Privacy Policy – Super Productivity
Last updated: April 2, 2026
Overview
Super Productivity is designed with privacy as a core principle. All your data is stored locally on your device by default. Data is only transferred to external services when you explicitly enable synchronization features.
Data Controller
Responsible for data processing (Art. 4(7) GDPR):
Johannes Millan Hauptstraße 4H 10407 Berlin, Germany Email: contact@super-productivity.com
For full legal notice, see our Imprint.
Legal Basis for Processing
We process personal data only when we have a lawful basis under Art. 6(1) GDPR:
| Processing Activity | Legal Basis |
|---|---|
| Local data storage | No processing by us (data stays on your device) |
| Sync services (when enabled) | Art. 6(1)(b) - Contract performance |
| Issue tracker integrations (when enabled) | Art. 6(1)(b) - Contract performance |
| Google Calendar integration (when enabled) | Art. 6(1)(b) - Contract performance |
| Website analytics | Art. 6(1)(f) - Legitimate interest in improving our website |
| YouTube videos (when played) | Art. 6(1)(a) - Consent (by choosing to play) |
| Contact requests | Art. 6(1)(b) - Pre-contractual measures |
Data Storage
Local Storage (Default)
By default, Super Productivity stores all your data locally:
- Desktop (Windows, macOS, Linux): Data is stored in your user data folder using IndexedDB and Backups are stored in SQLite files.
- Web App: Data is stored in your browser’s IndexedDB
- Mobile (Android): Data is stored in the app’s local storage
No data is transmitted to any server unless you explicitly enable a sync or integration feature.
Optional Synchronization
If you choose to enable synchronization, your data will be transferred to the service you select:
Dropbox Sync
- Your task data is stored in your personal Dropbox account
- Super Productivity uses Dropbox’s official API
- See Dropbox’s Privacy Policy
WebDAV Sync
- Your task data is stored on your chosen WebDAV server
- You control where your data is stored
- No data passes through Super Productivity servers
Super Sync (Optional Paid Service)
- If you use Super Sync, your data is stored on servers in Germany
- End-to-end encryption (E2EE) is available
- See our detailed Super Sync Privacy Policy for complete information
Third-Party Integrations
Super Productivity can integrate with external services. All integrations are optional and user-initiated:
- Credentials are stored locally on your device
- API calls are made directly from your device to the service
- No data passes through Super Productivity servers
Issue Tracker Privacy Policies
- Jira (Atlassian)
- GitHub
- GitLab
- OpenProject
- Gitea
- Redmine
- Trello (Atlassian)
- Linear
- ClickUp
- CalDAV/iCal: Privacy policy depends on your chosen provider
Google Calendar Integration
If you choose to enable the Google Calendar integration, the following applies:
- OAuth scopes requested:
https://www.googleapis.com/auth/calendar.calendars.readonly– reads the list of your Google Calendars (names, IDs, access roles) so you can select which calendar to connect. The calendar list is used in memory only and not stored. The selected calendar ID is saved to app settings, which may be synced via Super Sync with end-to-end encryption.https://www.googleapis.com/auth/calendar.events– creates, updates, and deletes calendar events for time-blocking. Only task data you explicitly schedule is written to Google Calendar. Calendar event data read from Google (including event IDs, titles, descriptions, times, and URLs) is stored locally on your device and may be synced via Super Sync with end-to-end encryption.
- What data is shared: Task titles, due dates, time estimates, and notes may be sent to Google Calendar to create or update calendar events. When time-blocking is used, an internal task ID is written to the event’s private metadata on Google Calendar. Attendee response status and calendar metadata (names, IDs, access roles) are read for calendar selection and filtering but are never stored.
- Data flow: All data is sent directly from your device to Google’s servers – no data passes through Super Productivity servers
- Authentication: Super Productivity uses OAuth 2.0 to connect to your Google account. OAuth tokens are stored locally on your device
- Data retention: Calendar event data (titles, descriptions, times, IDs, and URLs) is stored locally on your device. If you use Super Sync, this data may be synced to our servers with end-to-end encryption – we cannot read it. OAuth tokens are stored locally until you disconnect the integration, at which point they are deleted immediately
- Revoking access: You can disconnect Google Calendar at any time in Super Productivity’s settings. You can also revoke access from your Google Account permissions page
- Google’s policies: See Google’s Privacy Policy and Google API Services User Data Policy
Super Productivity’s use of Google Calendar data is limited to providing the calendar integration feature you enable. We do not use Google Calendar data for advertising, transfer it to third parties, or use it for purposes unrelated to the integration.
Other Services
- Unsplash (background images)
Data Collection
What the App Does Not Collect
The Super Productivity application does not:
- Track your usage or behavior
- Collect analytics or telemetry
- Use cookies for tracking
- Share data with advertisers
- Sell your data to third parties
Providing data is voluntary. The app works fully offline with local storage. You choose whether to enable sync or integrations.
Website Analytics
The Super Productivity website uses self-hosted Matomo Analytics:
- Host: matamo.super-productivity.com (self-hosted, no third-party access)
- Cookies: Disabled (cookie-free tracking)
- IP addresses: Anonymized before processing
- Data collected: Page views, referral sources, browser type, approximate location (country level)
- Retention: 26 months
The application itself contains no tracking or analytics.
YouTube Videos
This website embeds YouTube videos using privacy-enhanced mode (youtube-nocookie.com):
- Videos do not autoplay
- YouTube only collects data when you actively play a video
- When playing a video, YouTube may collect: IP address, device information, viewing behavior
By playing an embedded video, you consent to YouTube’s data practices. See Google’s Privacy Policy.
Data Retention
| Data Type | Retention Period |
|---|---|
| Local app data | Until you delete it |
| Google Calendar event data | Stored locally until you delete it |
| Google Calendar OAuth tokens | Until you disconnect the integration (deleted immediately) |
| Super Sync data | Until account deletion |
| Website analytics | 26 months |
| Contact requests | 3 years or until resolved |
Your Rights (GDPR)
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (“right to be forgotten”) (Art. 17)
- Restrict processing (Art. 18)
- Data portability - receive your data in a portable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time, without affecting prior processing (Art. 7(3))
Exercising Your Rights
- Local data: Use the app’s export and delete features
- Super Sync: Contact contact@super-productivity.com
- Third-party services: Contact the respective service (Dropbox, WebDAV provider)
Right to Complain
You have the right to lodge a complaint with a supervisory authority. Our lead authority is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit Friedrichstraße 219, 10969 Berlin https://www.datenschutz-berlin.de
Data Security
- All sync connections use TLS/SSL encryption
- Super Sync offers optional end-to-end encryption
- Local data is stored using standard browser/OS security mechanisms
Automated Decision-Making
Super Productivity does not use automated decision-making or profiling as defined in Art. 22 GDPR.
International Data Transfers
- Local storage: No transfers (data stays on your device)
- Dropbox sync: Dropbox Inc. (USA) - covered by EU-US Data Privacy Framework
- WebDAV sync: Depends on your chosen server location
- Super Sync: Servers located in Germany (no international transfer)
- Google Calendar: Google LLC (USA) - covered by EU-US Data Privacy Framework
- Issue trackers: Many providers (GitHub, GitLab, Atlassian, Linear, ClickUp) are US-based and covered by EU-US Data Privacy Framework or Standard Contractual Clauses
Children’s Privacy
Super Productivity is not directed at children under 16 (Art. 8 GDPR). We do not knowingly collect data from children.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.
Contact
If you have questions about this privacy policy:
Summary
| Feature | Data Location | Your Control |
|---|---|---|
| Default usage | Local device only | Full control |
| Dropbox sync | Your Dropbox account | You manage |
| WebDAV sync | Your WebDAV server | You manage |
| Super Sync | German servers (E2EE available) | Account deletion available |
| Google Calendar integration | Direct to Google | OAuth tokens stored locally, revocable anytime |
| Issue tracker integrations | Direct to service | Credentials stored locally |