Privacy Policy

Last updated: 14 July 2026

This policy explains what personal data we collect when you use IO Passport (the "Service"), how we use it, who we share it with, and what rights you have. It is written to be readable — where legal jargon is unavoidable, we've tried to say what it means in plain English.

1. Who is the data controller

The data controller is the entity operating IO Passport under the domain iopassport.com and its variants. Contact: hello@attos.one.

2. What we collect

Information you give us directly

  • Account information — your name, email, password (stored as a bcrypt hash — we never see or store your plain password), and optionally your phone number.
  • Profile settings — your timezone, country (if you set one), and email preferences.
  • Content you create — tasks, comments, decisions, lists, and any other content you type into the Service, including anyone you assign a task to.
  • Communications — anything you send us via email, support forms, or chat.

Information collected automatically

  • Timezone — detected from your browser at signup / activation, so we can send scheduled emails at the correct local time. This can be edited or removed from your Settings.
  • Device and browser data — IP address, browser type, operating system, referring URL, and pages viewed. Used for security, debugging, and analytics.
  • Session data — a signed JWT so we know you are logged in.
  • Cookies and similar — see the table below.

3. Cookies, storage, and trackers we set

NameSet byPurposeHow long
app_token IO Passport (localStorage) Keeps you logged in. Signed JWT. Until you sign out or the token expires
app_payload IO Passport (localStorage) Cached user profile used to render the UI without re-fetching. Same as above
iop_theme IO Passport (localStorage) Remembers your light/dark mode preference. Until you clear browser storage
Analytics cookies Third-party analytics vendor (see section 4) Anonymous, aggregated product usage metrics. Up to 24 months (vendor-controlled)

4. Third-party services we use

We rely on the following third parties to operate the Service. Each has their own privacy policy, and using the Service means you accept that we share the specific data listed below with them for the stated purpose.

VendorWhat they doWhat we send themTheir policy
Google Analytics Aggregated product usage analytics — which pages are visited, how features are used. Pseudonymised device / browser data, IP (masked where available), pageviews. No account content. policies.google.com/privacy
Our email vendor (SMTP / Brevo / SES / SendGrid — whichever is configured) Delivers transactional and Daily Rundown emails. Your name, email address, and the email content we are sending. Vendor policy on their website.
Cloud hosting provider Runs the servers and databases the Service uses. All data you enter into the Service (encrypted in transit and at rest where the provider supports it). Provider policy on their website.
Error and crash reporting (if enabled) Alerts us when the Service is broken. Stack traces, URLs, and browser data — configured to strip personal fields where technically possible. Vendor policy on their website.

We do not sell your personal data. We do not run advertising in the Service, and we do not share your data with ad networks.

5. How we use your data

  • To operate the Service you signed up for.
  • To send you the emails described in the Terms of Service.
  • To detect fraud, abuse, and security incidents.
  • To respond to your support requests.
  • To improve the Service — feature usage, error rates, performance.
  • To comply with legal obligations.

6. Legal basis (for users in the EU / UK)

  • Contract — to provide the Service you asked for.
  • Legitimate interests — to keep the Service secure, prevent abuse, and improve it.
  • Consent — for optional analytics and non-essential cookies where required by local law.
  • Legal obligation — where the law requires us to retain or disclose data.

7. How long we keep your data

Account data is kept while your account is active and for a reasonable period after deletion (typically up to 90 days) so accidental deletions can be recovered and backups can roll off. After that we delete or anonymise. We may retain minimal information longer where the law requires it.

8. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data ("right to erasure").
  • Object to certain processing, or restrict it.
  • Export your data in a portable format.
  • Withdraw consent at any time (for anything based on consent).
  • Lodge a complaint with a supervisory authority.

To exercise any of these rights, email hello@attos.one. We respond within 30 days.

9. Children

The Service is not intended for children under 16. Do not create an account for a child. If we find out we hold data on a child under 16, we will delete it.

10. International transfers

Your data may be processed in a country different from the one you live in (typically wherever our hosting provider operates its datacentres). Where transfers are subject to local law (e.g. from the EU / UK), we use appropriate safeguards — for example, Standard Contractual Clauses.

11. Security

We use HTTPS for all traffic, hash passwords with bcrypt, sign session tokens, and follow standard operational security practices. No system is perfectly secure — if you learn of a vulnerability, please email hello@attos.one.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will notify you by email or in-app before they take effect.

← Home Terms of Service →