Plain-language policy

Privacy Policy

Ishu is a personal task and scheduling assistant. This policy explains what the website and Android app collect, why it is needed, and the controls available to you.

Effective and last updated: 6 September 2026

Who is responsible

Ishu is the data controller for information handled by the Ishu website, Android app, and API. For privacy questions, access requests, or deletion help, contact privacy@ishu.app.

Information we collect

Website waitlist

If you join the waitlist, we collect your email address, consent, confirmation status, and limited campaign attribution such as source and creative. We also count page visits and signup/confirmation events. We do not use advertising cookies or sell this data.

Google identity

The Android app requires Google sign-in. We receive a stable Google account identifier (sub) and verified email address to create your Ishu account and keep tasks synchronized across your devices. The Google identity token is verified at sign-in and is not stored as your account identifier.

Tasks and scheduling

We store the tasks, task fields, completion and deletion records, scheduling preferences, generated placements, synchronization versions, and activity history you create in Ishu. The Ishu backend is the canonical task store; your Android device keeps an offline replica and a queue of pending changes.

Optional Google Calendar connection

Calendar access is requested separately and is optional. If you connect it, Ishu stores an encrypted Google refresh token, granted scopes, opaque calendar identifiers, and your busy-calendar selections. Ishu receives time intervals showing when selected calendars are busy. It does not collect external event titles, descriptions, locations, or attendees.

Ishu creates one secondary calendar named Ishu Tasks and writes your Ishu task title and scheduled time into events on that calendar. Editing those events in Google Calendar does not edit the underlying Ishu task.

Voice features

Speech recognition runs on your device when the device supports it. The resulting text transcript—not microphone audio—may be sent to Ishu's API. To interpret a request, the API may send the transcript, today's Ishu task titles, and anonymous busy intervals to OpenAI as a service provider. This information is used to return the feature you asked for, not for advertising or training a personalized AI model. A deterministic scheduler, not an AI model, chooses task time slots.

Technical and security records

We process device/session identifiers, hashed Ishu refresh tokens, request counts, and operational error information needed to authenticate requests, prevent abuse, diagnose failures, and keep the service reliable. Logs must not contain identity tokens, authorization codes, refresh tokens, task titles, voice transcripts, or Calendar metadata.

How we use information

  • Authenticate your Ishu account and synchronize tasks across your devices.
  • Keep offline changes safe until your device reconnects.
  • Show Calendar availability without collecting meeting details.
  • Create and reconcile events in your dedicated Ishu Tasks calendar.
  • Generate deterministic schedules, explain overflow, and support review and undo.
  • Provide voice interpretation when you choose a premium voice action.
  • Send the waitlist confirmation and launch notification you requested.
  • Protect accounts, rate-limit abuse, operate the service, and comply with law.

Google user data

Ishu's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Ishu requests only these Google permissions:

  • openid email profile for identity and verified email.
  • calendar.app.created to create and maintain the Ishu Tasks calendar and its events.
  • calendar.events.freebusy to see availability as anonymous time blocks.
  • calendar.calendarlist.readonly to let you select which Google calendars count as busy.

Google user data is used only for the user-facing identity, availability, scheduling, and Calendar-projection features described here. It is not sold, used for advertising, used to determine creditworthiness, or used to train generalized or personalized AI models.

Service providers and disclosure

We disclose only the information necessary for providers to operate Ishu: Google for identity and Calendar authorization, hosting/database/key-management providers for the API and encrypted storage, OpenAI for requested voice interpretation, and an email delivery provider for waitlist messages. Providers act under their own legal and security obligations. We may also disclose information when required by law or to protect users and the service. We do not sell or rent personal information.

Security

Connections use HTTPS. Ishu device refresh tokens are stored only as hashes and rotate after use. Google refresh tokens are envelope-encrypted with a unique data key protected by managed key management. Access is limited to the service components that need it. No internet service can guarantee absolute security, but Ishu is designed to minimize the data and credentials retained.

Retention

  • Account and task data remain until you delete the account, subject to legal needs.
  • Google authorization remains until you disconnect Calendar or delete the account.
  • Deletion tombstones are retained long enough to stop stale offline resurrection.
  • Waitlist data remains until launch notification, unsubscribe, or deletion request.
  • Encrypted backups containing deleted data expire within no more than 30 days.

Your controls

  • Export: use Export account data in Ishu Settings.
  • Disconnect Calendar: removes the Ishu Tasks calendar, revokes Google authorization, and deletes the stored Google credential without deleting Ishu tasks.
  • Log out: ends the current device session.
  • Log out everywhere: ends every Ishu session without disconnecting Calendar.
  • Delete account: revokes Google access and deletes Ishu sessions and user data, subject to the backup period above.
  • Waitlist: use the one-click unsubscribe link in either email.

You may also revoke Ishu from your Google Account's third-party connections. For access, correction, deletion, objection, or portability requests, email privacy@ishu.app.

Changes to this policy

We will update the date above when this policy changes. Material changes to Google user data access or use will be reflected here and in the app before the changed practice is introduced.