Privacy Policy – Super Productivity

Last updated: April 2, 2026

Overview

Super Productivity is designed with privacy as a core principle. All your data is stored locally on your device by default. Data is only transferred to external services when you explicitly enable synchronization features.

Data Controller

Responsible for data processing (Art. 4(7) GDPR):

Johannes Millan Hauptstraße 4H 10407 Berlin, Germany Email: contact@super-productivity.com

For full legal notice, see our Imprint.

We process personal data only when we have a lawful basis under Art. 6(1) GDPR:

Processing ActivityLegal Basis
Local data storageNo processing by us (data stays on your device)
Sync services (when enabled)Art. 6(1)(b) - Contract performance
Issue tracker integrations (when enabled)Art. 6(1)(b) - Contract performance
Google Calendar integration (when enabled)Art. 6(1)(b) - Contract performance
Website analyticsArt. 6(1)(f) - Legitimate interest in improving our website
YouTube videos (when played)Art. 6(1)(a) - Consent (by choosing to play)
Contact requestsArt. 6(1)(b) - Pre-contractual measures

Data Storage

Local Storage (Default)

By default, Super Productivity stores all your data locally:

  • Desktop (Windows, macOS, Linux): Data is stored in your user data folder using IndexedDB and Backups are stored in SQLite files.
  • Web App: Data is stored in your browser’s IndexedDB
  • Mobile (Android): Data is stored in the app’s local storage

No data is transmitted to any server unless you explicitly enable a sync or integration feature.

Optional Synchronization

If you choose to enable synchronization, your data will be transferred to the service you select:

Dropbox Sync

  • Your task data is stored in your personal Dropbox account
  • Super Productivity uses Dropbox’s official API
  • See Dropbox’s Privacy Policy

WebDAV Sync

  • Your task data is stored on your chosen WebDAV server
  • You control where your data is stored
  • No data passes through Super Productivity servers

Super Sync (Optional Paid Service)

  • If you use Super Sync, your data is stored on servers in Germany
  • End-to-end encryption (E2EE) is available
  • See our detailed Super Sync Privacy Policy for complete information

Third-Party Integrations

Super Productivity can integrate with external services. All integrations are optional and user-initiated:

  • Credentials are stored locally on your device
  • API calls are made directly from your device to the service
  • No data passes through Super Productivity servers

Issue Tracker Privacy Policies

Google Calendar Integration

If you choose to enable the Google Calendar integration, the following applies:

  • OAuth scopes requested:
    • https://www.googleapis.com/auth/calendar.calendars.readonly – reads the list of your Google Calendars (names, IDs, access roles) so you can select which calendar to connect. The calendar list is used in memory only and not stored. The selected calendar ID is saved to app settings, which may be synced via Super Sync with end-to-end encryption.
    • https://www.googleapis.com/auth/calendar.events – creates, updates, and deletes calendar events for time-blocking. Only task data you explicitly schedule is written to Google Calendar. Calendar event data read from Google (including event IDs, titles, descriptions, times, and URLs) is stored locally on your device and may be synced via Super Sync with end-to-end encryption.
  • What data is shared: Task titles, due dates, time estimates, and notes may be sent to Google Calendar to create or update calendar events. When time-blocking is used, an internal task ID is written to the event’s private metadata on Google Calendar. Attendee response status and calendar metadata (names, IDs, access roles) are read for calendar selection and filtering but are never stored.
  • Data flow: All data is sent directly from your device to Google’s servers – no data passes through Super Productivity servers
  • Authentication: Super Productivity uses OAuth 2.0 to connect to your Google account. OAuth tokens are stored locally on your device
  • Data retention: Calendar event data (titles, descriptions, times, IDs, and URLs) is stored locally on your device. If you use Super Sync, this data may be synced to our servers with end-to-end encryption – we cannot read it. OAuth tokens are stored locally until you disconnect the integration, at which point they are deleted immediately
  • Revoking access: You can disconnect Google Calendar at any time in Super Productivity’s settings. You can also revoke access from your Google Account permissions page
  • Google’s policies: See Google’s Privacy Policy and Google API Services User Data Policy

Super Productivity’s use of Google Calendar data is limited to providing the calendar integration feature you enable. We do not use Google Calendar data for advertising, transfer it to third parties, or use it for purposes unrelated to the integration.

Other Services

Data Collection

What the App Does Not Collect

The Super Productivity application does not:

  • Track your usage or behavior
  • Collect analytics or telemetry
  • Use cookies for tracking
  • Share data with advertisers
  • Sell your data to third parties

Providing data is voluntary. The app works fully offline with local storage. You choose whether to enable sync or integrations.

Website Analytics

The Super Productivity website uses self-hosted Matomo Analytics:

  • Host: matamo.super-productivity.com (self-hosted, no third-party access)
  • Cookies: Disabled (cookie-free tracking)
  • IP addresses: Anonymized before processing
  • Data collected: Page views, referral sources, browser type, approximate location (country level)
  • Retention: 26 months

The application itself contains no tracking or analytics.

YouTube Videos

This website embeds YouTube videos using privacy-enhanced mode (youtube-nocookie.com):

  • Videos do not autoplay
  • YouTube only collects data when you actively play a video
  • When playing a video, YouTube may collect: IP address, device information, viewing behavior

By playing an embedded video, you consent to YouTube’s data practices. See Google’s Privacy Policy.

Data Retention

Data TypeRetention Period
Local app dataUntil you delete it
Google Calendar event dataStored locally until you delete it
Google Calendar OAuth tokensUntil you disconnect the integration (deleted immediately)
Super Sync dataUntil account deletion
Website analytics26 months
Contact requests3 years or until resolved

Your Rights (GDPR)

Under the GDPR, you have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase your data (“right to be forgotten”) (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability - receive your data in a portable format (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time, without affecting prior processing (Art. 7(3))

Exercising Your Rights

  • Local data: Use the app’s export and delete features
  • Super Sync: Contact contact@super-productivity.com
  • Third-party services: Contact the respective service (Dropbox, WebDAV provider)

Right to Complain

You have the right to lodge a complaint with a supervisory authority. Our lead authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit Friedrichstraße 219, 10969 Berlin https://www.datenschutz-berlin.de

Data Security

  • All sync connections use TLS/SSL encryption
  • Super Sync offers optional end-to-end encryption
  • Local data is stored using standard browser/OS security mechanisms

Automated Decision-Making

Super Productivity does not use automated decision-making or profiling as defined in Art. 22 GDPR.

International Data Transfers

  • Local storage: No transfers (data stays on your device)
  • Dropbox sync: Dropbox Inc. (USA) - covered by EU-US Data Privacy Framework
  • WebDAV sync: Depends on your chosen server location
  • Super Sync: Servers located in Germany (no international transfer)
  • Google Calendar: Google LLC (USA) - covered by EU-US Data Privacy Framework
  • Issue trackers: Many providers (GitHub, GitLab, Atlassian, Linear, ClickUp) are US-based and covered by EU-US Data Privacy Framework or Standard Contractual Clauses

Children’s Privacy

Super Productivity is not directed at children under 16 (Art. 8 GDPR). We do not knowingly collect data from children.

Changes to This Policy

We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.

Contact

If you have questions about this privacy policy:

Summary

FeatureData LocationYour Control
Default usageLocal device onlyFull control
Dropbox syncYour Dropbox accountYou manage
WebDAV syncYour WebDAV serverYou manage
Super SyncGerman servers (E2EE available)Account deletion available
Google Calendar integrationDirect to GoogleOAuth tokens stored locally, revocable anytime
Issue tracker integrationsDirect to serviceCredentials stored locally