The branch's documents describe a world where the vendored provider reached users. It never did, and several claims follow from that mistake. `ROADMAP.md`: - Phase 5's "**Breaking:** the authority and both custom permissions no longer exist — anyone who pointed DAVx5 at that authority loses it, and the release notes have to say so" is wrong in the way that *removes* work: they were added and deleted inside this unreleased cycle, so nobody could have pointed anything at them. The release notes must not warn about losing something that never shipped. The per-locale release-notes item went with it. - "Run the instrumented suite on a device … none has ever executed" was stale: 52 tests, 0 failures, Pixel 10 / API 36, 13 Aug. What is genuinely open is a re-run against the tip, since the 4 Sep commits reworked the store and added instrumented cases that have never run. Both now say so, with the ARM64 aapt exit-code trap noted where someone will hit it. - The device-verification item described upgrading from a v0.3.2 APK with seeded data, which cannot be the real path. Replaced with the four cases that matter, including the one that only exists on a device that side-loaded a dev build of this branch. - M6's Glance item claimed "deps present in build.gradle.kts" — not any more. Translations and the language picker shipped in 0.4.0 and are marked done. `OWN-STORE.md` gets a correction banner over "Migrating existing users" saying the premise is wrong, and a section for the copy that replaces it. `STORAGE-AND-SYNC.md`'s banner said the vendored-provider decision was "made, shipped, and then costed properly" — built, not shipped. `PRIVACY.md` had the opposite problem: it describes CalDAV sync, Nextcloud Login Flow v2, RFC 6764 discovery and a Keystore-held password, none of which exist in 1.0.0 — the app holds no `INTERNET` permission at all. The permissions section listed six it does not declare. Since it is a legal document users are sent to from Settings → About, section 4 is now marked as describing a planned feature, section 9 lists exactly what the manifest declares (and says what is *not* there), and the backup and crash-report sections no longer assume network access or sync bookkeeping. Kept forward-looking rather than cut, so it does not have to change underneath anyone when sync lands. **Worth a read before merging** — it is the one change here with legal weight. `fastlane/.../full_description.txt` still opened with "It works directly on an existing tasks provider (OpenTasks / tasks.org) … no own account, no own sync" as the app's premise. That is the F-Droid listing for a release whose headline is that it needs nothing installed. Rewritten, with the feature list and the no-internet-permission point that is now literally true. `README.md` and `ExportWriter`'s "ships in eleven locales" (it is three) follow.
266 lines
12 KiB
Markdown
266 lines
12 KiB
Markdown
---
|
||
title: Privacy Policy — Agendula
|
||
description: What Agendula does with your data. No servers, no account, no analytics — your tasks stay on your device unless you add a CalDAV server yourself.
|
||
updated: 2026-09-21
|
||
---
|
||
|
||
<!--
|
||
THIS FILE IS THE POLICY. Edit it here, in a PR, reviewed like any other
|
||
change — it is the source of truth.
|
||
|
||
It is published at https://jeanlucmakiola.de/agendula/privacy, which is what
|
||
the app's Settings → About → Privacy policy row opens and what the Play
|
||
Console field must hold. That page holds no copy of the prose: the website
|
||
build checks this repository out beside itself and renders this file through
|
||
an Astro content collection, so there is exactly one copy of the policy
|
||
anywhere and the two cannot drift. An edit here reaches the live page on the
|
||
site's next build.
|
||
|
||
The page supplies its own <h1> from the `title` above, so this body starts at
|
||
the first section — do not add one. This comment is HTML so that it cannot
|
||
render on the published page.
|
||
-->
|
||
|
||
**Last updated:** 21 September 2026
|
||
Applies to the Android app **Agendula** (package `de.jeanlucmakiola.agendula`),
|
||
all versions and all distribution channels.
|
||
|
||
## In short
|
||
|
||
Agendula has no servers, no user accounts and no analytics. Your tasks live on
|
||
your device. They leave it in exactly one case: if you set up a CalDAV account
|
||
yourself, they are synchronised with **the server you entered** — and with
|
||
nothing and no one else. Nothing is ever sent to the developer.
|
||
|
||
> **As of version 1.0.0, CalDAV sync is not in the app yet.** It is designed and
|
||
> described here so that this policy does not have to change underneath you when
|
||
> it arrives, but the released app has **no network access of its own at all** —
|
||
> it does not hold Android's `INTERNET` permission, so section 4 cannot happen on
|
||
> this version. Until it ships, your tasks leave the device only if *you* export
|
||
> them, or if a separate sync app you installed yourself syncs a task provider you
|
||
> pointed Agendula at (section 3).
|
||
|
||
## 1. Controller
|
||
|
||
IT-Dienstleister | Jean-Luc Makiola
|
||
Mahlerstraße 10
|
||
14772 Brandenburg an der Havel
|
||
Email: [support@jeanlucmakiola.de](mailto:support@jeanlucmakiola.de)
|
||
|
||
## 2. No data collection by the developer
|
||
|
||
Agendula contains **no analytics, no tracking, no advertising, no
|
||
crash-reporting SDK and no third-party service that reports anything
|
||
anywhere**. No user profile is created, no advertising or device identifier is
|
||
generated, and no data is shared with or sold to anyone. There is no Agendula
|
||
account, and the developer operates no server that the app talks to.
|
||
|
||
All of this is verifiable in the
|
||
[source code](https://codeberg.org/jlmakiola/agendula), which is public.
|
||
|
||
## 3. Where your tasks live — your choice
|
||
|
||
- **On your device (the default)** — your task lists, tasks and reminders are
|
||
kept in Agendula's own database inside the app's private storage. Nothing is
|
||
published to other apps, and uninstalling the app removes it.
|
||
- **In a tasks provider you already use** — OpenTasks or tasks.org. Agendula
|
||
then reads and writes that app's task database through Android's provider
|
||
mechanism, after you grant its read/write permission. Whatever already
|
||
synchronises that provider (DAVx5, SmoothSync, DecSync CC, …) keeps doing so,
|
||
unchanged; that synchronisation is performed by those apps, not by Agendula,
|
||
and their privacy policies apply to it.
|
||
|
||
## 4. CalDAV sync — the only case where your tasks leave the device
|
||
|
||
*Not available in version 1.0.0 — see the note in "In short". This section
|
||
describes how it will behave, and is published in advance deliberately.*
|
||
|
||
Sync is optional and off until you add an account. If you add one, everything
|
||
below happens between your device and **the server you nominated**, and nowhere
|
||
else.
|
||
|
||
### What is stored on your device
|
||
|
||
The server address, your username, and your password or app password. The
|
||
password is encrypted with a key held in the Android Keystore, which cannot be
|
||
exported from the device.
|
||
|
||
### What is transmitted, and to whom
|
||
|
||
- The tasks in the synchronised lists, as standard iCalendar (`VTODO`) data,
|
||
and the credentials needed to authenticate.
|
||
- Requests carry the user agent `Agendula (Android)` — a fixed string, so that
|
||
you can recognise and revoke the session on your server. No device identifier
|
||
is sent.
|
||
- Connections are HTTPS. Cleartext HTTP is refused, so credentials are never
|
||
sent over an unencrypted connection.
|
||
|
||
Nothing is sent anywhere else. In particular, nothing is sent to the developer.
|
||
|
||
Under Google Play's Data Safety definitions this counts as **collected** — Play
|
||
defines collection as transmitting data off the device, regardless of who
|
||
receives it — and **not shared**, because the only recipient is the server you
|
||
nominated. Data is encrypted in transit.
|
||
|
||
### Finding your server
|
||
|
||
When you type a server address or an email domain, Agendula follows the
|
||
standard discovery procedure (RFC 6764): a DNS lookup for the `_caldavs._tcp`
|
||
service record of that domain, then `/.well-known/caldav` on the host. The DNS
|
||
query goes to whichever resolver your device or network uses, and the requests
|
||
go to the domain you typed — no directory of servers is consulted and no lookup
|
||
is sent to the developer.
|
||
|
||
### Signing in to a Nextcloud
|
||
|
||
If the server is a Nextcloud, Agendula uses Nextcloud's Login Flow v2: your
|
||
browser opens *your own server's* login page, you authorise there, and the
|
||
server hands the app a dedicated app password. Agendula never sees your actual
|
||
account password. The app password appears in your server's "Devices &
|
||
sessions" list as `Agendula (Android)`, and you can revoke it there at any
|
||
time. Removing the account in Agendula revokes it too, where the server
|
||
supports that.
|
||
|
||
### Your server's own policy
|
||
|
||
Your CalDAV provider has its own privacy policy, and your data on their server
|
||
is governed by it. Agendula has no relationship with them.
|
||
|
||
A note on certificates: Agendula trusts private certificate authorities that
|
||
you have installed in your device's user store, because self-hosted servers
|
||
routinely use them. That is a deliberate trade-off in favour of self-hosters —
|
||
any CA installed on your device (for example by an employer's management
|
||
profile) can, in principle, intercept traffic from the app, as it can from
|
||
other apps that make the same choice.
|
||
|
||
## 5. Other data Agendula handles on your device
|
||
|
||
### Reminders and notifications
|
||
|
||
Due-date reminders are scheduled by the app itself and displayed as local
|
||
notifications. Nothing is sent to a push service — there is no push service.
|
||
|
||
### Export files
|
||
|
||
You can export your tasks as standard iCalendar `.ics` files. Agendula writes
|
||
exactly the file you select through Android's system file picker, and has no
|
||
access to other files.
|
||
|
||
### App settings
|
||
|
||
Your preferences (theme, language, list and reminder defaults and similar) are
|
||
stored locally on your device and are removed when you uninstall the app.
|
||
|
||
## 6. Backups
|
||
|
||
If Android Auto Backup is enabled on your device, your tasks and settings may
|
||
be backed up to your own Google account, under Google's terms — the developer
|
||
has no access to it. What travels is Agendula's own task database and your
|
||
settings, and nothing else: the backup rules name those explicitly, which makes
|
||
everything not named — including the archived copy the app keeps of an older
|
||
version's database — excluded by default.
|
||
|
||
Once CalDAV sync ships, two further things will be kept out of that backup by
|
||
design: the stored password, and the per-device sync bookkeeping. Restoring onto
|
||
a new device will therefore mean signing in to your server again.
|
||
|
||
## 7. Crash reports
|
||
|
||
If Agendula crashes, it offers to report the problem. Nothing is sent
|
||
automatically — and on this version the app could not send it if it wanted to,
|
||
having no network permission. The report is copied to your clipboard and your
|
||
browser is opened with the project's issue tracker, the text pre-filled. **You see the full content, you decide whether to submit it,
|
||
and you can edit or discard it.**
|
||
|
||
Such a report contains:
|
||
|
||
- app version,
|
||
- Android version,
|
||
- device manufacturer and model,
|
||
- your device language,
|
||
- the timestamp,
|
||
- and the technical stack trace.
|
||
|
||
It is built from that fixed list and nothing else: **no** task data, **no**
|
||
server address or credentials, **no** account names, **no** log files and
|
||
**no** personal identifiers.
|
||
|
||
If you choose to submit it, the report becomes a public issue on the project's
|
||
issue tracker at Codeberg, operated by Codeberg e. V. Their privacy policy then
|
||
applies to that submission.
|
||
|
||
## 8. External links
|
||
|
||
The app links to the source code, the licence, the issue tracker, the
|
||
translation platform (Weblate) and a voluntary donation page (Ko-fi). Following
|
||
one of these links opens your browser and leaves the app; the privacy policy of
|
||
the respective website then applies. Agendula transmits no data of yours in the
|
||
process — it only opens the address.
|
||
|
||
## 9. Permissions and why they exist
|
||
|
||
This is the complete list the released app declares — you can check it against
|
||
the app's entry in F-Droid, or against `app/src/main/AndroidManifest.xml` in the
|
||
source:
|
||
|
||
- `POST_NOTIFICATIONS` — show reminders.
|
||
- `USE_EXACT_ALARM`, `SCHEDULE_EXACT_ALARM` — deliver reminders at the exact
|
||
due time.
|
||
- `RECEIVE_BOOT_COMPLETED` — re-register pending reminders after a restart.
|
||
- `org.dmfs.permission.READ_TASKS` / `WRITE_TASKS` and
|
||
`org.tasks.permission.READ_TASKS` / `WRITE_TASKS` — optional, requested only
|
||
if you choose the external-provider storage mode, and only for the provider
|
||
you selected (OpenTasks or tasks.org). All four are declared in the manifest
|
||
because a manifest is static, but none is requested until you pick that mode.
|
||
|
||
Note what is **not** there: Agendula declares no `INTERNET` permission, so the
|
||
released app cannot make a network connection of any kind. When CalDAV sync
|
||
ships it will need `INTERNET` and `ACCESS_NETWORK_STATE`, and the sync-framework
|
||
permissions to schedule itself; this section will be updated in the same release
|
||
that adds them, never before.
|
||
|
||
Agendula publishes no content provider of its own and declares no permissions
|
||
that other apps could request.
|
||
|
||
## 10. Distribution channels
|
||
|
||
Agendula is distributed through the project's releases on Codeberg, a
|
||
self-hosted F-Droid repository, Obtainium, and — where applicable — F-Droid and
|
||
the Google Play Store. When you download or update the app, the operator of
|
||
that channel processes data (such as your IP address) under their own privacy
|
||
policy. This is outside the developer's control and unrelated to the app's own
|
||
behaviour.
|
||
|
||
## 11. Children
|
||
|
||
Agendula is not directed at children and collects nothing about anyone.
|
||
|
||
## 12. Deleting your data
|
||
|
||
- **Remove a CalDAV account** from Settings → Accounts. This deletes the stored
|
||
credential and, where the server supports it, revokes the app password. Task
|
||
lists become device-only lists rather than being destroyed.
|
||
- **Remove an account and delete its local data** removes the lists and tasks
|
||
as well.
|
||
- **Uninstalling the app** removes everything Agendula stored on the device.
|
||
|
||
Deleting data from your CalDAV server is done on that server; data in an
|
||
external tasks provider is deleted in that app.
|
||
|
||
## 13. Your rights
|
||
|
||
The developer stores no personal data of yours — the only data transfer the app
|
||
performs is between your device and a server you operate or chose. There is
|
||
therefore no data held by the developer to which rights of access,
|
||
rectification, erasure, restriction, data portability or objection (Art. 15–21
|
||
GDPR) could apply. Your tasks are exportable as standard `.ics` files from
|
||
within the app at any time. You may contact the address above with any
|
||
question, and you have the right to lodge a complaint with a supervisory
|
||
authority.
|
||
|
||
## 14. Changes to this policy
|
||
|
||
Should the app's functionality change in a way that affects data processing,
|
||
this policy will be updated and the date at the top adjusted. The history of
|
||
this file is public in the repository.
|