Privacy Policy
Your tasks, lists, notes, tags, and projects are not stored on our servers. 2Do stores your data locally on your devices and syncs it only with the services you explicitly configure, such as CalDAV, iCloud CalDAV, or Dropbox.
Regulatory Compliance
2Do is designed around local-first data ownership. We do not run a hosted 2Do sync service, and we do not process, store, or transmit the task data you create inside the app through our own servers.
This approach supports common privacy and security requirements:
- GDPR (General Data Protection Regulation) – Your 2Do data remains on your device or with the sync provider you choose.
- HIPAA (Health Insurance Portability and Accountability Act) – We do not process Protected Health Information (PHI) on our servers. If you use 2Do in a healthcare setting, you must ensure your chosen sync provider is appropriate for that use.
- CCPA (California Consumer Privacy Act) – We do not sell or share the personal data you create inside 2Do.
2Do has not undergone formal certification for these regulatory frameworks. This page is provided for transparency and general guidance. If you are required to meet a specific legal or industry standard, it is your responsibility to ensure that the sync service you choose, such as CalDAV, iCloud CalDAV, or Dropbox, meets those requirements.
GDPR Compliance
2Do helps you and your organization meet GDPR requirements by keeping the data you add to the app under your control. The task data you create is not uploaded to Beehive Innovations servers. If you enable sync, 2Do communicates directly with the service you selected, and that provider becomes responsible for storing and handling the synced data.
Because we do not operate a hosted 2Do sync service or perform large-scale monitoring of customer task data, our role is limited to the website, licensing, support, crash reporting, and optional analytics described below.
HIPAA Compliance
2Do follows HIPAA-friendly local-data principles by ensuring that user-created task data is not stored, transferred, or processed on our servers. If you choose to store sensitive information in 2Do and sync it with a third-party service, you and your organization are responsible for ensuring that service is suitable for the sensitivity of the data.
SOC 2 Applicability
SOC 2 is aimed at service providers that store, process, or transmit customer data through hosted infrastructure. Since 2Do does not provide a hosted sync service and does not store your task database on our servers, SOC 2 certification is not applicable to the app itself.
2Do operates as a native app on macOS, iOS, iPadOS, and Android. Your task database, attachments, notes, tags, lists, and related app data remain on your device unless you choose to sync them with a supported service. We do not act as a proxy or intermediary for that sync traffic, and we cannot inspect the contents of your tasks.
EULA
Our End User License Agreement is accessible here.
Sync Accounts and Login Credentials
2Do uses the credentials or authorization tokens you provide only to connect to the sync services you configure. Supported sync options include:
- CalDAV servers
- iCloud CalDAV
- Dropbox
- Todoist
- Toodledo
- Apple Reminders (uses your Mac's system Reminders access rather than a login you provide)
Your credentials are stored by the app using the secure storage provided by the operating system where available, such as Keychain on Apple platforms. They are not sent to Beehive Innovations servers.
Mail to 2Do
Mail to 2Do gives each device running 2Do for Mac, iPhone, or iPad its own private, receive-only email address at the
2doapp.email domain. Email sent to that address is converted into a small task payload and encrypted the moment it
arrives, using a key that only your device holds. Once the encrypted payload is stored, we cannot read your message; no
human-readable message content is kept at rest. The raw email is deleted immediately after conversion, with a 24-hour
failsafe.
2Do never signs in to a mailbox of yours to provide this feature. It has no access to your email accounts, and it does not read, send, or change mail anywhere else.
The encrypted payload waits only until your device saves the task and is then deleted permanently and automatically. If your device stays offline, the payload is deleted after 30 days. Nothing is stored after delivery: Mail to 2Do does not create a mailbox, an account, or any browsable message store, and the service is receive-only, so it never sends email, replies, or bounces on your behalf.
To provide this feature, 2Do connects to api.2doapp.email to set up your private address and to fetch, acknowledge,
and manage the encrypted payloads. Addresses that go unused for 12 months are permanently deleted, and retired addresses
are never reused. This email data is used only to provide the feature you enabled. It is not used for advertising,
marketing, profiling, unrelated analytics, or AI model training, and we do not sell it or transfer it to data brokers.
A task created this way is treated like any other task you create. It stays in your local 2Do database and, if you enable sync, may sync through the provider you selected, such as CalDAV, iCloud CalDAV, or Dropbox. Delete the task if you no longer want that captured content in your database.
Location Data in Our Apps
2Do on iOS, macOS, and Android offers location-based task reminders, including the ability to create locations, assign locations to tasks, and use the Nearby view or nearby alerts. This lets 2Do remind you about tasks when you arrive at, leave, or pass near a saved place. It also lets you filter tasks by saved locations together with other task fields such as tags, keywords, and dates.
When you choose to use these features, 2Do may ask for permission to access your location, including background location updates where the operating system requires that permission for nearby alerts. 2Do prompts for this access only when you use a location-based feature, and location updates are used only to support the reminders, nearby lists, and filters you configure.
Your current location and saved task-location data are stored on your device for these app features and are not sent to Beehive Innovations servers. If you enable sync with a service you choose, task data that includes saved task locations may sync through that provider to your other devices. That sync is handled directly between 2Do and the provider you configured, and the provider's handling of synced data is governed by that provider's privacy and security practices.
Push Notifications
If you enable notifications, the operating system may provide 2Do with a push notification token for that app installation. The token is used only to route app notifications or background sync prompts through the platform notification service, such as Apple Push Notification service where applicable.
Push notification tokens do not contain your task database, email contents, location history, notes, attachments, or other task content. They are used only for notification delivery and related background work, such as helping another device notice that a sync-related change may be available. You can enable or disable notifications at any time in your device's system settings.
Licensing
When you purchase a direct 2Do Mac license, we store the information needed to issue invoices, generate a registration code, validate the license, and provide renewal support. This typically includes your email address, order information, registration code, and basic activation information.
This information is used only for licensing, fraud prevention, invoicing, refunds, support, and renewal workflows. It is not used to inspect or access your tasks.
Automatic Updates
2Do Mac periodically checks for updates by contacting our update servers. These checks may include anonymous information about the installed app version and macOS version so the app can determine whether an update is available.
Mailing List
If you subscribe to our mailing list, you may receive occasional messages about important product updates, announcements, or offers. We do not sell or share your email address. You may unsubscribe at any time through the mailing-list link or by contacting us.
Customer Support and Application Logs
When you contact support, we keep a record of the conversation and any attachments you voluntarily provide so we can help diagnose and resolve the issue.
If you choose to send diagnostic logs, those logs may contain app activity needed for troubleshooting. Logs are shared only when you send them to us. We cannot access your computer, your phone, or your 2Do database without your action.
We retain support logs only as long as needed to resolve the issue, protect service integrity, or meet legal and accounting requirements. You may request deletion of support logs at any time.
Support logs are handled with care. We review only the parts needed to diagnose the problem and avoid unrelated personal details whenever possible.
Non-Personal Information
Non-personal information is data that cannot be used on its own to identify a specific person. This can include crash reports, stack traces, performance metrics, app version, device model, operating-system version, and broad usage patterns.
We may use Google Firebase Crashlytics to receive crash reports and optional performance diagnostics. This helps us find bugs and improve stability. These reports are used only for product quality and troubleshooting.
Optional analytics, where present, are used to understand broad product usage trends and improve the app. They are not used to inspect your task contents.
Internet Access Policy
Apart from CalDAV, iCloud CalDAV, and Dropbox accounts that you configure, these are the main domains 2Do may contact. No task contents are collected, tracked, sold, or shared by us through these connections.
Outgoing Connections
versioncheck.2doapp.com
2Do Mac connects to this server to check for updates and validate direct licenses.
downloads.2doapp.com
This domain may be used to download app updates or related update metadata.
support.2doapp.com
This is the domain used by our support portal. Some help, registration-code lookup, renewal, or contact links may open pages under this domain.
api.2doapp.email
2Do connects to this server only when you enable the optional Mail to 2Do feature. It is used to set up your private email address and to fetch, acknowledge, and manage the encrypted task payloads created from mail sent to that address. Messages are encrypted for your device the moment they arrive, we cannot read them, and each one is permanently deleted the instant your task is saved, or after 30 days at most.
api.dropboxapi.com, content.dropboxapi.com
2Do connects to Dropbox only when you configure Dropbox sync. The app communicates directly with Dropbox using the account authorization you provide.
app.todoist.com, api.todoist.com
2Do connects to Todoist only when you sign in to Todoist or sync tasks through a Todoist account. The app
communicates directly with Todoist using the account authorization you provide. The Todoist sign-in (OAuth)
callback is relayed through 2doapp.com.
*.crashlytics.com, crashlyticsreports-pa.googleapis.com
2Do may send anonymous crash reports to Google Firebase Crashlytics to help identify and fix bugs.
firebaselogging-pa.googleapis.com, *.app-measurement.com
Optional analytics and performance diagnostics may use these domains when enabled. They are used for broad product quality signals and not for task-content tracking.
Apple Push Notification service
When enabled, push notifications may be used by the operating system to help devices notice changes and perform background work. You can control notification permissions from your device settings.
Cookies and Other Technologies
Our website may use cookies and similar technologies to provide core site behavior, understand website usage, and improve the user experience. You can disable cookies in your browser settings, although some website features may not work as expected.
When you visit the website, standard server logs may include your browser type, operating system, referring page, IP address, request time, and requested resource. We use this information in aggregate to administer the website, protect the service, and improve our product information.
Your Rights
You may contact us to request access, correction, or deletion of personal information we hold about you, such as support emails, licensing records, or mailing-list subscriptions.
Because your 2Do task data is stored locally on your device or with the sync service you chose, you can delete that data directly from the app, your device, or your sync provider. Uninstalling the app removes locally stored app data according to the behavior of the operating system.
Children's Privacy
2Do and this website are not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us so we can delete it.
Changes to This Policy
We may update this policy as 2Do, our website, or our support systems evolve. When we make material changes, we will update this page and, where appropriate, notify customers through the website, app, or email.