Privacy Policy
Effective September 14, 2026
This Privacy Policy explains what personal data we collect about you, why, how long we keep it, who we share it with, and the rights you have over it. It applies to our marketing site and to the Tudo Service.
1.Who controls your data
When you visit our marketing site, sign up, or use Tudo for your own personal account, Tudo, Inc. is the controller of your personal data.
When you use Tudo as part of a workspace someone else owns (your employer or a client), the workspace owner is the controller of the data they put into Tudo, and we are their processor. Their privacy notice governs that data; ours covers the account-level information we hold about you directly.
Reach our privacy team at privacy@usetudo.com. Brazilian residents can contact our DPO at the same address.
2.What we collect
We collect three categories of data:
- Account information you give us — name, email, profile picture, language, password hash, and (for paid accounts) billing address and card metadata via Stripe.
- Usage data generated by the Service — pages and features you use, timestamps, IP address, browser, OS. Used for product analytics, security, and debugging.
- Customer Data you put into the Service — board items, comments, files, contacts. We process this only on the workspace owner's instructions.
We do not collect special-category data (health, race, religion, etc.) by design. If you put such data into Customer Data, the workspace owner is responsible for the appropriate legal basis under LGPD / GDPR.
3.Why we process your data (lawful basis)
Under the GDPR (EU/UK), the LGPD (Brazil), and the CCPA/CPRA (California), every processing activity needs a lawful basis. Ours are:
- Performance of contract — to deliver the Service you signed up for (account creation, billing, hosting your data, sending transactional emails like sign-in confirmations or trial reminders).
- Legitimate interests — to keep the Service secure, prevent abuse, improve the product, and run minimal product analytics.
- Consent — for non-essential cookies, marketing communications, and optional integrations.
- Legal obligation — to comply with tax, accounting, anti-fraud, and data-protection laws.
4.How long we keep it
Active accounts: as long as your account is active, plus 30 days after cancellation. During the 30-day grace period you can cancel deletion or download your data.
Inactive marketing-list contacts: 24 months after last engagement, then deleted.
Tax-relevant invoice data: retained for the period required by Brazilian and US tax law (typically 5–7 years), even after account deletion.
Backups: encrypted database backups are kept for 30 days on a rolling basis, then permanently destroyed.
6.Google account data (Gmail and Google Calendar)
Tudo can connect to your Google account so you can work with your existing mail and calendar without leaving Tudo. This only happens if you choose to connect it. Nothing in this section applies to accounts that have never been connected, and disconnecting stops it.
What we access
When you connect a Google account, you are asked to grant these permissions:
- Read your Gmail messages, and change their state (
gmail.modify) — one permission covering everything Tudo’s Inbox does with your mailbox:- read your conversations and their attachments;
- compose and send mail, including replies, scheduled sends and follow-ups, so they leave from your own address rather than ours;
- archive a conversation, and move it back to the inbox;
- mark it read or unread;
- star and unstar it;
- move it to Trash, and restore it.
- View, create, update and delete calendar events (
calendar.events) — so your Google schedule appears beside Tudo’s own events, and so bookings and meetings created in Tudo land on your calendar. - See the list of calendars available to you, read-only (
calendar.calendarlist.readonly) — so you can choose which calendars to connect, and so we can tell which Google account this is. This permission cannot create, delete, share or rename a calendar, and Tudo does not do any of those things: it reads and writes events, and nothing else on your calendars. - Your name, email address and profile picture — to identify the connected account and show you which one is in use.
We do not access Google Drive, Google Contacts, or any other Google service. We do not request permissions beyond the ones listed above.
Snooze and follow-up reminders are Tudo features, not Gmail ones. When you snooze a conversation or set a follow-up, Tudo records that against its own copy of the conversation and brings it back to you at the time you chose. Nothing is sent to Gmail, and the conversation is not moved or changed in your mailbox.
How we use it
Only to operate the features you are using, on your instruction, inside your workspace. We do not use Google data for advertising, for profiling, or to build products unrelated to the feature that fetched it, and we do not sell it.
How we store and protect it
The credential Google issues to Tudo is encrypted at rest using AES-256-GCM. Message and calendar content is stored in our database under row-level access rules that confine it to the workspace it belongs to, and is transmitted over TLS. Access by our staff is limited to what is needed to operate and support the Service, as described in How we secure it below.
Who we share it with
Google data is shared only with the infrastructure providers listed in our Subprocessors page, and only so the Service can run. Two cases are worth naming explicitly:
- Our model provider. If you use a feature that summarises a thread, drafts a reply, or answers a question about your mail or calendar, the relevant content is sent to our model provider to produce that single result. It is processed to answer your request and is not retained for any other purpose.
- Nobody else. We do not transfer Google data to third parties for advertising, resale, credit assessment, or any purpose unrelated to a feature you are using.
Google data is not used to train models
Google user data obtained through these permissions is never used to train, retrain, fine-tune or otherwise improve generalised artificial-intelligence or machine-learning models — neither ours nor a third party’s. Where content is sent to our model provider, it is sent for inference only, under contractual terms that prohibit its use for training.
Disconnecting
You can disconnect a Google account at any time from Tudo’s Inbox or Calendar settings. When you do, we delete our copy of the credential and stop the notification channel that tells us about new mail, and we revoke the credential with Google. Tudo can no longer reach your Google account from that moment.
One detail worth stating plainly: a single Google account can power both your Inbox and your Calendar, and Google issues one credential covering both. If you disconnect only one of the two, we delete that feature’s copy and leave the credential working for the other — revoking it would silently disconnect the feature you kept. Once you disconnect the last of them, the credential is revoked with Google.
You can also revoke Tudo’s access directly from your Google Account at myaccount.google.com/permissions.
What disconnecting does not do: email and calendar entries already synced into your workspace stay there, because they are often part of a business record your team still needs. They are no longer updated, and no new data is fetched.
Deleting the data
To remove the Google-derived content itself, delete it inside Tudo, or ask us at privacy@usetudo.com to delete everything associated with a connected account. Deleting your workspace deletes it along with everything else, on the schedule in How long we keep it above.
Limited Use
Tudo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
7.International transfers
Tudo's primary data hosting is in the United States. When data of EU/UK or Brazilian residents is processed in the US, we rely on the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, and ANPD-recognized safeguards under LGPD Art. 33. Our DPA includes the SCCs by default.
8.Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and personal data ("right to be forgotten").
- Export your data in a portable format (JSON).
- Object to processing based on legitimate interests.
- Withdraw consent at any time, where consent was the basis.
- Lodge a complaint with your local data-protection authority (ANPD in Brazil, your EU Member State authority, the ICO in the UK, your Attorney General in the US).
You can exercise the first four rights from Settings → Profile → Your data right inside Tudo. For everything else, email privacy@usetudo.com — we respond within 15 days, and at most 30 days as allowed by LGPD.
9.How we secure it
Data in transit is encrypted with TLS 1.2+. Data at rest is encrypted at the database and storage layers. Passwords are stored as Argon2 hashes — we never see them.
Access to production systems is restricted to a small number of named personnel under least-privilege controls and is logged. We run a security disclosure program at security@usetudo.com.
Our SOC 2 Type I audit is in progress; ISO 27001 is on the roadmap. The current status is published on the Trust Center.
11.Children
Tudo is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has signed up, write to privacy@usetudo.com and we will delete the account.
12.Changes to this policy
We may update this Privacy Policy from time to time. Material changes are announced by email to workspace owners at least 30 days before they take effect. The "Effective" date at the top of this page always reflects the current version.