Privacy notice

Last updated: 2026-06-15. The German version is the legally binding one for residents of Germany; this English version is provided for convenience.

1. Controller

The controller within the meaning of the GDPR is the person named in the legal notice (Impressum):

Aliaksandr Yesafau
c/o Autorenglück #89278
Albert-Einstein-Straße 47
02977 Hoyerswerda
Germany
Email: load email address with JavaScript

A data protection officer has not been appointed because the legal thresholds in Art. 37 GDPR are not met.

2. Overview

Takledo is a private, non-commercial one-person hobby project: a personal AI organizer (todos, notes, recipes, shopping lists, calendar) that you can also operate by chat through the Model Context Protocol (MCP). Personal data is processed only to the extent required to run the service. This notice describes each processing activity with its purpose, legal basis, retention and recipients.

3. Server logs when you load the site

Data: the hosting platform and reverse proxy may process IP address, request timestamp, requested URL, HTTP status and user agent in operational logs.
Purpose: service delivery, rate limiting, abuse protection, troubleshooting and security.
Legal basis: Art. 6 (1) (f) GDPR - legitimate interest in a stable and abuse-resistant service.
Retention: operational logs are configured for short-term retention and are deleted when no longer required; incident-related records may be kept until the incident is resolved.

4. Account and passwordless sign-in

Data: email address, a salted hash of the current one-time 6-digit login code with issue and expiry timestamps and failed-attempt count, the accepted terms version and timestamp, your chosen timezone and retention setting, and an authentication cookie (HttpOnly, Secure in production, SameSite=Lax). Takledo never stores passwords.
Purpose: authentication, session integrity, recording the usage agreement and protection against account takeover.
Legal basis: Art. 6 (1) (b) GDPR (performance and documentation of the usage relationship) and Art. 6 (1) (f) GDPR (security).
Retention: account data remains until you delete your account. A login code is cleared after successful use, after five failed attempts or after its 10-minute validity period. The authentication cookie expires after up to 14 days and may be renewed while actively used.

5. Your content

Data: the items you create - todos, notes, calendar events, shopping lists and their items, categories - together with their timestamps.
Purpose: providing the core service so you (and the AI clients you authorize) can read and manage your items.
Legal basis: Art. 6 (1) (b) GDPR.
Retention: until you delete the item or your account. Deleting an item moves it to a recoverable trash and it is permanently purged after your chosen retention window (90, 180 or 365 days). Deleting your account removes your content.

6. Connecting AI clients (OAuth)

Data: dynamically registered client records (client id, name, redirect URIs), issued authorization codes and access/refresh tokens, and the scope/consent you grant. Takledo is its own OAuth 2.1 authorization server.
Purpose: letting ChatGPT, Claude or other MCP clients act on your behalf after you sign in and consent.
Legal basis: Art. 6 (1) (b) GDPR.
Retention: tokens until they expire or are revoked; client registrations until removed.

7. Cookies and similar technologies

Takledo uses only strictly necessary cookies: an authentication cookie (HttpOnly, Secure in production, SameSite=Lax) and a short-lived antiforgery cookie for protected forms. Legal basis: § 25 (2) No. 2 TDDDG and Art. 6 (1) (b) GDPR. These are set without consent because sign-in and core features cannot work without them. No advertising or third-party tracking cookies are used. Your language and view preferences are stored locally in your browser, not in a cookie sent to the server.

8. Recipients and processors

Personal data is shared only with the processors required to run the service; a data processing agreement (Art. 28 GDPR) is in place with each.

Hosting: servers in the European Union. Processes all server-side data described above.
Email delivery: Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France). Processes the recipient address and the login-code email content plus delivery metadata.

No transfer to other third parties takes place. Personal data is not sold and not used for third-party advertising.

9. Transfers to third countries

Takledo does not routinely transfer personal data outside the EU/EEA. Hosting runs on servers located in the EU. Brevo also processes data in the EU; certain Brevo subprocessors may be located outside the EU under Standard Contractual Clauses (Art. 46 (2) (c) GDPR) as documented in the Brevo DPA.

10. Your rights

You may exercise the following rights at any time: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection against processing based on Art. 6 (1) (f) (Art. 21), and withdrawal of consent with effect for the future (Art. 7 (3)).

No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place. Requests can be sent informally to the contact above. You can delete your account yourself at any time in account settings.

11. Right to lodge a complaint

Without prejudice to other remedies, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is in particular:

Sächsischer Datenschutz- und Transparenzbeauftragter
Devrientstraße 5
01067 Dresden, Germany
Web: www.saechsdsb.de

12. Changes to this notice

This privacy notice can be updated when processing changes or legal requirements demand it. The current version is published on this page. Material changes will be announced to signed-in users by email or an in-account notice.