Privacy Policy

Last Updated: October 21, 2025

1Introduction

Welcome to TidySync.ai ("we", "our", "us"). TidySync.ai is an AI-powered productivity and automation platform designed to help you transform your emails into organized, actionable tasks.

Our service allows users to:

  • Register and create accounts securely
  • Connect email accounts (Gmail, Outlook) via OAuth authentication
  • Integrate calendar services (Google Calendar, Microsoft Calendar)
  • Leverage AI-powered task automation and smart scheduling
  • Collaborate with team members in shared workspaces

This Privacy Policy explains how we collect, use, protect, and share your personal information when you use TidySync.ai. By using our service, you agree to the terms outlined in this policy.

2Data Collection & Usage

What Data We Collect

Account Information

  • Name and email address
  • Password (encrypted with bcrypt)
  • Profile information and preferences
  • Workspace and team membership data

Integration Data

  • Email content and metadata (subject, sender, recipient, date)
  • Calendar events and availability
  • OAuth access tokens (encrypted and securely stored)
  • Task and project information

Usage & Analytics Data

  • Device information (browser, OS, IP address)
  • Usage patterns and feature interactions
  • Performance metrics and error logs
  • Cookies and session data

How We Use Your Data

We use the collected data for the following purposes:

  • Service Delivery: To provide core features like email-to-task conversion, AI scheduling, and smart suggestions
  • Personalization: To customize your experience based on preferences and usage patterns
  • Communication: To send service updates, notifications, and support responses
  • Improvement: To analyze usage and improve our AI models and features
  • Security: To detect fraud, prevent abuse, and ensure platform security
  • Compliance: To meet legal obligations and enforce our terms

3Third-Party Integrations (OAuth)

Secure OAuth Authentication

TidySync.ai uses OAuth 2.0 authentication to securely connect with Google and Microsoft services. This industry-standard protocol ensures your credentials remain safe.

Google OAuth Integration

When you connect your Google account, we request the following permissions:

  • Gmail API: Read email messages, metadata, and labels to create tasks
  • Google Calendar API: Read and write calendar events for scheduling features
  • User Profile: Access basic profile information (name, email, photo)

Important: TidySync.ai complies with Google's API Services User Data Policy, including the Limited Use requirements.

Microsoft OAuth Integration

When you connect your Microsoft account, we request the following permissions:

  • Outlook Mail API: Read email messages and metadata
  • Microsoft Calendar API: Read and write calendar events
  • User Profile: Access basic profile information

Important: TidySync.ai complies with Microsoft API usage guidelines and data handling requirements.

What We Don't Do

  • ❌ We never store your passwords
  • ❌ We never sell your data to third parties
  • ❌ We never send emails on your behalf without explicit permission
  • ❌ We never share your data with advertisers

Revoking Access

You can revoke TidySync.ai's access to your Google or Microsoft account at any time:

4AI Processing & Data Security

How AI Processes Your Data

TidySync.ai uses advanced AI models to analyze your emails, extract actionable tasks, suggest due dates, and provide smart scheduling recommendations. This processing happens securely within our infrastructure.

AI Data Handling Principles

  • Privacy-First: AI processing is performed only on your authorized data
  • No Training: Your personal data is never used to train our general AI models
  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Minimal Retention: AI processing data is kept only as long as necessary
  • No Sharing: AI-processed data is never shared with third parties

Your data stays yours. We process it solely to deliver the features you request, and we never sell or share it for advertising purposes.

5Your Rights (GDPR & CCPA)

TidySync.ai is committed to protecting your privacy rights under GDPR (General Data Protection Regulation) and CCPA (California Consumer Privacy Act).

Your Rights Include

Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal information

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

Right to Portability

Export your data in a machine-readable format

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected]

We will respond to your request within 30 days and provide verification to ensure the security of your data.

6Security & Data Retention

Security Measures

We implement industry-leading security practices to protect your data:

  • Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Authentication: Secure password hashing (bcrypt) and OAuth 2.0
  • Access Control: Role-based permissions and least-privilege principles
  • Monitoring: 24/7 security monitoring and incident response
  • Regular Audits: Periodic security assessments and penetration testing
  • Compliance: SOC 2 Type II compliance (in progress)

Data Retention

We retain your data according to the following policies:

  • Active Accounts: Data retained while your account is active
  • Deleted Accounts: Data permanently deleted within 90 days of account deletion
  • Backup Data: Backup copies deleted within 180 days
  • Legal Holds: Data may be retained longer to comply with legal obligations

7Cookies & Analytics

TidySync.ai uses cookies and similar technologies to enhance your experience and analyze usage patterns.

Types of Cookies We Use

  • Essential Cookies: Required for authentication and core functionality
  • Analytics Cookies: Help us understand how users interact with our service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling essential cookies may affect functionality.

8Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make significant changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email or in-app notification
  • Request your consent if required by law

We encourage you to review this policy periodically to stay informed about how we protect your data.

9Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

TidySync.ai Privacy Team

Email: [email protected]

We typically respond within 1-2 business days.