — neither signed-in nor anonymous clients hold any direct read privilege on those tables. A participant’s selections can be modified only with a secret issued to their device when they join; the server stores only a hash of that secret.
  • No human reads your data: no person, including the operator, reads your Google user data — except where permitted by Google’s policy (security incident response, legal obligations, or your explicit consent).
  • On-device cache: for rendering speed, some data may be cached in your browser storage (IndexedDB). That cache lives only on your device and is not the system of record.

5. How long we retain data, and how to delete it

  • Retention principle: your email address and encrypted refresh token are retained only while your Google Account remains connected to the Service, and are destroyed without delay once that purpose ends.
  • On disconnect: when you disconnect from within the app menu, the stored encrypted token is deleted immediately and the Service asks Google to revoke the grant.
  • Event share links: an event copy stored by a share link, together with its open/save counters, expires 3 days after creation and can no longer be viewed; it is then deleted from the server the next time you open the app. You may also delete it immediately with “Revoke link” on the share screen rather than waiting for expiry.
  • Scheduling polls: a poll’s settings and its participants’ names and time selections expire 7 days after the poll closes and can no longer be viewed; they are then deleted from the server the next time the creator opens the app. The creator may also delete the poll immediately from the app, which deletes the participants’ names and selections as well.
  • Automatic expiry when unused: under Google’s own policy a refresh token expires if it goes unused for 6 months. Once expired, the Service can no longer access any of your data with it.
  • How to request deletion: email ilovz73ai@gmail.com from, or citing, your registered address. All stored information will be destroyed and a confirmation sent within 7 business days of receipt.
  • Method of destruction: electronic records are deleted irrecoverably. For shared-calendar events, an empty row marked as deleted is kept so that other devices and members converge, but its content (title, place, note) is erased at once. The Service handles no payments or transactions, so there are no records it is legally required to retain.
  • Data in your Google Account: your events, tasks, and app data folder contents remain in your own Google Account and can be managed or deleted by you directly in Google.
  • Revoking access yourself: you may revoke qoro todo’s access at any time at Google Account → Security → Your connections to third-party apps & services.
  • Device cache: browser-storage cache is cleared on disconnect, or by clearing site data in your browser.

6. Limited Use disclosure and AI/ML non-use affirmation

qoro todo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, qoro todo:

  • uses Google user data only to provide or improve the user-facing features that are prominent in the app;
  • does not use or transfer Google user data for serving advertisements;
  • does not sell Google user data, and does not transfer it to data brokers or information resellers;
  • does not use Google Workspace APIs data to develop, improve, or train generalized or non-personalized AI and/or ML models, and does not transfer such data to any third party for that purpose;
  • does not allow humans to read Google user data, except for security purposes, to comply with applicable law, with your explicit consent, or as otherwise permitted by the policy.

7. Your rights

You may request access to, correction of, deletion of, or suspension of processing of your personal information using the contact address below. The Service stores your email address, an encrypted token, whatever you have entered into a shared calendar, a copy of any event for which you created a share link, and any scheduling polls you created together with the names and time selections their participants entered. Disconnecting inside the app deletes the email address and token immediately; leaving a shared calendar deletes your display name and colour there along with the content of the events you posted to it; Revoke link on the share screen deletes that event copy and its counters immediately; deleting a scheduling pollremoves it and its participants’ names and selections immediately (deleting a shared calendar removes all of its data, a share-link copy expires after 3 days even if you never revoke it, and a scheduling poll expires on its own 7 days after it closes). Anything remaining is erased on request via the contact address below. The Service does not knowingly collect personal information from children under 14.

8. Contact and changes to this policy

  • Privacy contact / operator: ilovz73ai@gmail.com
  • Service address: https://qorotodo.ooo
  • If this policy changes, the revised text and its effective date will be posted on this page before the change takes effect.