Privacy Policy
Last updated: August 31, 2026
1. Introduction
VA To-Do is operated by Lester Labs LLC. References to "VA To-Do," "we," "our," or "us" in this Privacy Policy mean Lester Labs LLC. We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, Chrome extension, and related services (collectively, the "Service"). This policy complies with applicable privacy laws in the United States and the Republic of the Philippines, including Republic Act No. 10173 (Data Privacy Act of 2012).
2. Data We Collect
Account Information
- Email address (required for registration)
- Display name (optional)
- Authentication data (password hash or Google OAuth token)
Task & Client Data
- Tasks, notes, descriptions, labels, and due dates you create
- Client names and associated information
- Time tracking logs and productivity data
- Kanban board sections and task organization
Google Calendar Data (Optional)
- If you connect Google Calendar, we sync read-only copies of your calendar list and event details, along with the email address of the connected Google account. See Google User Data & Limited Use for the full disclosure.
Usage Data
- Browser type and version
- Device information and operating system
- Pages visited and features used
- Timestamps and session duration
Payment Information
- Payment data is processed securely by Stripe; card details are entered directly into Stripe's payment form and never reach our servers, so we never see or store your card number or CVC
- Subscription status, plan type, and billing history
Local Storage Data
- Theme preferences (light/dark mode)
- Sidebar state and view preferences
- Authentication tokens for session management
3. How We Use Your Data
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process your transactions and manage your subscription
- Send transactional emails (account verification, password resets, payment receipts)
- Power AI-assisted features (task breakdown, weekly reports, client messages) using anonymized task data
- Monitor and analyze usage patterns to improve user experience
- Detect, prevent, and address security issues and fraud
- Comply with legal obligations
4. Legal Basis for Processing
Under the Data Privacy Act of 2012 (RA 10173), Section 12, we process your personal information based on the following lawful criteria:
- Consent: You provide consent when creating an account and agreeing to our Terms of Service
- Contractual necessity: Processing is necessary to fulfill our service agreement with you
- Legitimate interest: We process data to improve our Service, ensure security, and prevent fraud
- Legal obligation: We may process data to comply with applicable laws and regulations
6. Google User Data & Limited Use
VA To-Do offers an optional, read-only Google Calendar integration. This section applies only if you choose to connect your Google account, and it describes our compliance with the Google API Services User Data Policy, including its Limited Use requirements.
What We Access and Store
When you connect Google Calendar, we request read-only access using the Google API scopes calendar.calendarlist.readonly and calendar.events.readonly, plus your basic profile email address to label the connected account. We store:
- Your list of calendars: names, colors, time zones, and access roles
- Event details within a rolling sync window around the current date: titles, descriptions, locations, start and end times, organizers, attendees, and meeting links
- The email address of the connected Google account
- OAuth tokens, encrypted at rest with AES-256-GCM
How We Use Google User Data
Google user data is used solely to provide user-facing features you request: displaying your events alongside your tasks and showing in-app reminders before an event starts. Your events are private to you. They are never visible to other members of your workspaces and never appear on shared projects. The integration is read-only: we never create, edit, or delete anything in your Google Calendar.
Limited Use Statement
VA To-Do's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular, we do not:
- Use Google user data to develop, improve, or train generalized or foundational artificial intelligence or machine learning models. Google user data is never sent to OpenAI or any other AI provider, and the AI-assisted features described in this policy never receive it.
- Sell Google user data, use it for advertising, or transfer it to data brokers or information resellers
- Allow humans to read Google user data, unless we have your affirmative agreement for support purposes, it is necessary for security or abuse investigation, or we are required to do so by law
Revoking Access
You can disconnect Google Calendar at any time from Settings under Integrations. Disconnecting revokes our access with Google and permanently deletes all synced calendar data, event data, and stored tokens from our systems. You can also revoke VA To-Do's access from your Google Account permissions page.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data: Retained until you delete your account
- Task and client data: Retained until you delete it or your account is terminated
- Payment records: Retained for 7 years as required by tax and financial regulations
- Usage logs: Retained for up to 90 days
Upon account deletion, we will permanently remove your personal data within 30 days, except where retention is required by law.
9. Security
We implement industry-standard security measures to protect your data, including:
- Encryption of data in transit (TLS/HTTPS)
- Secure password hashing (bcrypt via Supabase Auth)
- Row-level security policies on database tables
- Regular security audits and updates
- Access controls and least-privilege principles for internal systems
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
10. Your Rights (United States)
If you are a resident of California or another U.S. state with applicable privacy legislation (such as the CCPA/CPRA), you have the right to:
- Know: Request disclosure of the categories and specific pieces of personal information we collect about you
- Delete: Request deletion of your personal information, subject to certain exceptions
- Opt-out: Opt out of the sale of personal information (we do not sell your data)
- Non-discrimination: Exercise your privacy rights without discriminatory treatment
To exercise these rights, contact us at the information provided below.
11. Your Rights (Philippines)
Under the Data Privacy Act of 2012 (RA 10173), you have the following rights as a data subject:
- Right to be Informed: Be informed of the collection and processing of your personal data
- Right to Object: Object to the processing of your personal data
- Right to Access: Request access to your personal data held by us
- Right to Rectification: Request correction of inaccurate or incomplete personal data
- Right to Erasure or Blocking: Request removal or blocking of personal data
- Right to Data Portability: Obtain your personal data in a structured, machine-readable format
- Right to File a Complaint: File a complaint with the National Privacy Commission (NPC) if you believe your data privacy rights have been violated
National Privacy Commission: https://www.privacy.gov.ph
12. International Data Transfers
Your data may be transferred to and processed in countries outside the Philippines, including the United States, where our service providers operate. In accordance with Section 21 of RA 10173, we ensure that adequate safeguards are in place for cross-border data transfers, including data processing agreements with our service providers that maintain equivalent levels of data protection.
13. Children's Privacy
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act (COPPA). If we discover that we have collected data from a child under 13, we will promptly delete such information. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
14. Communications & A2P Compliance
VA To-Do sends transactional communications necessary for the operation of the Service. These include:
- Account verification and email confirmation
- Password reset notifications
- Payment receipts and subscription status updates
- Critical service and security alerts
We comply with:
- TCPA (Telephone Consumer Protection Act): We do not send unsolicited marketing messages to U.S. users without express consent
- NTC Regulations: We adhere to the National Telecommunications Commission guidelines for electronic communications sent to users in the Philippines
You may manage your communication preferences in your account settings. Note that you cannot opt out of essential transactional communications required for Service operation.
15. Third-Party Links
The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party service you visit.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will provide at least 30 days' notice of material changes by posting the updated policy on the Service and notifying registered users by email where possible. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.
17. Contact & Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Company: Lester Labs LLC
- Email: support@vato-do.com
- Website: https://www.vato-do.com/
For inquiries related to the Data Privacy Act of 2012, you may also reach our Data Protection Officer at the email address above.
