Who we are
SimpleWeek ("we", "us") is a weekly task board available at https://simpleweek.com. The service is run by Maks Rafalko, who is also the data controller for everything described below.
For anything to do with privacy, write to maks.rafalko@gmail.com. We answer every message.
What we collect
We only collect what the board needs in order to work. There are three kinds of data.
Your account
Your email address, your chosen username, a one-way hash of your password (we never store or see the password itself), your timezone and your interface language. You give us these when you register; the timezone and language are what place your tasks on the right day and render the interface.
What you put on the board
Your tasks, their text and checklists, the columns and boards you arrange them in, the dates and times you set, and any images you attach to a task. This is your content. We store it so we can show it back to you, and for no other purpose.
Technical data
Your IP address, browser and device type, and the pages you open. The IP address is also used once, at your first visit, to guess which of the three interface languages to show you. Server logs holding this data are kept for 30 days and then deleted.
Google Calendar
Connecting Google Calendar is optional. SimpleWeek works fully without it, and nothing below happens until you click through Google's consent screen yourself.
When you do connect it, SimpleWeek asks Google for the
https://www.googleapis.com/auth/calendar scope, and stores the access and refresh
tokens Google issues. The tokens live in our database, alongside your account, and are used
for one thing only: keeping your calendar in step with your board.
What SimpleWeek does with your calendar
- Creates an event on your primary calendar when you give a SimpleWeek task a date and a time.
- Updates that event when you change the task's text, date or time.
- Deletes that event when you delete the task or clear its time.
What SimpleWeek never does
- It does not read the events already in your calendar, and does not copy them into SimpleWeek.
- It does not store any calendar data on our servers. The event lives in your Google Calendar; all we keep is the identifier of the event we created, so we can update or remove it later.
- It does not touch any calendar other than your primary one.
- It does not use your Google data for advertising, profiling, or training any model, and never sells or transfers it. Human beings do not read it.
Limited Use
SimpleWeek's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting
You can cut SimpleWeek off from your calendar at any moment, from your Google account's permissions page. When you do, we delete the stored tokens the next time the connection is used. Events that SimpleWeek already created stay in your calendar, and are yours to keep or delete.
Why we use your data
- To run the board: sign you in, show your tasks, and put them on the right day in your timezone.
- To mirror your dated tasks into Google Calendar, if you have connected it.
- To send you the account email you asked for — registration confirmation, password resets, and the daily reminder of what is due. Every reminder carries a one-click unsubscribe link, and you can turn all email off from your settings.
- To understand which pages are used and to keep the service working and secure.
We do not sell your data. We do not share it with advertisers. We do not use the contents of your tasks for anything other than showing them to you.
Who else sees it
A small number of services process data on our behalf, each for one narrow purpose.
- Google Calendar API — only if you connect it, and only as described above.
- Mailgun — delivers our email. It receives your email address and the message body.
- Google Analytics — counts page views on the public pages. It sees a truncated IP address and browsing behaviour, not your tasks.
- UserReport — the feedback widget inside the app.
- Google Fonts — serves the typeface, and in doing so sees your IP address.
- Our hosting provider — stores the database and the server logs.
Beyond these, we disclose data only where the law requires it.
Cookies
SimpleWeek sets a session cookie to keep you signed in, and a cookie that remembers your language and whether you chose the light or dark theme. Google Analytics sets its own cookies on the public pages. There are no advertising cookies, and nobody tracks you across other sites.
Keeping and deleting your data
We keep your account and your board for as long as your account exists. Server logs are deleted after 30 days.
Ask us to delete your account — one email to maks.rafalko@gmail.com is enough — and we erase your account, your tasks, your uploaded images and your stored Google tokens within 30 days. It does not go to an archive. It is gone.
Your rights
You can ask us for a copy of everything we hold about you, ask us to correct it, or ask us to delete it. Write to maks.rafalko@gmail.com and we will respond within 30 days. If you are in the EU or the UK, you also have the right to complain to your data protection authority.
Security
The site is served over HTTPS. Passwords are stored as salted one-way hashes, so a copy of the database would not reveal them. Google tokens are stored on the same protected server and are never sent to the browser. No system is perfect, and we will tell affected users promptly if anything ever goes wrong.
Children
SimpleWeek is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has registered, tell us and we will remove the account.
Changes to this policy
If we change how we handle your data, we will update this page and move the date at the top. Anything that materially affects you, we will also send by email.
Contact
Questions, requests, or complaints: maks.rafalko@gmail.com.