Privacy Policy
How Thunderlist collects, uses, shares, stores, and protects personal data—and the choices available to you.
Version 2.0 · Effective August 6, 2026
Who we are and what this policy covers
Bayon AI, a business based in Washington, United States, operates Thunderlist and is the controller of personal data used to provide it. Its business address is 309 Highland Dr., Seattle, WA 98109, United States. Contact privacy@bayonai.com for privacy requests and support@bayonai.com for product support.
This policy applies to the Thunderlist website, progressive web app, Android app, account services, support communications, and connected billing and notification features. A third-party service you choose to connect may apply its own policy to data it receives.
Data we process
We process the following categories when you create an account, use a workspace, enable optional features, make a purchase, or contact us:
- Account and identity data: email address, account ID, sign-in method, email-verification state, and profile details you provide.
- Workspace data: lists, tasks, subtasks, notes, due dates, reminders, recurring schedules, comments, assignments, list membership, invitations, activity history, settings, and time-zone preferences.
- Files: attachment content, file name, type, size, uploader, task association, and storage metadata.
- Notifications and devices: notification preferences, feed entries, device or browser push token, app identifier, platform, and registration status.
- Subscription data: Thunderlist user ID, selected plan, entitlement tier and status, trial or renewal state, and provider transaction references. Thunderlist does not receive your complete payment-card number.
- Support and authentication communications: messages you send, email-delivery status, request identifiers, recipient domain, and information needed to investigate an issue.
- Technical data: IP address and request metadata ordinarily received by hosting and security systems, browser or device type, app version, timestamps, error details, and service logs. Development logs are not a production analytics profile.
- Local app data: user-scoped workspace snapshots, queued offline edits, service-worker caches, and authentication state stored on your device so the app can work reliably and offline.
Where data comes from
Most data comes directly from you. We may also receive limited data from these sources:
- From you when you register, create or share work, upload a file, choose settings, buy a plan, or contact support.
- From collaborators when they invite, assign, mention, or share activity with you. An inviter may provide your email address so Thunderlist can deliver and secure the invitation.
- From your device and normal service operation, including authentication, synchronization, security, offline storage, and notification delivery.
- From payment, subscription-entitlement, and app-store services when they report purchase or entitlement status.
Why we process data and our legal bases
We process personal data only for stated product, security, support, billing, and legal purposes. For people in the EU or EEA, the corresponding GDPR legal bases are:
- Contract necessity: create and secure your account; synchronize and preserve your workspace; support sharing, attachments, reminders, offline edits, subscriptions, and requested support.
- Legitimate interests: prevent fraud and abuse; keep the service reliable; diagnose failures; protect users and Thunderlist; enforce the Terms; and improve core usability without building an advertising profile. We balance these interests against your rights.
- Consent or your affirmative choice: register a device for push notifications or use another feature where law requires consent. You can disable push in Thunderlist and device settings.
- Legal obligation: keep or disclose limited records when tax, accounting, consumer, law-enforcement, court, or regulatory rules validly require it.
When data is shared
We do not sell personal data, share it for cross-context behavioral advertising, or use Thunderlist workspace content to train public advertising profiles. We disclose data only as needed for the service, at your direction, or for a valid legal reason.
Processors are expected to use the data only to provide contracted services and to protect it appropriately. Billing and app-store providers may also act as independent controllers for their payment, fraud, tax, and marketplace obligations.
- Other Thunderlist users you choose to collaborate with. Shared-list members can see the content and identity context made available in that list according to their role.
- Cloud infrastructure and application-operation providers for authentication, database and file storage, server functions, notifications, web hosting, content delivery, security, and short-lived runtime logs.
- A transactional-email provider to deliver account, security, support, and deletion-request messages.
- Stripe for web checkout and payment administration; RevenueCat for cross-platform subscription entitlements; and Google Play for Android purchases and distribution.
- Professional advisers, auditors, or authorities when reasonably necessary to protect rights, complete a corporate transaction, or comply with a valid legal requirement.
How long we keep data
We use the shortest period consistent with providing the service, resolving disputes, maintaining security, and meeting legal obligations. Current product-specific periods and criteria are:
- Account and workspace content remains while your account is active or until you delete the content, the relevant owner deletes a shared workspace, or a verified account-deletion request is completed.
- Notification-feed records expire after 90 days. Server delivery events expire after 30 days, and inactive push registrations are pruned after 90 days.
- Authentication and deletion-request email-delivery logs are configured for 30-day retention.
- Current cloud application logs are retained for 30 days. Required administrative audit logs are retained for 400 days. Current web-hosting runtime logs are retained for one day unless an extended observability service is enabled and this policy is updated.
- Offline snapshots and queued edits stay on your device until synchronized, cleared, signed out, or removed through browser/app storage controls. Uninstalling the app does not delete server data.
- Subscription, tax, transaction, dispute, security, backup, and deletion-audit records remain only as long as required by the provider, applicable law, or a documented security or legal need.
- When data is deleted from active systems, provider backups and deferred copies age out on protected cycles and are not restored for ordinary product use. A cloud provider's current processing terms allow up to 180 days to complete deletion from its systems where no legal retention exception applies.
International processing
Thunderlist and its providers may process data in the United States and other countries where they operate. Those countries may have different privacy laws from your own.
Thunderlist's current database, file-storage, server-function, and primary web-hosting processing are in United States regions. Core cloud-infrastructure and web-hosting providers act as processors for covered customer data under their published data-processing terms.
Where EU/EEA, UK, Swiss, or other transfer rules apply, the relevant provider terms provide approved standard contractual clauses or another lawful transfer mechanism, together with contractual, technical, and organizational safeguards. Bayon AI remains responsible for using covered services and configurations, honoring data-subject rights, and reviewing material provider or subprocessor changes.
Security
Thunderlist uses HTTPS in transit, provider access controls, authenticated server boundaries, deny-by-default database rules, private attachment authorization, and restricted operator access. Local offline data is protected by your device and browser security, so use a device lock and sign out before giving a device to someone else.
No service can guarantee absolute security. If you believe your account or data is at risk, contact support promptly. We will investigate and provide legally required breach notices when applicable.
Your privacy rights
Depending on your location and the circumstances, you may have the rights below. Send a request to privacy@bayonai.com. We may ask for proportionate information to verify account control and will respond within the period required by applicable law, normally one month under the GDPR.
Thunderlist does not make decisions producing legal or similarly significant effects through solely automated processing. Exercising a privacy right will not result in unlawful discrimination. You may complain to the privacy, consumer-protection, or data-protection authority available where you live, work, or believe an infringement occurred.
- Ask for access to and a copy of your personal data.
- Correct inaccurate data and complete incomplete data.
- Request deletion, restriction, or portability where the conditions apply.
- Object to processing based on legitimate interests and withdraw consent for future processing where consent is the basis.
- Complain to a data-protection authority where you live, work, or believe an infringement occurred.
US state privacy disclosures
Residents of US states with applicable privacy laws may request access, correction, deletion, or a portable copy and may appeal a denied request by replying to our decision at privacy@bayonai.com. Thunderlist does not sell personal information, use it for targeted advertising, or share it for cross-context behavioral advertising.
Thunderlist processes account credentials, private communications, precise task timing, and uploaded content only for the service purposes described here. We do not use or disclose sensitive personal information to infer characteristics about you.
Cookies and local device storage
Thunderlist uses account-authentication persistence, IndexedDB, local storage, service-worker caches, and limited session storage that are strictly necessary to sign you in, remember security and app state, preserve a user-scoped workspace snapshot, queue offline edits, secure requests, and update the app. Hosting and security providers may also use essential storage to deliver or protect the service. Blocking it may prevent core or offline features from working.
Thunderlist does not currently use advertising cookies, cross-site behavioral tracking, or optional analytics cookies or storage. Because only strictly necessary storage is used, Thunderlist does not currently show a cookie-consent banner. If non-essential tracking is introduced, it will remain disabled until this policy and any consent or opt-out controls required by law are in place.
Children
Thunderlist is a general-audience productivity service and is not directed to children under 13. You must be at least 13 to create an account. If local law requires parent or guardian authorization for a person under the local age of legal or digital consent, that authorization is required before use.
Thunderlist does not ask for a date of birth or use an age-input gate. If Bayon AI learns that an account belongs to a child under 13, or that required authorization is missing, contact privacy@bayonai.com; we will investigate and delete or otherwise handle the data as law requires.
Changes and contact
We may update this policy when Thunderlist, its providers, or applicable rules change. The effective date will be updated, and we will give additional notice before a material change when required. Questions and requests can be sent to privacy@bayonai.com.