Privacy Policy

Effective date: September 26, 2026

Todoke ("the app") is a third-party client for GitHub Issues, developed by David Collado Sela ("we", "us"). This policy explains what data the app touches, where it lives, and — most importantly — what we never see.

The short version: we collect almost nothing. Todoke has no server that stores your GitHub data, no ads, and no trackers. Your GitHub token lives only in your device's Keychain, and your issues travel directly between your device and GitHub. Two things do leave your device: anonymous usage totals, sent to TelemetryDeck so we know what to fix (see Analytics, advertising, and tracking), and Todoke Pro's one-time purchase, processed by our payments partner RevenueCat (see Todoke Pro purchases). Neither is ever linked to you or to your GitHub account.

Signing in with GitHub

Todoke signs you into your existing GitHub account using GitHub's standard OAuth authorization code flow, with PKCE (a code verifier/challenge pair, generated fresh on your device) added on top, in a system browser session. The app never sees your GitHub password.

PKCE alone isn't enough to complete GitHub's flow: GitHub's authorization-code exchange still requires a confidential application secret, which cannot safely ship inside a public app binary. For that one step — and that step only — the app calls a small service we operate (a Cloudflare Worker at todoke-auth.bitomule.workers.dev) that holds the secret on our behalf. This service:

  • performs only the momentary code-for-token exchange (and token refresh) with GitHub;
  • holds the application secret so the app doesn't have to;
  • stores nothing — no database, no user records, no token logs. The exchange is transient: the token passes through to your device and is immediately forgotten;
  • never receives your issues, comments, repositories, or any other GitHub content.

Your access token

The token GitHub issues to you is stored only on your device, in the iOS Keychain (device-only, protected after first unlock). It is never synced to iCloud, never sent to us, and only ever transmitted to api.github.com and github.com to make the requests you ask for.

Your GitHub data

Issues, comments, repositories, labels, and profile information flow directly between your device and GitHub, authenticated with your own token. Todoke displays that data; it does not copy it to any server of ours. Your use of GitHub itself is governed by GitHub's Privacy Statement.

Todoke can only access the repositories you explicitly grant when you install the Todoke GitHub App, requesting only the Issues permission plus GitHub's mandatory read-only Metadata permission (repository names and labels — never source code). You can review the exact permissions the app requests on that page before installing it, and again any time at github.com/settings/installations.

Todoke Pro purchases

Todoke Pro is a single one-time purchase (there is no subscription) that we sell and deliver through Apple's In-App Purchase system and process with our payments partner, RevenueCat.

RevenueCat's SDK is configured on every launch — not only at the moment of purchase — so the app can tell whether your Apple Account already owns Todoke Pro. That means every install, free or Pro, sends RevenueCat an anonymous, app-specific identifier it generates on your device, and, when you buy or restore, your purchase transaction.

That identifier is never linked to your GitHub identity, your GitHub token, or anything you do inside Todoke — RevenueCat never sees an issue, a comment, or a repository name. It exists to answer one question: is this Apple Account entitled to Todoke Pro. It is not used for advertising, tracking, or building a profile of you, and Todoke's own code never adds identifying information to it.

Analytics, advertising, and tracking

Todoke contains no advertising and no trackers, and it does not build a profile of you.

It does count how the app is used, in aggregate, through TelemetryDeck, a privacy-focused analytics service. What it sends is a short list of anonymous events — the app was opened, a sign-in started, finished or was cancelled, issues loaded (as a rough count of repositories, never their names), the upgrade screen was shown, a purchase started, finished or failed — together with the technical context TelemetryDeck attaches to every event: app version, device model, iOS version, language, region, and display and accessibility settings. Each install is identified only by an app-specific device identifier that is salted and hashed on your device and hashed again by TelemetryDeck on arrival, so neither they nor we can turn it back into anything about you.

No issue, comment, repository name, GitHub username or token is ever sent. We use these totals to find where people get stuck and what to fix; they are never used for advertising, never linked to your GitHub identity, and never combined with data from other companies.

Beyond RevenueCat, described above, and TelemetryDeck, Todoke contains no third-party SDK that receives data from your device.

This website

todokeapp.com counts page views with TelemetryDeck's web script. It sets no cookies and does no fingerprinting. Each page load sends one anonymous page-view event: which page, the site you came from, campaign tags in the link if any, your country and language, and your browser and device type. To tell one visitor from another on the same day, TelemetryDeck hashes your IP address and browser string together with a salt that changes every day, so you are not recognised the next day or on any other site. The site has no ads and no other third-party scripts.

Preferences

App preferences (issue filters, repository defaults, and similar settings) are stored on your device in local app storage (UserDefaults). They never leave your device.

Signing out and revoking access

When you sign out, Todoke deletes the token from your device's Keychain and asks GitHub to revoke it, so it can no longer be used anywhere.

You can also revoke Todoke's access yourself at any time, independently of the app, at github.com/settings/apps/authorizations, and manage or uninstall the Todoke GitHub App from your repositories at github.com/settings/installations.

Data retention

We retain nothing on our own infrastructure. Removing the app from your device (or signing out) removes everything Todoke stored locally, and revoking the authorization on GitHub severs the app's access to your GitHub data entirely. RevenueCat keeps the purchase record described above under its own privacy policy, for as long as needed to keep your Todoke Pro entitlement working. TelemetryDeck keeps the anonymous usage events under its own privacy policy; because they cannot be tied back to you, there is nothing in them we could find and delete for a specific person.

Children

Todoke is not directed at children and is not intended for use by anyone under 13 (or the equivalent minimum age in your jurisdiction). GitHub itself requires users to be at least 13. We do not knowingly collect any information from children.

Changes to this policy

If this policy changes, the updated version will be posted at this address with a new effective date.

Contact

Questions about privacy in Todoke: [email protected]