Skip to content

Privacy policy

Last updated 6 September 2026

In short: We collect your email, your tasks, and enough usage data to know whether the product works. We do not sell it, do not advertise, and do not train models on it. You can export everything or delete all of it yourself, at any time, without asking us.

Who is responsible

Oasis Digital, of Dubai, United Arab Emirates, is the data controller for personal data processed through otoodo. Contact us at support@oasis-digital.ae.

What we collect, and why

  • Your account. Email address, display name, password (stored only as a hash, by our authentication provider), and your timezone. Needed to give you an account at all — the lawful basis is performance of our contract with you.
  • Your content. Projects, tasks, notes, estimates, deadlines, working hours, the names of people you delegate work to, and your completion history. This is the service. We process it to produce your plan and for no other purpose.
  • Why you left, if you choose to tell us when you cancel or close your account. Optional, always. See the retention section for what happens to it afterwards.
  • Billing. If you subscribe, Stripe collects and holds your payment details. We never see your card number. We store your Stripe customer id, your plan, its status and its renewal date.
  • Technical and usage data. Server logs (IP address, request path, timestamp) kept briefly for security and debugging, and aggregate product analytics — which screens are used, whether people finish setting up — on the basis of our legitimate interest in knowing whether the product works. Analytics never carry the content of your tasks.

What we never do

  • Sell or rent your personal data to anyone.
  • Show you advertising, or share your data with advertising networks.
  • Use the content of your tasks to train machine-learning models.
  • Read your tasks, except where you explicitly ask us to look at something to help with a support request.

Who processes it for us

We use a small number of providers, each under a data-processing agreement, each only for what it says:

  • Supabase — database, authentication and backups.
  • Netlify — hosting and content delivery.
  • Stripe — payments, invoices and tax. Stripe is the controller of your payment data, under its own privacy policy.
  • OpenAI — only if you choose to connect a ChatGPT action. In that case what you say to ChatGPT goes to OpenAI under their terms, not ours. This is off unless you switch it on.

Some of these are outside your country. Transfers are covered by the providers’ standard contractual clauses.

How long we keep it

  • Your content: until you delete it, or until you close your account — whichever comes first.
  • Your account: deleted immediately when you close it. There is no recovery window, which is the trade for it being genuinely deleted.
  • One exception, stated plainly: if you tell us why you are leaving, we keep that answer — but not the link to you. The account id on it is removed at the same moment the account is, so what remains is a sentence with nobody attached to it. We keep it because it is the most useful thing anyone ever tells us, and we unlink it because there is no reason for us to know who said it.
  • Backups: rolled off within 30 days of deletion.
  • Billing records: kept for as long as tax law requires, typically seven years. These are invoices, not task content.
  • Server logs: 30 days.

Your rights

You can exercise the first two of these yourself, from Settings, without asking us or waiting for us:

  • Portability. Export everything as JSON, on any plan.
  • Erasure. Delete your account and all its data, immediately.
  • Access, correction, objection and restriction. Email support@oasis-digital.ae and we will respond within 30 days.

If you are in the UK or EU you may also complain to your local supervisory authority. We would rather you told us first.

Cookies

otoodo sets one kind of cookie: the session cookie that keeps you signed in. It is strictly necessary for the service to work, so there is no consent banner to click. We do not use advertising or cross-site tracking cookies.

Security

Every table in the database has row-level security enforced at the database itself, keyed to your user id — so one account cannot read another’s rows even if the application layer were bypassed. Traffic is encrypted in transit. Passwords are hashed by our authentication provider and never stored by us. API tokens are stored only as SHA-256 hashes, so a database dump would not yield a working token.

If a breach affects your personal data, we will tell you and the relevant authority within 72 hours of becoming aware of it.

Changes

We will post any change here and update the date above. If a change materially affects you, we will email you before it takes effect.