Last updated 10 October 2026
- What you type into a task is encrypted in the app before it is saved.
- The database refuses every request that is not from the account that owns the data.
- You can add a second sign-in step, and open the app with Face ID or a fingerprint.
- No advertising or analytics scripts run on this site or in the app.
Encryption
The words in a task or reminder are encrypted on your device, in the app, before they are sent anywhere. That covers the title, the description, the steps, and the names of the people in it. The method is AES-256-GCM, a standard used by banks and governments.
Each account has its own encryption key. That key is itself stored encrypted, under a master key that is held in our server’s protected settings and never in the database or the app. When you sign in, the server confirms who you are and hands your key to the app for that session.
What is not encrypted this way
Dates, times, status, priority, whether an item repeats, and whether it is work or personal are stored as ordinary values. The app needs them to sort your list, and the server needs them to send a reminder at the right minute.
What this means in practice
- Someone who obtained a copy of the database alone would see scrambled text where your task titles and notes are.
- This is not end-to-end encryption. Our server can unlock your key. It does so to let you sign in on a new device, to put a task’s title in a notification, and to build your weekly summary email.
- All stored data is also encrypted on disk by our database provider.
Who can read what
Every table that holds your data has access rules enforced by the database itself, not only by the app. A request is answered only if it comes from the signed-in account that owns the rows it asks for. One account cannot read, change or delete another account’s items, even by calling the database directly.
If two-step sign-in is on for your account, the same rules also require the second step to have been passed. A stolen password alone then opens nothing.
A private workspace, an address such as yourname.ceotodo.app, accepts exactly one account. Once it has an owner, nobody else can sign up or sign in there.
Sign-in protection
- Passwords must be at least ten characters. They are stored only as a one-way hash, so nobody, including us, can read them.
- Email confirmation. A new account works only after the emailed link is opened. Links are single-use, and are not spent by mail scanners that open links automatically.
- Two-step sign-in. You can add a six-digit code from an authenticator app. It is turned on in your profile.
- Face ID or fingerprint. After signing in once, you can have the app ask for your device’s face or fingerprint check each time it opens, and again after five minutes away. The check is done by your device; we never receive your face or fingerprint.
- Password reset goes to your email address, with a link that works for one hour.
In transit and in the browser
- Every connection uses HTTPS, and browsers are told to refuse anything else for this site.
- The site only allows scripts from its own address to run, and only allows the app to talk to its own database. This limits what an injected script could do.
- The site cannot be embedded inside another page, which blocks a class of trick where a real page is hidden under a fake one.
- No third-party scripts are loaded: no advertising, no analytics, no social widgets.
Who handles your data
Each of these receives only what it needs to do its job.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database and sign-in, hosted in Mumbai, India | Your account, and your items with their text encrypted |
| Hostinger | Serves this website and the app’s files | Ordinary web requests. None of your tasks |
| Resend | Sends email | Your email address and the email itself: confirmation, password reset, weekly summary |
| Groq | Turns speech into text | The audio of what you dictate, for that request. We do not keep the recording |
| Aivah.ai | The live voice assistant, and the voice model it runs on | Your speech and the tasks needed to answer you, for that conversation |
| Apple, Google, Mozilla | Deliver notifications to your device | The reminder’s title and time, encrypted for your device |
Sign-in and usage records
Each day you open the app we record that you did, how often, the kind of device, and your IP address, from which we work out your country. The IP address is deleted after 30 days; the country is kept. This is how unusual sign-ins are spotted. These records never include what is in your tasks, and are visible only to the service’s administrator.
What this does not protect against
- Someone who has your unlocked phone or laptop while you are signed in. Turn on Face ID to narrow this.
- Someone who has both your password and your email inbox, if two-step sign-in is off.
- Malicious software on your own device.
- What you choose to dictate or tell the assistant is sent to the speech and voice providers listed above, for that request.
What you can do
- Turn on two-step sign-in in your profile.
- Turn on Face ID or fingerprint unlock on your phone.
- Use a long password you do not use anywhere else.
- Sign out on any device you share.
Reporting a problem
If you think you have found a weakness, please tell us before telling anyone else, and give us time to fix it.
Ask the person who gave you access to the app, or the administrator of your workspace. They can reach us directly, and requests about your data are answered within 30 days.