Overview
Modocus is a local-first task manager and does not require a Modocus account. Core task data stays on your device. Selected data leaves the device only when you choose to use your own API key, Pro+ or the Free AI pool, Google Drive backup, an external content preview, or the optional task-location picker, as described below. The Free AI pool provides 30 operations per device per UTC calendar month, shared across Assistant chat, task insights, and cloud voice fallback; meeting import is excluded.
Local data and device credentials
Tasks, projects, notes, attachments, timers, event history, and saved task locations (coordinates and any reverse-geocoded address) are stored in a local SQLite database and the app container. API keys and replayable StoreKit transaction credentials are stored in the system Keychain. Modocus does not receive your Apple ID, email address, card number, or App Store payment details. Attachments are included in Free and do not require Pro or Pro+.
Using your own API key
When you select OpenAI, OpenRouter, or a compatible custom AI provider and enter your own API key, only prompts, selected task context, or audio that you actively submit are sent directly from your device to that provider. They do not pass through Modocus, and your API key is not sent to Modocus. The provider processes data under its own terms and privacy policy.
Pro+ and free AI operations
When you use Pro+ or a Free AI operation, prompts, relevant task context, or audio that you actively submit are forwarded via Modocus to an AI provider. The provider or model may change based on the task, quality, reliability, compliance, and cost. Modocus does not persist request bodies, audio, or AI response bodies. The Free pool provides 30 operations per device per UTC calendar month, resets at the start of each UTC calendar month, and is shared across Assistant chat, task insights, and cloud voice fallback. Meeting import is excluded, and on-device transcription does not consume the pool.
Pro+ includes 400 user-initiated operations per StoreKit billing period. To enforce the allowance, process refunds, and operate the service, we retain a salted anonymous subscription subject, hashed operation or transaction identifiers, and anonymous operational metrics such as feature, provider or model, token or audio usage, latency, status, and error codes. Operational metrics are retained for 14 days; billing-period quota state remains through the applicable period, and refund state remains until Apple reverses the refund notice or the record is no longer needed.
Plans, purchases, and the App Store
Free provides unlimited core task management and includes attachments. Pro is a one-time, non-consumable purchase that permanently unlocks deeper features. Pro+ is a monthly auto-renewable subscription that includes Pro features and network AI usage only while active. Apple handles payment, renewal, cancellation, refunds, and purchase restoration through StoreKit. The app forwards an Apple-signed subscription transaction credential through Modocus for anonymous authentication; App Store Server Notifications V2 provide refund or revocation status. Transaction identifiers are salted and hashed before persistent storage.
Backup and external content
Google Drive backup is enabled only after you authorize it. OAuth PKCE saves backup files directly to your own Google Drive; Modocus holds no relay credential and keeps no copy of the backup.
When you open a YouTube or Bilibili preview in a note, the app may request those platforms’ public thumbnail or metadata endpoints. Those platforms receive the information normally included in a network request.
The optional task-location picker uses foreground location permission to show your current position. Opening the picker may cause Apple Maps to load map data and the system reverse-geocoding service to receive selected or current coordinates to return an address; those services receive the coordinates and information normally included in a network request. Coordinates and any returned address that you save are stored with the task on your device and included in backups or exports you choose to create.
App analytics, advertising, and website data
The Modocus app contains no third-party advertising and does not use behavioral analytics to track how you use the app. We do not sell personal data. Crash logs remain on-device unless you choose to send them.
This website uses Google Analytics with IP anonymization to understand page visits. If you submit a launch-notification email, the email, language, source, submission time, truncated user-agent, and a deterministic SHA-256 digest of the request IP are stored in Cloudflare D1. The digest is used only as a pseudonymous abuse-prevention identifier; it is not anonymous because candidate IP addresses can be hashed and compared with it. Waitlist records remain until you request deletion by emailing hello@modocus.app or the notification purpose ends.
Your rights
You can access task data in the app and export it in JSON or zip backups. You can delete data in the app or uninstall it to remove local app data. You may also email hello@modocus.app to request access to, correction of, or deletion of data we can reasonably locate. Because subscription subjects are one-way hashes, we may need support information shown on your device and cannot derive your Apple ID from the hash. Additional rights under GDPR, CCPA, or other applicable law also apply.
Security and international processing
Network traffic uses HTTPS. Cloudflare provides infrastructure for Modocus network services and this website, while OpenAI or another disclosed provider may process AI requests. Data can therefore be processed outside your country or region. No internet service can promise absolute security; do not submit sensitive information that is unnecessary for the feature you selected.
Children's privacy
Modocus is not directed at children under 13 and does not knowingly collect personal information from children. A parent or guardian who learns that a child submitted personal information can contact hello@modocus.app to request deletion.
Changes and contact
We update the effective date on this page. If our processing changes materially, we will provide a prominent notice in the app or on this page, and historical versions remain available in the public source repository. For privacy questions, complaints, or data requests, email hello@modocus.app.