Legal
Privacy Policy
Last updated: August 2026
About this page
This page is maintained by OneList.ai to answer common privacy questions about OneList.ai. It describes the data the app collects, how that data is stored and protected, and the choices you have. If you have questions that are not covered here, contact details will be added as soon as they are available.
What we collect
We collect only what is needed to run the app:
- Account information: your email address and, if you choose it, a Google account identifier used for sign-in.
- List data: task titles, detailed notes, status (Urgent, To do, Done), star/pin state, order position, and any links or file attachments you upload.
- Sharing preferences: your public handle or slug and whether your list is set to public or private.
- Session tokens: essential authentication cookies/tokens that keep you signed in.
What we do not do
- We do not install analytics, tracking pixels, or advertising cookies.
- We do not sell or share your data with third parties for marketing.
- We do not access your tasks or attachments except when necessary to operate the service.
How your data is stored and protected
OneList.ai is hosted on Lovable Cloud. Data is stored in a managed database service with the following protections:
- In transit: all connections between your browser and our backend use TLS/SSL encryption.
- At rest: database storage is encrypted using AES-256 by the cloud provider.
- Access control: Row-Level Security policies ensure your tasks and settings are only readable by you, or by others only when you explicitly set your list to public.
Platform security features are provided by Lovable Cloud. App-level security, such as keeping your list private by default and choosing a strong handle, is a shared responsibility.
Public vs. private lists
Your list is private by default. If you change it to public, anyone with your handle URL (for example, onelist.ai/your-handle) can view your tasks. You can switch back to private at any time in the app settings.
Cookies
We use only essential cookies and session tokens required for authentication. There are no analytics, advertising, or optional cookies.
Your rights and controls
You can:
- Add, edit, delete, and reorder tasks at any time.
- Delete attachments and notes.
- Change your list between public and private.
- Sign out from the app settings.
If you want to delete your account entirely, contact details will be added here once they are available.
Third-party services
We rely on Lovable Cloud for hosting, authentication, and database services. Authentication is handled through standard OAuth and magic-link providers. We do not embed social media widgets, analytics scripts, or advertising networks.
Changes to this policy
We may update this policy as the app changes. The latest version will always be available at this page, and the "Last updated" date will be revised accordingly.
Contact us
A dedicated support contact is coming soon. In the meantime, privacy questions can be submitted through any in-app feedback or support channel that becomes available.
