# GoingsOn Privacy Policy *Last updated: June 14, 2026* GoingsOn is published by Make Creative, LLC. This policy explains what data the app handles, where it goes, and what it does not do. ## Summary - GoingsOn is a local-first app. Your tasks, projects, notes, calendar events, contacts, and email all live in a database on your own device. - We do not run a server that receives your content. We do not see your data. - Email message contents never leave your device except to talk directly to your own mail provider. They are not included in cloud sync. - Cloud sync is optional and off by default. When enabled, your data is end-to-end encrypted before it leaves the device, so the sync server cannot read it. - No telemetry, analytics, ads, or tracking. ## What GoingsOn Stores on Your Device Everything below is kept in app storage on your device (on Apple platforms, the app's container): - Tasks, projects, subtasks, milestones, annotations, and notes - Calendar events and time-tracking sessions - Contacts and their details (emails, phone numbers, social handles) - Cached email message bodies and metadata for accounts you add - File attachments - Local backups the app takes automatically - Plugin scripts you install Email account credentials (IMAP/SMTP app passwords and any OAuth tokens) are stored in the operating system's secure keychain (Apple Keychain, Windows Credential Manager, or the Linux Secret Service), never in the app database or in plain files. This data stays on your device unless you choose to sync it. ## What GoingsOn Sends Off Your Device GoingsOn connects only to services that you configure: - **Your email servers (IMAP/SMTP/JMAP).** When you add an account (Google, Microsoft, Fastmail, or any other host), the app connects straight to that provider to send and receive your mail. We do not proxy or relay these connections. - **OAuth providers.** When third-party OAuth sign-in is offered in a future update, authenticating an email account will exchange tokens directly with that provider under its own privacy policy. At launch, email accounts connect via IMAP/SMTP app passwords only. - **Update server.** The app checks for new versions. The check sends only your current app version, platform, and CPU architecture. No personal data. - **Cloud sync (optional, off by default).** If you turn it on, the app syncs to a sync server using end-to-end encrypted payloads. By default this is Make Creative's server at makenot.work. ## Cloud Sync Details If you enable sync: - **What syncs:** tasks, projects, events, contacts, attachments, and related app data, as end-to-end encrypted change records and encrypted file blobs. - **What does not sync:** your email message contents, and your email or sync credentials. These stay on your device. - **Encryption:** data is encrypted on your device with a key stored in your OS keychain. That key is never sent to the server, so the server operator cannot read your synced data. - **Payments:** sync is a paid subscription. Payment is processed by Stripe through makenot.work; GoingsOn only checks whether your subscription is active. We never see or store your card details. ## What GoingsOn Does Not Do - No analytics SDK, no crash-reporter beacons, no usage tracking - No advertising, no third-party trackers - No location collection - No selling or sharing of your data with third parties ## Your Data and Your Control - Your data is yours and lives on your device. You can export it at any time. - Deleting the app removes its local database and stored content from that device. - To stop syncing, turn sync off in Settings. To remove synced data from the server, contact us at info@makenot.work. ## Children GoingsOn is not directed at children under 13, and we do not knowingly collect data from them. ## Changes Material changes to this policy will be noted in the app's release notes and reflected in the date above. ## Contact info@makenot.work