MooseDoList Sign in

Legal

Privacy

Last updated: 6 October 2026

MooseDoList is a to-do list run by Moose Ltd. This page explains what it keeps about you, where it lives and why. It keeps only what it needs to work, and you can delete all of it whenever you like.

The short version

  • We know your email address and the list you keep here. Nothing else from your Google account.
  • No analytics, no ads, no third-party trackers. One cookie, to keep you signed in.
  • Passkey protection encrypts your task names so only you can read them.
  • We never sell your data or use it for ads. Delete your account in Profile and it's gone at once.

What we collect

  • Your email address. You sign in with Google, and we ask Google for your email address and nothing more. We don't get your name, photo, contacts or anything else in your Google account, and we never see your Google password.
  • Your list. Your tasks and ideas, with their schedules, due dates and times, priorities and whether they're paused, plus a record of each one you complete and on which day.
  • Task history. What happened to each task and when (created, renamed, moved, completed and so on), so you can see it in the task's details. A rename keeps the old name.
  • Your settings. Your timezone, how much confetti you like, and whether you've been through the welcome screen.
  • Sign-in sessions. One record for each browser you're signed in on: a scrambled (hashed) copy of its session token and when it expires.
  • Passkey protection keys, if you turn it on. Copies of your encryption key, each locked with one of your passkeys or your recovery code, and the ID of each passkey. We can't unlock any of them.

Like any website, MooseDoList also passes through technical systems that see your IP address and basic details of each request, such as the address asked for and the time. Our hosting provider uses these to deliver and protect the service, and we keep short-lived logs of them to fix problems.

On your device

So the app keeps working offline, your browser holds changes that haven't reached us yet and a copy of your settings. With passkey protection on, it also keeps your unlocked key, stored so that page code can use it but can't read it out. Signing out removes the key from that browser.

Passkey protection (end-to-end encryption)

Passkey protection is optional. When it's on, your browser encrypts the name of every task and idea, including the names kept in your completions and history, with a key that only you hold. You unlock it with a passkey (Face ID, Touch ID or Windows Hello) or your recovery code. We only ever store the encrypted text, so we can't read your task names, and neither can anyone who gets hold of our database.

Some things stay readable to our server so the app can work: your email address, dates and times, schedules, priorities, which tasks are done and how many, the kinds of change in your history, and your settings.

If you lose every passkey and your recovery code, nobody can recover your task names, including us. With protection off, task names are stored as plain text that our server can read.

Where your data lives

MooseDoList runs on Cloudflare: the app on Cloudflare Workers and your data in Cloudflare D1, on Cloudflare's global network. That means it may be processed in countries other than yours. Google is used only to sign you in. Those are the only two companies involved.

We look at stored data only when we need to fix a problem with the service or the law requires it.

Cookies

  • session keeps you signed in. It's set by MooseDoList itself, lasts 30 days and renews as you use the app.
  • While you sign in with Google, two short-lived cookies (deleted on your return, or after 10 minutes) make sure the sign-in that comes back is the one you started.

That's all. There are no analytics, advertising or third-party cookies, and no tracking scripts. The fonts and icons come from MooseDoList itself.

How long we keep it

We keep your data for as long as you have an account. Deleting a task hides it from your lists, but it stays with your account, with its history, so undo works and past days keep their tally, until you delete your account. A sign-in session stops working after 30 days without use, and signing out ends it straight away.

Deleting your account

You can delete your account yourself, at any time: open Profile in the app and choose Delete account. It's immediate and permanent. Your email address, tasks, ideas, completions, history, settings, sessions and passkey protection keys are all removed in one go, and it can't be undone. The browser you do it in forgets its local copy too, and any other device is signed out the next time it connects.

Sharing

We don't sell or rent your data, share it with advertisers, or use it to train AI. Cloudflare and Google handle it only to run the service as described above. We'd hand anything over to anyone else only if the law required us to.

Your rights

Depending on where you live, you may have rights to see, correct, delete or get a copy of your data. You can see and change everything you've stored in the app itself, and delete all of it from Profile.

Changes

If we change how MooseDoList handles your data, we'll update this page and the date at the top. The Terms of use cover the rest of the deal.

Read next Terms of use
© 2026 Moose Ltd Optional end-to-end encryption with passkeys. Privacy · Terms · Icon: Flaticon