Privacy Policy

Your privacy is important to us. This policy explains how Todo2 (our Cursor AI Editor extension and website) collects, uses, and protects your personal information.

Last Updated: June 10, 2025

1. Data Controller Information

Todo2 is responsible for your personal information. We provide a Cursor AI Editor extension for task management and maintain a website at todo2.pro. We are committed to protecting your privacy and complying with applicable data protection laws.

What this means: Under privacy laws like GDPR, a "data controller" is the organization that decides what personal information to collect and how to use it. That's us - Todo2. We're the ones responsible for your data and the ones you should contact with any privacy questions.

Company: Todo2

Extension: Cursor AI Editor Extension

Website: https://todo2.pro

Contact: info+todo2@theadamlabs.com

2. Information We Collect

Website Information (todo2.pro)

  • Email address (for account creation and authentication)
  • Name and profile information (if provided)
  • Payment information (processed securely through Stripe)
  • IP address and device information
  • Browser type and version
  • Website usage analytics (via Google Analytics)
  • Cookies and similar tracking technologies
  • Communication records (support tickets, feedback)

Extension Information (Cursor AI Editor)

  • Basic usage statistics (when enabled via todo2.enableUsageTracking)
  • Extension performance metrics
  • Feature usage patterns
  • Error logs and diagnostic information
  • Note: We do NOT collect details about your code, tasks, or project content

Extension Usage Tracking: You can disable usage tracking at any time by setting todo2.enableUsageTracking to false in your Cursor settings. This setting is enabled by default but can be changed at any time.

3. How We Use Your Information

We use your personal information for the following purposes:

Website (todo2.pro)

  • Processing payments and managing subscriptions
  • Authenticating users and securing accounts
  • Providing customer support and responding to inquiries
  • Website analytics and usage tracking (via Google Analytics)
  • Sending important service updates and notifications
  • Marketing communications (with your consent)

Extension (Cursor AI Editor)

  • Providing and maintaining the Todo2 extension functionality
  • Improving extension performance and user experience
  • Identifying and fixing bugs and technical issues
  • Understanding feature usage to guide development priorities
  • Complying with legal obligations and preventing fraud

5. Data Sharing and Third Parties

We may share your personal information with trusted third parties in the following circumstances:

Website Service Providers

  • Stripe: Payment processing and subscription management
  • Google Analytics: Website analytics and usage tracking (website only)
  • Firebase: Authentication and database services
  • Microsoft Clarity: User experience analytics (website only)
  • AWS: Cloud hosting and infrastructure

Extension Data

Extension usage tracking data (when enabled) is processed internally and not shared with third-party analytics services. This data helps us improve the extension but does not include any details about your code or tasks.

Legal Requirements

We may disclose information when required by law, court order, or to protect our rights and safety.

6. Data Retention

We retain your personal information for the following periods:

Website Data

  • Account Data: Until account deletion or 3 years after last activity
  • Payment Information: As required by financial regulations (typically 7 years)
  • Website Analytics: Aggregated data retained for 2 years
  • Support Records: 3 years after case closure
  • Marketing Data: Until consent is withdrawn or 2 years of inactivity

Extension Data

  • Usage Statistics: Aggregated data retained for 1 year
  • Error Logs: 90 days for debugging purposes
  • Performance Metrics: 6 months for optimization

When retention periods expire, we securely delete or anonymize your personal information.

7. Security Measures

We implement comprehensive security measures to protect your personal information:

  • End-to-end encryption for data transmission
  • Secure authentication using Firebase Auth
  • Regular security audits and vulnerability assessments
  • Access controls and employee training
  • Secure cloud infrastructure with AWS
  • Regular backups and disaster recovery procedures

While we implement industry-standard security measures, no system is 100% secure. We continuously monitor and improve our security practices.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your website experience:

Website Cookies (todo2.pro only)

  • Essential Cookies: Required for basic website functionality
  • Analytics Cookies: Help us understand how you use our website (Google Analytics)
  • Preference Cookies: Remember your settings and preferences
  • Authentication Cookies: Keep you logged in securely

Extension Privacy: The Todo2 Cursor extension does not use cookies or browser tracking. Only basic usage statistics are collected when enabled through the extension settings. But no Todo2 tasks or code is collected or stored on our servers.

You can control website cookies through your browser settings. Disabling certain cookies may affect website functionality.

9. Your Rights

You have the following rights regarding your personal information:

GDPR Rights (EU Users)

  • Right to access your data
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object

CCPA Rights (California Users)

  • Right to know what data is collected
  • Right to delete personal information
  • Right to opt-out of data sales
  • Right to non-discrimination

How to Exercise Your Rights: Contact us at info+todo2@theadamlabs.com with your request. We will respond within 30 days.

Extension Privacy Controls

For the Todo2 Cursor extension, you have additional privacy controls:

  • Disable Usage Tracking: Set todo2.enableUsageTracking to false in Cursor settings
  • Complete Data Privacy: Your code and task content never leaves your local environment
  • Uninstall: Remove the extension to stop all data collection

10. International Data Transfers

Your personal information may be transferred to and processed in countries outside your residence. We ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • Adequacy decisions where available
  • Binding corporate rules for intra-group transfers
  • Certification schemes and codes of conduct

11. Children's Privacy

Todo2 is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will take steps to remove such information from our systems.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Notify you via email for significant changes
  • Post a notice on our website
  • Provide additional notice as required by law

Your continued use of our services after changes become effective constitutes acceptance of the updated policy.

13. Contact Information

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: info+todo2@theadamlabs.com

Subject Line: Privacy Policy Inquiry

Response Time: We aim to respond within 48 hours

For data protection inquiries specifically, please include "Data Protection" in your subject line.

This Privacy Policy is effective as of June 10, 2025. By using Todo2, you acknowledge that you have read and understood this policy.