Stability over architecture
Privacy that keeps local work local.
TEND sign-in establishes an identity and a secure session. It does not turn on cloud sync, upload Todo content, or transfer ownership of your local data.
English
1. Scope
This notice covers the optional TEND account and sign-in service. The current Todo product stores tasks and product preferences in your browser. First-stage authentication identifies you but does not copy that Todo data to an account server.
2. Information used for sign-in
When sign-in is enabled and you choose a provider, TEND may process:
- an internal user ID;
- the provider name and stable provider subject identifier;
- display name, email address, and avatar URL returned by the provider;
- whether an Apple email is an Apple relay/private address;
- login, session creation, update, expiry, and revocation timestamps;
- short-lived verification records and security/audit metadata needed to prevent abuse; and
- encrypted provider tokens only when the protocol or a supported revocation flow requires retention.
3. What TEND does not do
- TEND does not sell personal data.
- TEND does not upload or change your local tasks when you sign in or out.
- TEND does not automatically enable cloud sync.
- TEND does not merge accounts by matching an email address. Linking requires an authenticated user and explicit confirmation.
- TEND never asks for an OpenAI API key to sign you in.
4. Providers and service infrastructure
Google and Apple process authorization under their own privacy terms when you choose them. A ChatGPT sign-in option appears only if TEND has official OpenAI authorization and supported OAuth/OIDC configuration; otherwise it remains unavailable. Hosting and database services process only the account-service data needed to serve and secure the account feature.
5. Browser and server storage
Opening the web workspace saves a first-party preference cookie, tend-web-entry=web, for up to one year, refreshed on later visits. It lets the homepage remember your choice of the web app. It contains no task content, account identity, or unique tracking ID. Clearing this cookie makes the homepage show the download page again.
The signed-in session uses a Secure, HttpOnly, SameSite cookie. It is not stored in localStorage, sessionStorage, or Todo IndexedDB data. Account records live in the isolated server database. Local Todo content remains under the browser storage boundary until a separately designed cloud-sync feature obtains explicit consent.
6. Retention and deletion
Sessions expire after inactivity and at an absolute deadline, and can be revoked on sign-out or for security. Short-lived OAuth verification data expires after the flow. Account identity records are retained while the account is active or as reasonably required for security, dispute prevention, and legal obligations. A supported account-deletion request removes or de-identifies account data subject to those limited obligations; it does not erase local browser tasks.
7. Your choices
You can use the local Todo app without signing in, sign out of TEND, revoke TEND in the provider account, or request access, correction, or deletion through the support channel made available with the account service. Signing out of TEND does not sign you out of Google, Apple, or ChatGPT globally.
8. Security and changes
TEND limits browser-visible account data, validates provider responses on the server, restricts redirect origins, and filters sensitive logs. No system can promise perfect security. Material changes to this notice will be reflected by a new effective date before expanded data use is enabled.
中文
1. 适用范围
本说明适用于可选的 TEND 账户与登录服务。当前待办产品把任务和产品偏好保存在你的浏览器中。第一阶段认证只用于确认身份,不会把这些待办数据复制到账户服务器。
2. 登录使用的信息
启用登录后,当你主动选择供应商时,TEND 可能处理:
- 内部用户 ID;
- 供应商名称及稳定的供应商主体标识;
- 供应商返回的显示名称、邮箱地址和头像 URL;
- Apple 邮箱是否为 Apple 隐私转发地址;
- 登录、会话创建、更新、过期和撤销时间;
- 防止滥用所需的短期验证记录和安全审计元数据;以及
- 仅在协议或受支持的撤销流程需要时保存的加密供应商令牌。
3. TEND 不会做什么
- TEND 不会出售个人数据。
- 登录或退出不会上传或更改你的本地任务。
- TEND 不会自动启用云同步。
- TEND 不会仅凭邮箱相同自动合并账户;账户关联要求用户已登录并明确确认。
- TEND 绝不会要求你提供 OpenAI API Key 来完成登录。
4. 供应商与服务基础设施
当你选择 Google 或 Apple 时,它们会依照各自的隐私条款处理授权。只有在 TEND 获得 OpenAI 官方资格并具备受支持的 OAuth/OIDC 配置后,才会提供 ChatGPT 登录;否则该能力保持不可用。托管和数据库服务只处理账户功能运行与安全所需的数据。
5. 浏览器与服务器存储
打开网页版会保存第一方偏好 Cookie:tend-web-entry=web,最长保留一年,后续访问时续期。它只用于让首页记住你选择使用网页版,不包含任务内容、账户身份或唯一追踪标识。清除此 Cookie 后,首页会再次显示下载页。
登录会话使用 Secure、HttpOnly、SameSite Cookie,不会写入 localStorage、sessionStorage 或待办 IndexedDB 数据。账户记录保存在隔离的服务器数据库中。在另行设计的云同步功能取得明确同意之前,本地待办内容始终留在浏览器存储边界内。
6. 保留与删除
会话会在闲置或达到绝对期限后过期,也可在退出或安全事件时撤销。OAuth 短期验证数据会随流程到期。账户身份记录在账户有效期间保留,或在安全、争议预防及法律义务合理需要的范围内保留。受支持的账户删除请求会删除或去标识账户数据,但上述有限义务除外;该操作不会清除浏览器里的本地任务。
7. 你的选择
你可以不登录继续使用本地待办应用、退出 TEND、在供应商账户中撤销 TEND,或通过账户服务提供的支持渠道申请访问、更正或删除。退出 TEND 不等于从 Google、Apple 或 ChatGPT 全局退出。
8. 安全与变更
TEND 会限制浏览器可见的账户数据,在服务器验证供应商响应,约束重定向来源并过滤敏感日志。任何系统都无法承诺绝对安全。若数据用途发生重大变化,本说明会先更新生效日期,再启用扩大的用途。