← Back to Home
Privacy Policy
Last Updated: March 2026
Welcome to Timebox Canvas. Your privacy is critically important to us. This Privacy Policy outlines how your
information is handled when you use the Timebox Canvas application ("the Application").
1. Data Collection & Storage
Timebox Canvas is a deeply integrated, client-side only application designed to operate directly within your
browser. We do not own, operate, or maintain any backend database servers that store your personal
data.
All data created or modified within the Application, including tasks, notes, subtasks, and board configurations,
is stored exclusively in the following places:
- Locally in your browser: Utilizing standard Web Storage (localStorage/IndexedDB) for
caching and immediate retrieval.
- Directly to your personal Google Account: Core application data is stored in Google Tasks.
If you enable optional Google Drive features, related files and metadata such as attachments, cover images,
synced wallpaper, and Drive links are stored in your Google Drive.
- Authentication token handling: The hosted application may store a Google refresh token and
the last granted scope set in protected server-side auth storage so access tokens can be renewed. This is
not used to store board or task content.
2. Google Account Permissions
To function properly, the Application requests authorization to access specific Google scopes. Base sign-in uses
Google Tasks plus basic account identity. Additional integrations are optional and only requested when you turn
them on in Settings:
- Google Tasks: To read, create, update, and delete tasks and task lists synchronized with
Timebox Canvas.
- Basic Google identity: To read your profile name, email address, and avatar so the app can
show your account and keep local settings scoped to the correct Google user.
- Google Drive (Optional): To manage attachments, cover previews, Drive links, synced
wallpaper, and Drive folder access for enabled boards.
- Google Calendar (Optional, read-only): To show calendar events in Unified Day and to
account for events when calculating daily capacity.
- Google Contacts (Optional): To provide @mention type-ahead conveniences within task
descriptions, allowing you to quickly reference contacts.
You can revoke these permissions at any time through your Google Account Security settings.
3. Managing and Deleting Your Data
Because Timebox Canvas stores information directly in your browser and in your own Google account, you remain in
control of that data. You can manage or delete it in the following ways:
- Tasks and board content stored in Google Tasks: Delete the relevant tasks, task lists, or
board data from within Timebox Canvas or directly in Google Tasks.
- Files stored in Google Drive: Remove attachments, cover images, synced wallpaper files, or
related Drive files directly from Google Drive if you no longer want them retained there.
- Local browser storage: Clear your browser storage, site data, or application data for this
site to remove locally cached settings and stored session-related information from your device.
- Google account access: Revoke the application's Google access in your Google Account
Security settings to stop the application from accessing your Google data going forward.
- Authentication token data: If you want stored authentication credentials removed, revoke the
application's Google access and request removal through the application's support or admin channel.
Timebox Canvas does not maintain a separate central database of your board or task content, so deleting the data
in the locations above is the primary method for removing it.
4. Telemetry and Analytics
We do not use embedded third-party trackers, analytics scripts (like Google Analytics), or behavioral tracking
pixels within the core application. The application does not collect usage analytics or behavioral telemetry to
track how you interact with specific features.
5. Advertising
Timebox Canvas does not display advertisements and does not share, rent, or sell any of your personal
information, task data, or Google Account details to third-party advertising networks or data brokers.
6. Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify users by
indicating the date of the latest revision at the top of this page. Your continued use of the Application after
changes have been published constitutes your acceptance of the revised policy.
7. Contact
If you have any questions or concerns about this Privacy Policy or how your data is handled, please reach out via
our GitHub repository or primary support channels.