OneTask privacy policy
Your iPhone tasks stay yours.
OneTask keeps native iPhone todo and task data local to your device. The optional Web and Android waitlist and the support form are separate website services and only collect the information needed to provide those services.
Data controller and contact
The data controller for the OneTask website services is OneTask, published by Yuss9. Privacy and data requests can be sent through the support form or by email to support@onetask.yuss.dev.
Task data stays local on your iPhone
The OneTask iPhone app stores tasks locally in Apple's App Group container so the main app, widgets and Share extension can work with the same task data on the same device. Live Activities are also driven locally. Creating, completing, pinning, archiving, sharing into OneTask and restoring tasks does not require a OneTask account or remote task database, and native task data is not uploaded to the OneTask website.
Manual JSON backup export and restore are user-initiated. Restore files are validated before replacement, and OneTask may keep a local recovery copy of the previous database on the same device so an accidental or failed restore can be recovered. These files are not transmitted to OneTask servers by the app.
Local notifications and visible system surfaces
Task reminders, optional Daily Brief notifications, Focus completion alerts, Carry Over and Weekly Review alerts are scheduled locally through iOS. OneTask does not send task content to a OneTask server to deliver these notifications. Daily Brief is off by default and is scheduled only after you explicitly enable it and notification permission is available. Siri and the Share extension can preserve a reminder time you include in a captured task and schedule it locally when iOS notification permission is already allowed.
iOS controls how notification, widget and Live Activity content appears on the Lock Screen, Dynamic Island and other system surfaces. Optional Face ID Lock protects the main OneTask app interface; it does not override the notification or widget visibility choices you make in iOS Settings. You can change OneTask notification and Lock Screen visibility at any time in the system Settings app.
Waitlist data
If you join the OneTask Web or Android waitlist, OneTask stores your normalized email address, selected platform and signup timestamp in PostgreSQL. One email represents one waitlist signup, and submitting the same email again does not create another row.
Support data
When you send a support request, OneTask stores the name you provide, your email address, subject, message, request status and submission timestamp. This information is used only to review, manage and answer your request.
Purpose and legal basis
Waitlist data is processed to remember your request to hear about future Web or Android availability. The legal basis is your consent, which you can withdraw at any time. Support data is processed to answer requests, resolve problems and manage privacy requests based on OneTask's legitimate interest in providing and supporting the service and, where applicable, taking steps at your request.
Retention
Waitlist entries are kept until the relevant launch and communication cycle is complete or until you ask for deletion. Inactive waitlist entries are reviewed for deletion after 24 months. Support requests are normally kept for up to 24 months after the last exchange so recurring issues and prior answers can be understood, unless a longer period is required by law or to establish, exercise or defend legal claims.
Withdrawal and deletion
You can leave the waitlist or request deletion of your website personal data at any time. Use the support form with a subject such as “Delete my data”, or email support@onetask.yuss.dev from the same address you used for the waitlist or support request. OneTask will use the email only to verify and process the request and aims to complete valid deletion requests within 30 days, unless retention is legally required.
Anti-spam and abuse prevention
Public forms use a honeypot and lightweight rate limiting. Rate limiting uses temporary in-memory hashes derived from network addresses. Raw network addresses are not written to the OneTask application database for this purpose, and the temporary rate-limit state disappears when the application process restarts. Hosting or reverse-proxy infrastructure may still create normal operational logs independently of the application database.
What OneTask does not do
The website does not receive your native iPhone task list, does not expose a public endpoint for listing waitlist or support records, and does not sell personal data. OneTask is not designed around advertising profiles or behavioral advertising.
Security and processors
Website data is stored in the infrastructure used to operate OneTask and is protected with application validation, database access controls, HTTPS, security headers and restricted public endpoints. Service providers used to host or operate the website may process data only as necessary to provide their infrastructure services.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal data, and to withdraw consent. Contact OneTask through the support page to exercise these rights. You may also have the right to complain to your local data-protection authority.
Changes to this privacy notice
This privacy notice may be updated when OneTask's website features or data practices change. The current version is always published on this page.