Who is responsible
Ishu is the data controller for information handled by the Ishu website, Android app, and API. For privacy questions, access requests, or deletion help, contact privacy@ishu.app.
Information we collect
Website waitlist
If you join the waitlist, we collect your email address, consent, confirmation status, and limited campaign attribution such as source and creative. We also count page visits and signup/confirmation events. We do not use advertising cookies or sell this data.
Google identity
The Android app requires Google sign-in. We receive a stable Google account identifier
(sub) and verified email address to create your Ishu account and keep tasks
synchronized across your devices. The Google identity token is verified at sign-in and
is not stored as your account identifier.
Tasks and scheduling
We store the tasks, task fields, completion and deletion records, scheduling preferences, generated placements, synchronization versions, and activity history you create in Ishu. The Ishu backend is the canonical task store; your Android device keeps an offline replica and a queue of pending changes.
Optional Google Calendar connection
Calendar access is requested separately and is optional. If you connect it, Ishu stores an encrypted Google refresh token, granted scopes, opaque calendar identifiers, and your busy-calendar selections. Ishu receives time intervals showing when selected calendars are busy. It does not collect external event titles, descriptions, locations, or attendees.
Ishu creates one secondary calendar named Ishu Tasks and writes your Ishu task title and scheduled time into events on that calendar. Editing those events in Google Calendar does not edit the underlying Ishu task.
Voice features
Speech recognition runs on your device when the device supports it. The resulting text transcript—not microphone audio—may be sent to Ishu's API. To interpret a request, the API may send the transcript, today's Ishu task titles, and anonymous busy intervals to OpenAI as a service provider. This information is used to return the feature you asked for, not for advertising or training a personalized AI model. A deterministic scheduler, not an AI model, chooses task time slots.
Technical and security records
We process device/session identifiers, hashed Ishu refresh tokens, request counts, and operational error information needed to authenticate requests, prevent abuse, diagnose failures, and keep the service reliable. Logs must not contain identity tokens, authorization codes, refresh tokens, task titles, voice transcripts, or Calendar metadata.
How we use information
- Authenticate your Ishu account and synchronize tasks across your devices.
- Keep offline changes safe until your device reconnects.
- Show Calendar availability without collecting meeting details.
- Create and reconcile events in your dedicated Ishu Tasks calendar.
- Generate deterministic schedules, explain overflow, and support review and undo.
- Provide voice interpretation when you choose a premium voice action.
- Send the waitlist confirmation and launch notification you requested.
- Protect accounts, rate-limit abuse, operate the service, and comply with law.
Google user data
Ishu's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Ishu requests only these Google permissions:
openid email profilefor identity and verified email.-
calendar.app.createdto create and maintain the Ishu Tasks calendar and its events. -
calendar.events.freebusyto see availability as anonymous time blocks. -
calendar.calendarlist.readonlyto let you select which Google calendars count as busy.
Google user data is used only for the user-facing identity, availability, scheduling, and Calendar-projection features described here. It is not sold, used for advertising, used to determine creditworthiness, or used to train generalized or personalized AI models.
Service providers and disclosure
We disclose only the information necessary for providers to operate Ishu: Google for identity and Calendar authorization, hosting/database/key-management providers for the API and encrypted storage, OpenAI for requested voice interpretation, and an email delivery provider for waitlist messages. Providers act under their own legal and security obligations. We may also disclose information when required by law or to protect users and the service. We do not sell or rent personal information.
Security
Connections use HTTPS. Ishu device refresh tokens are stored only as hashes and rotate after use. Google refresh tokens are envelope-encrypted with a unique data key protected by managed key management. Access is limited to the service components that need it. No internet service can guarantee absolute security, but Ishu is designed to minimize the data and credentials retained.
Retention
- Account and task data remain until you delete the account, subject to legal needs.
- Google authorization remains until you disconnect Calendar or delete the account.
- Deletion tombstones are retained long enough to stop stale offline resurrection.
- Waitlist data remains until launch notification, unsubscribe, or deletion request.
- Encrypted backups containing deleted data expire within no more than 30 days.
Your controls
- Export: use Export account data in Ishu Settings.
- Disconnect Calendar: removes the Ishu Tasks calendar, revokes Google authorization, and deletes the stored Google credential without deleting Ishu tasks.
- Log out: ends the current device session.
- Log out everywhere: ends every Ishu session without disconnecting Calendar.
- Delete account: revokes Google access and deletes Ishu sessions and user data, subject to the backup period above.
- Waitlist: use the one-click unsubscribe link in either email.
You may also revoke Ishu from your Google Account's third-party connections. For access, correction, deletion, objection, or portability requests, email privacy@ishu.app.
Changes to this policy
We will update the date above when this policy changes. Material changes to Google user data access or use will be reflected here and in the app before the changed practice is introduced.