Privacy Policy

Last updated: July 20, 2026

Spliq (“Spliq,” “we,” “us,” or “our”) provides a task management application available at https://spliq.org (the “Service”). This Privacy Policy explains how we handle information when you use the Service, with particular attention to how we access and use data from your Google/Gmail account.

By using the Service, you agree to the collection and use of information as described in this Privacy Policy.

1. Who We Are

Spliq is operated as an individual/independent project. For any questions about this Privacy Policy or your data, contact:

2. Architecture — Gmail Data Is Processed Only on the Client Side

Spliq uses a backend server (hosted on our own infrastructure) to support core app functionality unrelated to Gmail, such as user accounts, authentication/authorization, storage of your projects and tasks, and aggregate usage analytics. However, all interaction with the Gmail API happens exclusively on the client side, in your web browser — this is a deliberate architectural choice that limits our access to your email data:

  • Google OAuth authorization for Gmail access is performed entirely in your browser. Your Gmail OAuth access/refresh tokens are obtained and used directly by your browser and never transmitted to, processed by, or stored on our backend server.
  • All reading, sending, and management of your emails (archiving, deleting, labeling, etc.) is performed by your browser making direct calls to Google’s Gmail API. This traffic goes directly between your browser and Google — it does not pass through our servers.
  • Because our backend never receives your Gmail OAuth token or your raw email content, it has no technical ability to access, store, or process your Gmail data.

Our backend does store the following, separate from any Gmail data:

  • Your Spliq account information (e.g., name, email address used for login, authentication credentials);
  • Projects and tasks you create within the app (task titles, descriptions, statuses, due dates, etc.) — this is task data you or the app has created, not the underlying raw email content;
  • Aggregate, non-content usage analytics to help us understand how the app is used and improve it.

See Section 3 below for more detail on what is, and is not, sent to our backend.

3. Information We Access

3.1 Google Account / Gmail Data

To provide task-management features, Spliq requests access to your Gmail account via Google’s OAuth 2.0 authorization flow, using the following scope: [https://mail.google.com/](https://mail.google.com/) (full Gmail access)

This scope allows the Service, running locally in your browser, to:

  • Read your emails (e.g., to let you create tasks from messages, view message content, and extract relevant details such as sender, subject, and body);
  • Send emails on your behalf (e.g., replying to a message or sending a message related to a task), only when you explicitly initiate that action;
  • Manage your emails and mailbox, including archiving, deleting, labeling, and organizing messages, only when you explicitly initiate that action within the app.

We only request this level of access because it is required for the core task-management functionality of the app (turning emails into actionable tasks, and letting you act on those tasks — such as replying to or archiving the related email — without leaving the app).

Spliq does not:

  • Sell, rent, or trade your Gmail data;
  • Use your Gmail data for advertising or ad-targeting purposes;
  • Use your Gmail data to train generative AI/ML models;
  • Allow humans to read your email data, except in the limited circumstances described in Section 6 (e.g., with your consent, for security purposes, or to comply with the law).
3.2 Google Account Basic Profile Information

We may access basic profile information (such as your name, email address, and profile picture) via Google Sign-In, used solely to identify you within the app and personalize the interface.

3.3 Data Kept Only in Your Browser (Not Sent to Our Backend)
  • Gmail OAuth tokens are obtained and used entirely client-side. They are held only in your browser’s session memory for the duration of your active session and are not persisted between browser visits/restarts, and are never transmitted to or stored on our backend server. When you close your browser or your session ends, these tokens are cleared.
  • Raw Gmail content (the full text/contents of your emails) is read directly from Google’s API into your browser to render the app interface and is not sent to, or retained by, our backend.
3.4 Data Stored on Our Backend

Separately from the Gmail-related data described above, our backend server (hosted on our own infrastructure) stores:

  • Account data: information needed to create and authenticate your Spliq account (e.g., name, login email address, hashed credentials or authentication identifiers);
  • Projects and tasks: the projects and tasks you create in the app — including any titles, notes, or descriptions you or the app generates (for example, a task title derived from an email subject) — so that your task data persists across sessions and devices;
  • Usage analytics: aggregate, non-content data about how the app is used (e.g., feature usage counts, session activity) to help us maintain and improve the Service.

Task data stored on our backend may reference or be derived from an email (e.g., a task title taken from an email subject line), but the underlying raw email content and your Gmail OAuth tokens are not sent to or stored on our backend — Gmail data handling remains confined to your browser and Google’s own servers, as described in Section 2 and 3.1–3.3.

You can request deletion of your account and associated backend-stored data (account, projects, tasks) at any time by contacting us at supp.spliq@gmail.com, or via any in-app account-deletion option if available.

4. How We Use Information

Gmail data (processed entirely client-side) is used only to:

  • Display your emails and derived tasks to you within the app interface;
  • Allow you to create, edit, complete, and organize tasks based on your emails;
  • Allow you to send, reply to, archive, delete, or label emails directly from the app, at your explicit direction.

Account, project, task, and analytics data stored on our backend is used only to:

  • Create and authenticate your Spliq account, and keep you logged in;
  • Persist your projects and tasks across sessions and devices;
  • Understand aggregate usage patterns so we can maintain, secure, and improve the Service.

We do not use your data for any purpose beyond providing and improving the features described above.

5. Google API Services User Data Policy

Spliq’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • We only use Gmail data to provide or improve user-facing features that are prominent in the app’s interface (task creation, email management).
  • We do not transfer Gmail data to third parties, except as necessary to provide the app’s core functionality, to comply with applicable law, or as part of a merger/acquisition (with prior notice).
  • We do not use Gmail data for serving advertisements.
  • We do not allow humans to read Gmail data unless: (a) we have your affirmative agreement for specific messages; (b) it is necessary for security purposes (e.g., investigating abuse); (c) it is required to comply with applicable law; or (d) the data has been aggregated and anonymized.

6. Data Sharing and Disclosure

We do not sell your personal data. Your Gmail data is never received by our backend and therefore is never available for us to share (see Section 2–3). Account, project, task, and analytics data stored on our backend is not shared with third parties, except in the following limited cases:

  • With your direction — actions you explicitly take in the app involving Gmail (e.g., sending an email) go directly from your browser to Google’s servers, not through us.
  • Service providers — we may use infrastructure/hosting providers strictly to operate our own server (e.g., our VPS provider), who process data only on our behalf and under confidentiality obligations, and who do not have access to your Gmail data.
  • Legal requirements — if required to comply with a legal obligation, court order, or governmental request.
  • Security and abuse prevention — if necessary to investigate or prevent fraudulent, unauthorized, or illegal activity.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice to you.

We do not use any third-party analytics, advertising, or error-tracking services — usage analytics are collected and processed on our own backend infrastructure.

7. Data Retention and Deletion

  • Gmail OAuth tokens: exist only in your browser’s session memory and are cleared automatically when your browser session ends. They are never stored on our backend.
  • Account, project, task, and analytics data: retained on our backend server for as long as your account remains active, so that your projects and tasks persist across sessions and devices. You may request deletion of your account and all associated backend data at any time by contacting us at supp.spliq@gmail.com, or via an in-app account-deletion option if available. We will delete this data within a reasonable period, except where retention is required to comply with a legal obligation.
  • Revoking Gmail access: You may revoke Spliq’s access to your Google account at any time via your Google Account security settings. Revoking access immediately stops any further access to your Gmail data, independent of your Spliq account status.

Since your Gmail data never reaches our backend, deleting your Spliq account and/or revoking OAuth access together remove all traces of your data from, and access via, the Service.

8. Data Security

We take the following measures to protect your data:

  • All communication with Google’s APIs occurs directly from your browser over HTTPS/TLS encryption, without passing through our backend.
  • Gmail OAuth tokens are handled using Google’s standard OAuth 2.0 flow, are never transmitted to or stored on our backend, and are not persisted beyond your active browser session.
  • Our backend server (hosted on our own infrastructure) uses HTTPS/TLS for all traffic, and access to account/task data is restricted and authenticated.
  • The Service is served exclusively over HTTPS at https://spliq.org.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. However, since your Gmail data never passes through or resides on our backend, your exposure to a server-side breach affecting your Gmail data is minimized by design — a compromise of our backend would not expose your emails or Gmail OAuth tokens.

9. Your Rights (GDPR / EU Users)

As Spliq operates without a backend and does not retain your data, most of your data remains under your own control (in your browser and in your Google account). Nonetheless, to the extent applicable under the EU General Data Protection Regulation (GDPR), you have the right to:

  • Access — request information about what data, if any, is processed;
  • Rectification — correct inaccurate data;
  • Erasure — request deletion of any data (noting most data lives locally on your device or in your Google account, which you control directly);
  • Restriction/Objection — object to or restrict certain processing;
  • Data portability — receive your data in a portable format;
  • Withdraw consent — revoke Spliq’s Google API access at any time via your Google Account permissions.

To exercise these rights, contact us at supp.spliq@gmail.com. You also have the right to lodge a complaint with your local data protection authority.

10. International Data Transfers

Because processing occurs locally in your browser and directly against Google’s APIs, we do not ourselves transfer your data internationally. Any data transfer between your browser and Google occurs under Google’s own privacy and security practices.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by an updated “Last updated” date at the top of this page. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

12. Contact Us

If you have questions about this Privacy Policy or how Spliq handles your data, contact us at: