GSD at the speed of light!

Put all your tasks in one place, share, collaborate, and finish things off!

Privacy Policy

How Thunderlist collects, uses, shares, stores, and protects personal data—and the choices available to you.

Version 2.3 · Effective August 28, 2026

Who we are and what this policy covers

Bayon AI, a business based in Washington, United States, operates Thunderlist and is the controller of personal data used to provide it. Its business address is 309 Highland Dr., Seattle, WA 98109, United States. Contact privacy@bayonai.com for privacy requests and support@bayonai.com for product support.

This policy applies to the Thunderlist website, progressive web app, Android app, account services, support communications, and connected billing and notification features. A third-party service you choose to connect may apply its own policy to data it receives.

Data we process

We process the following categories when you create an account, use a workspace, enable optional features, make a purchase, or contact us:

  • Account and identity data: email address, account ID, sign-in method, email-verification state, and profile details you provide.
  • Workspace data: lists, tasks, subtasks, notes, due dates, reminders, recurring schedules, comments, assignments, list membership, invitations, activity history, settings, and time-zone preferences.
  • Files: attachment content, file name, type, size, uploader, task association, and storage metadata.
  • Notifications and devices: notification preferences, feed entries, device or browser push token, app identifier, platform, and registration status.
  • Subscription data: Thunderlist user ID, selected plan, entitlement tier and status, trial or renewal state, and provider transaction references. Thunderlist does not receive your complete payment-card number.
  • Support and authentication communications: messages you send, email-delivery status, request identifiers, recipient domain, and information needed to investigate an issue.
  • Technical data: IP address and request metadata ordinarily received by hosting and security systems, browser or device type, app version, timestamps, error details, and service logs. Development logs are not a production analytics profile.
  • Optional product analytics: if you opt in, PostHog receives a pseudonymous account identifier, normalized screen and feature-use events, browser or app context, timestamps, automatic interaction and dead-click metrics, heatmaps, web-vital measurements, and browser error details. It also receives a session replay with all visible text, form input, and DOM attribute values masked. We do not send workspace content, email addresses, document IDs, query values, network request bodies, request headers, or console logs to this service.
  • MCP connection data: when you choose to connect an external MCP client, we process the client-supplied display name, registered callback host, approved read or write scopes, credential identifiers stored only as hashes, and credential expiration state. We do not send your workspace content to an AI model as part of Thunderlist's MCP service.
  • Local app data: user-scoped workspace snapshots, queued offline edits, service-worker caches, and authentication state stored on your device so the app can work reliably and offline.

Where data comes from

Most data comes directly from you. We may also receive limited data from these sources:

  • From you when you register, create or share work, upload a file, choose settings, buy a plan, or contact support.
  • From collaborators when they invite, assign, mention, or share activity with you. An inviter may provide your email address so Thunderlist can deliver and secure the invitation.
  • From your device and normal service operation, including authentication, synchronization, security, offline storage, and notification delivery.
  • From payment, subscription-entitlement, and app-store services when they report purchase or entitlement status.
  • From an MCP client only after you approve its requested access in Thunderlist. The client receives data from Thunderlist only through the scopes you approve.

Why we process data and our legal bases

We process personal data only for stated product, security, support, billing, and legal purposes. For people in the EU or EEA, the corresponding GDPR legal bases are:

  • Contract necessity: create and secure your account; synchronize and preserve your workspace; support sharing, attachments, reminders, offline edits, subscriptions, and requested support.
  • Contract necessity and your affirmative connection choice: provide the read or write MCP access that you explicitly approve, secure the connection, and let you disconnect it.
  • Legitimate interests: prevent fraud and abuse; keep the service reliable; diagnose failures; protect users and Thunderlist; enforce the Terms; and improve core usability without building an advertising profile. We balance these interests against your rights.
  • Consent or your affirmative choice: register a device for push notifications or use another feature where law requires consent. You can disable push in Thunderlist and device settings.
  • Consent: optional product analytics runs only after you enable Product analytics in Settings. You can withdraw consent at any time in Settings, which stops future capture and clears the analytics identity on that device.
  • Legal obligation: keep or disclose limited records when tax, accounting, consumer, law-enforcement, court, or regulatory rules validly require it.

When data is shared

We do not sell personal data, share it for cross-context behavioral advertising, or use Thunderlist workspace content to train public advertising profiles. We disclose data only as needed for the service, at your direction, or for a valid legal reason.

Processors are expected to use the data only to provide contracted services and to protect it appropriately. Billing and app-store providers may also act as independent controllers for their payment, fraud, tax, and marketplace obligations.

  • Other Thunderlist users you choose to collaborate with. Shared-list members can see the content and identity context made available in that list according to their role.
  • Cloud infrastructure and application-operation providers for authentication, database and file storage, server functions, notifications, web hosting, content delivery, security, and short-lived runtime logs.
  • A transactional-email provider to deliver account, security, support, and deletion-request messages.
  • Stripe for web checkout and payment administration; RevenueCat for cross-platform subscription entitlements; and Google Play for Android purchases and distribution.
  • PostHog for optional product analytics, error tracking, interaction diagnostics, and privacy-masked session replay after your consent. It receives only the pseudonymous and minimized data described in this policy.
  • An MCP client you choose to connect. A client with read access can receive the lists, tasks, subtasks, and notes you can access. A client with separately approved write access can also create or update lists, tasks, and subtasks. The client is an independent recipient for the data it receives and may process or transmit it under its own terms, including to an AI provider. Review the client and its callback host before you approve it.
  • Professional advisers, auditors, or authorities when reasonably necessary to protect rights, complete a corporate transaction, or comply with a valid legal requirement.

How long we keep data

We use the shortest period consistent with providing the service, resolving disputes, maintaining security, and meeting legal obligations. Current product-specific periods and criteria are:

  • Account and workspace content remains while your account is active or until you delete the content, the relevant owner deletes a shared workspace, or a verified account-deletion request is completed.
  • Notification-feed records expire after 90 days. Server delivery events expire after 30 days, and inactive push registrations are pruned after 90 days.
  • Authentication and deletion-request email-delivery logs are configured for 30-day retention.
  • Current cloud application logs are retained for 30 days. Required administrative audit logs are retained for 400 days. Current web-hosting runtime logs are retained for one day unless an extended observability service is enabled and this policy is updated.
  • PostHog product analytics and error reports are retained for up to 12 months under the current project setting; session replays are retained for 30 days. All replay text, form input, and DOM attribute values are masked before transmission.
  • MCP authorization codes expire after five minutes, access tokens after one hour, and refresh tokens after 30 days. Thunderlist removes expired MCP credential records through a daily maintenance process. When you disconnect an MCP client in Settings, we immediately delete its active authorization-code, access-token, and refresh-token records for your account.
  • Offline snapshots and queued edits stay on your device until synchronized, cleared, signed out, or removed through browser/app storage controls. Uninstalling the app does not delete server data.
  • Subscription, tax, transaction, dispute, security, backup, and deletion-audit records remain only as long as required by the provider, applicable law, or a documented security or legal need.
  • When data is deleted from active systems, provider backups and deferred copies age out on protected cycles and are not restored for ordinary product use. A cloud provider's current processing terms allow up to 180 days to complete deletion from its systems where no legal retention exception applies.

International processing

Thunderlist and its providers may process data in the United States and other countries where they operate. Those countries may have different privacy laws from your own.

Thunderlist's current database, file-storage, server-function, and primary web-hosting processing are in United States regions. Core cloud-infrastructure and web-hosting providers act as processors for covered customer data under their published data-processing terms.

Where EU/EEA, UK, Swiss, or other transfer rules apply, the relevant provider terms provide approved standard contractual clauses or another lawful transfer mechanism, together with contractual, technical, and organizational safeguards. Bayon AI remains responsible for using covered services and configurations, honoring data-subject rights, and reviewing material provider or subprocessor changes.

Security

Thunderlist uses HTTPS in transit, provider access controls, authenticated server boundaries, deny-by-default database rules, private attachment authorization, and restricted operator access. Local offline data is protected by your device and browser security, so use a device lock and sign out before giving a device to someone else.

No service can guarantee absolute security. If you believe your account or data is at risk, contact support promptly. We will investigate and provide legally required breach notices when applicable.

Your privacy rights

Depending on your location and the circumstances, you may have the rights below. Send a request to privacy@bayonai.com. We may ask for proportionate information to verify account control and will respond within the period required by applicable law, normally one month under the GDPR.

Thunderlist does not make decisions producing legal or similarly significant effects through solely automated processing. Exercising a privacy right will not result in unlawful discrimination. You may complain to the privacy, consumer-protection, or data-protection authority available where you live, work, or believe an infringement occurred.

  • Ask for access to and a copy of your personal data.
  • Correct inaccurate data and complete incomplete data.
  • Request deletion, restriction, or portability where the conditions apply.
  • Object to processing based on legitimate interests and withdraw consent for future processing where consent is the basis.
  • Complain to a data-protection authority where you live, work, or believe an infringement occurred.

US state privacy disclosures

Residents of US states with applicable privacy laws may request access, correction, deletion, or a portable copy and may appeal a denied request by replying to our decision at privacy@bayonai.com. Thunderlist does not sell personal information, use it for targeted advertising, or share it for cross-context behavioral advertising.

Thunderlist processes account credentials, private communications, precise task timing, and uploaded content only for the service purposes described here. We do not use or disclose sensitive personal information to infer characteristics about you.

Cookies and local device storage

Thunderlist uses account-authentication persistence, IndexedDB, local storage, service-worker caches, and limited session storage that are strictly necessary to sign you in, remember security and app state, preserve a user-scoped workspace snapshot, queue offline edits, secure requests, and update the app. Hosting and security providers may also use essential storage to deliver or protect the service. Blocking it may prevent core or offline features from working.

Thunderlist does not use advertising cookies or cross-site behavioral tracking. Optional product analytics remains disabled until you explicitly enable it in Settings. When enabled, PostHog may use analytics storage for pseudonymous product-use events, privacy-masked session replay, error reports, interaction diagnostics, and web-vital measurements. You can withdraw consent at any time in Settings.

MCP access is not enabled by browser storage. You must explicitly approve each connected client on its Thunderlist authorization screen, and you can disconnect it from Settings > Account > Connected apps.

Children

Thunderlist is a general-audience productivity service and is not directed to children under 13. You must be at least 13 to create an account. If local law requires parent or guardian authorization for a person under the local age of legal or digital consent, that authorization is required before use.

Thunderlist does not ask for a date of birth or use an age-input gate. If Bayon AI learns that an account belongs to a child under 13, or that required authorization is missing, contact privacy@bayonai.com; we will investigate and delete or otherwise handle the data as law requires.

Changes and contact

We may update this policy when Thunderlist, its providers, or applicable rules change. The effective date will be updated, and we will give additional notice before a material change when required. Questions and requests can be sent to privacy@bayonai.com.