TidstTidst

Privacy Policy

Last updated: September 24, 2026

1. Data Controller

Tidst is operated by Christian Hougaard, Denmark.

Tidst is the data controller for the personal data we process about you. If you have questions about our processing of your data, please contact us at tidst@proton.me.

2. What information do we collect?

We collect and process the following personal data:

  • Account information: Email address and Todoist display name when creating an account.
  • Todoist data: Projects, tasks and activity retrieved via the Todoist API to enable time tracking.
  • Asana data: Tasks, projects, tags and workspace names retrieved via the Asana API to enable time tracking. Collected only if you choose to connect Asana.
  • Google Calendar data: Event titles, start times, end times and attendee email addresses (used only to suggest which client a meeting belongs to) from the Google Calendar(s) you choose to connect. Collected only if you opt in, and only for calendars you explicitly select. We never read event descriptions or locations.
  • Google Tasks data: Task titles and completion times from the Google Tasks lists you choose to watch. Collected only if you opt in when connecting Google.
  • ClickUp data: Task titles, statuses, tags, time estimates and tracked time from the ClickUp workspaces you choose to connect, retrieved via the ClickUp API to enable time tracking.
  • monday.com data: Item titles, status labels, tags and tracked time from the monday.com boards you choose to watch, retrieved via the monday.com API to enable time tracking.
  • Trello data: Board names, list names, and card titles with completion activity from the boards you choose to watch, retrieved via the Trello API to enable time tracking.
  • Notion data: Database names, task titles, status and last-edited times from the shared Notion databases you choose to watch, retrieved via the Notion API to enable time tracking.
  • Outlook Calendar data: Event titles, start times, end times and attendee email addresses (used only to suggest which client a meeting belongs to) from the Outlook Calendar(s) you choose to connect. Collected only if you opt in, and only for calendars you explicitly select. We never read event bodies or locations.
  • Time entries: The time data you create and edit in Tidst.
  • Settings: Your preferences such as currency, hourly rates, budget goals and visual preferences.
  • Newsletter: Email address, if you subscribe to our newsletter.
  • Billing information: We do not collect payment information for using Tidst, which is currently free.

3. Purpose of processing

We process your personal data for the following purposes:

  • To provide and maintain the Tidst service.
  • To synchronize with your Todoist or Asana account.
  • To generate reports and billing documentation.
  • To send you onboarding emails and news (only with your consent).

Use of Google user data: Data obtained through our Google integrations (Calendar and Tasks) is used solely to display your selected calendar events and completed tasks for time tracking within Tidst. It is never used for advertising, marketing, or analytics, and is never shared with third parties for such purposes.

Use of Microsoft user data: Data obtained through our Outlook Calendar integration is used solely to display your selected calendar events for time tracking within Tidst. It is never used for advertising, marketing, or analytics, and is never shared with PostHog. It is shared only with Microsoft, as necessary to retrieve the data itself.

4. Legal basis

We process your data based on performance of contract (Art. 6(1)(b) GDPR) to deliver the service, and consent (Art. 6(1)(a)) for newsletters. You may withdraw your consent at any time.

5. Cookies

Tidst exclusively uses essential cookies, which are necessary for the service to function correctly. These cookies are used for authentication and session management. We do not use any tracking, analytics or marketing cookies. Since we only use essential cookies, no separate consent is required.

We do not use automated decision-making or profiling as defined in Article 22 of the GDPR.

6. Data sharing

We share your personal data with the following parties:

  • Todoist (Doist Inc.): To retrieve your project data via OAuth integration.
  • Asana (Asana, Inc.): To retrieve your task and project data via OAuth integration, only if you choose to connect Asana.
  • Google: To retrieve calendar event data via OAuth integration, only if you choose to connect Google Calendar.
  • Microsoft: To retrieve calendar event data via OAuth integration, only if you choose to connect Outlook Calendar.
  • ClickUp (ClickUp, Inc.): To retrieve your task data via OAuth integration, only if you choose to connect ClickUp.
  • monday.com (monday.com Ltd.): To retrieve your board and item data via OAuth integration, only if you choose to connect monday.com.
  • Trello (Atlassian): To retrieve your board and card data via its authorization flow.
  • Notion (Notion Labs, Inc.): To retrieve your database and task data via OAuth integration, only if you choose to connect Notion.
  • PostHog: For product analytics, only with your consent to analytics cookies. Used to understand how Tidst is used so we can improve it.
  • Supabase and Vercel: Supabase hosts our database and authentication service; Vercel hosts the frontend. Both store and process your data on our behalf.
  • Resend: To deliver the emails we send you. Resend receives your email address, your name, and the contents of the message, which for the weekly summary includes your tracked hours and the titles of unlogged tasks and calendar events from that week.

We never sell your data to third parties.

Support access: Tidst is run by one person, who can open the data in your account (time entries, clients, projects and settings) in order to investigate a fault you have reported or answer a question you have asked. It is used for that and nothing else, and nothing is passed on as part of it. Where a screenshot answers the question, we ask you for one instead.

Tidst's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. Data retention

We retain your data as long as you have an active account with Tidst. If you delete your account, we delete your personal data immediately, unless we are legally obligated to retain it longer. We also retain a record of email addresses that previously used a free trial (from before Tidst became free), even after account deletion, to prevent abuse of that historical trial system.

8. International data transfers

Some of our service providers are located outside the European Economic Area (EEA). We use the following providers in the United States: Supabase (database and authentication, hosted on AWS), Vercel (frontend hosting), and Todoist/Doist Inc. (OAuth integration). These transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring your data is protected to the same standard as within the EEA.

9. Your rights

As a data subject, you have the following rights:

  • Access: You can request to see the personal data we hold about you.
  • Rectification: You can ask to have incorrect information corrected.
  • Erasure: You can ask to have your data deleted.
  • Restriction: You can ask us to restrict the processing of your data.
  • Data portability: You can download all your time entries directly from Settings → Export Your Data. You may also contact us to receive your data in another machine-readable format.
  • Objection: You can object to our processing of your data.
  • California residents (CCPA): You have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell your personal information.

tidst@proton.me to exercise your rights. You also have the right to file a complaint with the Danish Data Protection Agency.

If you are located in the United Kingdom, you may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Security

We use industry standards to protect your data, including encrypted data transfer (TLS/SSL), secure authentication via Todoist OAuth, and access control to our systems.

11. Changes

We may update this privacy policy from time to time. For significant changes, we will notify you via email or a notice in the service.