Legal

Privacy Policy

Effective June 13, 2026

What we collect, why, who we share it with, and the choices you have.

Gumhop ("Gumhop," "we," "us") is a task-capture and rewards app.

Who we are

For the information described here, Gumhop is the data controller.

What we collect

We only collect what we need to run the app.

You give us

  • Account email — to sign you in (one-time code, magic link, or email + password) and to send service email.
  • Password (if you use email + password sign-in) — we never see or store your password in readable form. It is handled and hashed by our authentication provider. See Security.
  • Your content — the tasks, notes, lists, folders, subtasks, and reward packs you create, including any text, links, dates, contacts, locations, or images you add.
  • Profile and settings — optional display name, theme preference, your timezone, and your notification preferences.

Created automatically when you use Gumhop

  • Timezone — so reminders, due dates, and the morning brief land at the right local time.
  • Push subscription details — if you enable push, your browser provides a push endpoint and the cryptographic keys needed to deliver notifications, plus a short user-agent string.
  • AI usage metadata — when AI parsing runs, we log the model, token counts, latency, and success/failure for monitoring and cost. We do not store your task text in these logs.
  • API key metadata — if you create an API key, we store its name, a one-way hash, and a short display prefix. We never store the full key after it is shown to you once.
  • Limited technical/usage data — standard server and network information such as IP address, browser type, and request logs, processed to operate, secure, and debug the service.

We do not

  • Sell your data.
  • Run third-party advertising or ad-tracking on you.
  • Use cross-site tracking cookies or fingerprinting for advertising.

How AI processing works

Gumhop uses AI to read a task you type in plain language and pull out structured details (title, due date/time, priority, links, emails, locations, subtasks).

  • When AI parsing is enabled, the text of the task you capture is sent to our third-party AI provider to be parsed. We send your task text (truncated to roughly 2,000 characters) along with the current date and your timezone. We do not send your email address, account ID, or other profile data with it.
  • The AI returns structured fields, which we save to your task.
  • You can turn AI parsing off any time in Settings. With it off, your task text is not sent to the AI provider.
  • Treat AI output as a helpful guess, not a guarantee — always check important dates and details.

Why we use your data

PurposeData used
Provide the core app (store and sync your tasks/lists/rewards)Content, profile, settings
Sign you in and keep you signed inEmail, password (hashed), session cookies
Parse natural-language tasks into structured fieldsTask text (when AI parsing is on), timezone
Send the daily brief and reward emailsEmail, content, settings
Send push notificationsPush subscription, settings
Deliver reminders at the right local timeTimezone, due dates
Operate, secure, debug, and prevent abuseTechnical/usage data, AI usage metadata

Where applicable (e.g. GDPR/UK GDPR), our legal bases are performance of a contract, legitimate interests (security, abuse prevention, reliability), and consent (e.g. push notifications).

Who we share it with (sub-processors)

We use a small set of trusted providers and share only what each needs:

  • Authentication, database & storage provider — stores your account, content, profile, push subscription records, and reward media.
  • AI provider — parses your task text into structured fields (only when AI parsing is enabled).
  • Email provider — delivers account and notification email.
  • Hosting provider — runs and serves the app (processes requests and standard server data, including IP address).
  • Browser push services — when you enable push, notifications are delivered through your browser's own push service.

We don't sell your data or share it with advertisers. We may disclose information if required by law, to protect our rights, or to investigate fraud, abuse, or security issues.

Cookies and local storage

Gumhop keeps cookies and browser storage to a minimum. We don't use advertising or cross-site tracking cookies — none.

Essential authentication / session cookies

When you sign in, our authentication provider sets cookies in your browser to keep you logged in and to securely refresh your session as you move between pages. Without these, you'd have to log in repeatedly and the app wouldn't work. These are strictly necessary.

Local storage

Gumhop may use your browser's local storage to hold session/auth information and remember lightweight preferences (such as your theme) so the app loads in the right state. This stays in your browser. If you enable push notifications, your browser also stores a push subscription so notifications can be delivered; you can revoke it any time by turning off notifications in Gumhop's Settings or in your browser/OS settings.

Managing cookies

You can clear or block cookies in your browser settings, but blocking the essential authentication cookies will prevent you from staying signed in to Gumhop.

Data retention

  • Your content and account are kept for as long as your account is active.
  • AI usage logs (metadata only) and standard server logs are kept for a limited period, then deleted or aggregated.
  • Push subscriptions are removed when you disable notifications or the push service reports them gone.
  • When you delete your account, your profile, tasks, lists, folders, subtasks, rewards, push subscriptions, daily summaries, API keys, and uploaded reward media are deleted, generally within 30 days, except where we must retain limited records to comply with law.

Your rights and choices

Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to or restrict certain processing. In Gumhop you can already:

  • Access and edit your tasks, lists, profile, and settings directly in the app.
  • Turn AI parsing on/off, and turn each notification channel on/off, in Settings.
  • Export your data — contact us to request a copy of your account data.
  • Delete your account — contact us and we'll delete your account and associated data.

We may need to verify your identity (for example, that you control the account email). If you're in the EU/UK and unsatisfied, you may complain to your local data protection authority.

Children

Gumhop is not directed to children. You must be at least 13 (or the minimum age of digital consent in your country) to use Gumhop. If you believe a child has provided us data, contact us and we'll delete it.

International data transfers

Our providers may process data in countries outside where you live, including the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses. In particular, our AI provider may process task text outside your country when AI parsing is enabled; if you prefer otherwise, turn AI parsing off.

Security

We take protecting your tasks seriously. Here's how Gumhop keeps your data safe, in plain terms:

  • Encryption in transit. All traffic between your browser and Gumhop is served over HTTPS/TLS. Push notification payloads are encrypted to your device's keys.
  • Row-level access controls. Our database enforces, at the database level, that you can only read and write your own tasks, lists, rewards, profile, and settings — not anyone else's.
  • Password hashing. If you use email + password sign-in, your password is hashed and managed by our authentication provider. We never see, log, or store your password in plain text.
  • Secrets and keys. API keys you create are stored only as one-way hashes with a short display prefix; the full key is shown to you once at creation and can't be recovered by us. Service credentials are kept as server-side secrets and never exposed to the browser.
  • Minimal AI exposure. When AI parsing is on, only your task text (plus the date and your timezone) is sent to our AI provider — not your email or account identity. AI usage logs record token counts and timing, not your task content.

What you can do

  • Use a strong, unique password (if using password sign-in), or stick with one-time code / magic-link sign-in.
  • Keep any API keys you generate secret, and revoke keys you no longer use.
  • Sign out on shared devices and disable notifications on devices you no longer control.

Reporting a vulnerability

If you discover a security issue, we want to hear from you — and we appreciate responsible disclosure.

  • Contact us privately to report the issue, with enough detail to reproduce it.
  • Give us a reasonable chance to fix it before any public disclosure.
  • Please don't access or modify other users' data, run automated attacks, degrade the service, or use destructive testing.

We'll acknowledge reports that include enough detail and work to address confirmed issues promptly. We appreciate good-faith reports and can credit you if you'd like.

Changes to this policy

We may update this policy as Gumhop evolves. We'll change the effective date above and, for material changes, make a reasonable effort to notify you.

Contact

For questions, requests, or concerns about this policy, contact us.