Tindo is a small self-hosted tool. No company, no ads, no tracking. This page explains exactly what happens to your data — including the parts that are not flattering.
Your data lives in your own separate space; other users (including the owner's calendar) cannot see it. You can export or delete everything at any time.
Technically, the owner can. The owner has server administration rights and can read the database files.
In practice: the owner does not look, and has no interest in looking. No snooping, no other use, no sharing with anyone.
That is a limitation of a self-hosted tool, not something a promise can fix — so the owner tells you plainly instead of glossing over it.
If the user base grows and people are willing to pay, database encryption will be added: a key derived from your password, so that even the owner cannot read your content.
“Import itinerary” and “Let AI tidy the list” send the text you paste to the DeepSeek API (a third-party AI service).
So: do not put passwords, ID numbers or card numbers in there.
If you would rather nothing leaves the server, simply don't use those two features — you can add events and list items by hand.
Data is stored unencrypted on the server. If the server were compromised, data could be read. This is a known limitation of a small, single-person project.
For any privacy question — or if you want your data removed but would rather not do it yourself — use the message form on the sign-up page.