Legal
Privacy Policy
Last updated: 1 August 2026
This Privacy Policy explains how Must Have Apps SIA (“we”, “us” or “our”) collects, uses and protects information when you use the Donebase mobile app and the Donebase website (together, the “Service”). Donebase is offline-first: your data lives on your device and is synced to our servers only when you sign in to an account. We collect the minimum needed to run the Service, and we never sell your data.
1. Introduction & scope
This policy applies to the Donebase app on iOS and Android and to this website. By using the Service you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Information we collect
Account information
If you create an account, we collect the email address you register with and an optional display name. Authentication is handled through our own API; we store a secured credential, never your password in plain text.
Content you create
When you are signed in, the content you add — tasks and events, habits, goals, lists, completions, reminders, and the connections and shares you set up with other people — is synced to and stored on our servers so it stays available across your devices and with anyone you share it with. If you use Donebase without an account, this content stays only on your device.
Device & usage information
We collect limited technical information such as device type, operating system version and app version, and diagnostic data. We use Firebase Analytics and Firebase Crashlytics to understand which features are used and to detect and fix crashes. This helps us improve the Service and is not used to build advertising profiles.
Website analytics
This website — not the app — uses Google Analytics 4 to count visits and see which pages people read. It works by storing a cookie in your browser that gives your visit a random identifier. It does not tell us who you are, and we never use it for advertising. Google processes this data on our behalf; their explanation of it is here.
Analytics is off until you turn it on. On your first visit a small notice asks you to choose, and unless you press Allow no analytics cookie is ever stored. In that state Google still receives a plain record that a page was viewed — no cookie, and no identifier tying one visit to the next — which is how we count traffic without following anybody around. Advertising signals stay switched off whichever way you choose, because we do not run ads.
Your answer is kept in your own browser and we do not ask again. To change it, use Privacy choices at the foot of any page; clearing your browser's site data also clears it, and the notice will ask once more.
Permissions
With your consent, Donebase may request access to your device calendars (to import events onto your timeline) and to send notifications (for reminders and quiet-hours-aware alerts). You can grant or revoke these permissions at any time in your device settings.
3. How we use information
We use the information we collect to: provide and maintain the Service; sync your content across your devices and with people you share with; send the reminders and notifications you enable; process and validate subscriptions; diagnose problems and improve performance; and communicate with you about support requests and important changes. We do not use your planning content for advertising.
4. Legal bases for processing
Where the GDPR applies, we process your information on the basis of: performance of our contract with you (to provide the Service); your consent (for optional permissions such as calendar access and notifications, and for website analytics, all of which you can withdraw); and our legitimate interests (to keep the Service secure and to improve it). You may object to processing based on legitimate interests at any time.
5. Calendar integrations & Google API Services User Data
Donebase can import events from Google Calendar, Microsoft Outlook, and the calendars already on your device, so your day reflects what is already booked. This import is one-way and read-only: Donebase reads your events to display them alongside your tasks and never creates, edits or deletes events in your source calendars.
Donebase's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access Google Calendar data solely to provide the calendar-import feature within Donebase; we do not use it for advertising, we do not sell it, and we do not allow humans to read it except where necessary for security, to comply with the law, or with your explicit consent. You can revoke Donebase's access at any time from your Google Account permissions.
Where you connect a Microsoft Outlook or Microsoft 365 calendar, we access your calendar events under the same read-only, limited-use principles, and you can revoke access from your Microsoft account settings.
6. Sharing & multiplayer
Donebase lets you connect with other people and share individual tasks or events with them as an editor or a viewer. When you share an item, its contents become visible to the people you share it with, and their changes sync back to you. You control what you share and can stop sharing or remove a connection at any time. We share your information with other users only as directed by these sharing actions.
7. Subscriptions & payments
Donebase is free to download. Optional “Donebase Pro” subscriptions are sold through the Apple App Store and Google Play. Payments are handled entirely by those stores — we never receive or store your card details. We use RevenueCat to validate and manage subscription status; RevenueCat receives a pseudonymous identifier and your purchase information to tell the app whether your subscription is active. Manage or cancel your subscription in your App Store or Google Play account settings.
8. No ads, no sale of your data
We do not show third-party ads in Donebase, and we do not sell or rent your personal information to anyone. We do not share your planning content with data brokers or advertising networks.
9. Data retention
We keep your account and synced content for as long as your account is active. When you delete your account, we remove your personal content from our production systems, and residual copies in encrypted backups are purged within a rolling backup window. We may retain limited records where required for legal, tax or fraud-prevention purposes.
10. Your rights, export & deletion
You can export your data from within the app at any time. You can delete your account and all associated content directly in the app's Settings, or by emailing us at hello@musthaveappscorp.com. Depending on where you live, you may also have rights to access, correct, restrict or object to processing of your personal data, and to lodge a complaint with your local data-protection authority. We will respond to verified requests within the time required by applicable law.
11. Security
We protect your data with encryption in transit (TLS), authenticated APIs, access controls, and regular review of our systems. No method of transmission or storage is perfectly secure, but we work to protect your information and to promptly address any vulnerabilities that are reported to us.
12. Children's privacy
Donebase is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
13. International data transfers
We are based in the European Union and may process and store your information on servers located in other countries. Where personal data is transferred internationally, we take steps to ensure it receives an adequate level of protection consistent with this policy and applicable law.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “last updated” date above and, for significant changes, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.
15. Contact us
If you have any questions about this Privacy Policy or your data, contact us at hello@musthaveappscorp.com. Must Have Apps SIA, Valguma iela 18 - 16, Rīga, LV-1048, Latvia.