Axelo is a to-do list and daily planner with a built-in AI assistant. It is built to be private: no accounts, no advertising, no analytics, no tracking. Your tasks live on your iPhone.
What stays on your device
- Your tasks, subtasks, notes, dates, priorities and lists
- Your completion history, streaks and trophies
- Your AI conversation history and the assistant's optional memory
- Appearance and behaviour preferences
There is no Axelo account, so none of this is linked to your name or email. Deleting Axelo removes the app's database. Data may remain in an iPhone or iCloud device backup until that backup is deleted or expires.
Calendar is only ever read, and stays on your device
If you grant calendar access, Axelo reads events only to display them alongside your tasks. Reading events requires what iOS calls "full access", so that is the permission Axelo asks for - but Axelo never adds, changes or deletes anything in your calendar, and events read from Apple Calendar are never sent to the AI or anywhere else.
What leaves your device, and only with your consent
The AI assistant works by sending your message, any photos you attach, and a bounded snapshot of your Axelo data to our server. That snapshot can include task titles, notes, subtasks, dates, plans, reminders, priorities and lists; completion history; streaks and trophies; relevant preferences; your recent conversation; the assistant's memory while memory is enabled; and the current date, time and time zone. Axelo also sends an anonymous RevenueCat subscription identifier and, when you use paid AI, Apple-signed purchase and device-integrity proofs so our server can verify access, make a copied subscription identifier alone insufficient, prevent request replay, and count usage. Internal task and list identifiers and events read from Apple Calendar are never included.
Nothing is sent to the AI until you agree in the app before your first AI message, and the AI features require an active subscription. Without a subscription, Axelo's only network activity is the anonymous subscription check described under Purchases.
AI processing
Our server passes your message, any photos you attach, and the snapshot to OpenAI as a data processor to generate the reply. The purchase and device-integrity proofs described under Purchases are verified separately and are never sent to OpenAI. OpenAI states that API inputs and outputs are not used to train its models by default. Its abuse-monitoring logs may contain customer content and are generally retained for up to 30 days, but longer retention can apply when required by law or reasonably necessary to protect its services or third parties. Image inputs flagged as potentially containing child sexual abuse material may be retained for manual review. See OpenAI's API data controls for details. Our own server does not store, log, or tail request contents - it holds only status codes, timings, usage counters and the security records described below.
We require OpenAI, RevenueCat, and any other third party that processes user data for Axelo to provide the same or equivalent protection for user data as described in this Privacy Policy and required by applicable law.
Optional web search
When a question needs current information, the assistant may use your current question to search the public web, and can include results in its answer with visible links to the cited sources.
Purchases
Subscriptions are paid entirely through Apple and your App Store account; we never see your payment details. To validate your subscription, Axelo uses RevenueCat with a random, anonymous identifier that is not linked to your name, email, or any Axelo account. Axelo keeps this identifier in the device Keychain so the same device can reuse it after a reinstall.
Before an app installation can use paid AI, Axelo sends our server an Apple-signed StoreKit transaction, the App Store's device-verification identifier, and an Apple App Attest statement. That statement cryptographically covers the registration challenge and authorization details. The server verifies the transaction against the supplied StoreKit device-verification value and active RevenueCat subscription, verifies that the request comes from a genuine Axelo installation, then binds that anonymous subscription to the app's attested key. Each later paid AI request carries a fresh App Attest assertion over that exact request so a copied subscription identifier alone or a captured request cannot be reused.
The full signed transaction, device-verification identifier and attestation statement are checked in memory and are not retained. Our server stores two limited kinds of records: per-subscription-period usage counters (chat and task-parse counts only, never content), and a security record containing the anonymous RevenueCat customer and subscription identifiers, the App Store transaction identifier used to register the key, the App Attest key identifier and public key, its production or development environment, an anti-replay counter, and creation and last-used times. These are opaque identifiers and cryptographic data, not your name, email, payment details, device serial number, advertising identifier, or anything you wrote. When you withdraw AI consent, a successful revocation request deletes the security record for that installation. If the request cannot be completed immediately, Axelo keeps it pending and retries later. The server also automatically deletes security records after 90 days without use. Per-subscription-period usage counters are not removed by this automatic security cleanup. To request deletion of any remaining anonymous records while Axelo is still installed, open Settings > Privacy > Copy support ID, then email that ID to the address below so we can locate and delete the matching records. An email address alone cannot identify them because Axelo has no accounts.
Notifications
Reminders and notifications are generated locally on your device and are optional.
Children
Axelo is not directed at children and does not knowingly collect personal information from anyone, including children.
Your choices
- Simply don't use the AI tab - everything else works fully offline
- Turn the assistant's memory on or off in Settings
- Delete AI conversations in the app
- Manage calendar access at any time in iOS Settings
- Delete the app to remove its database; copies in device backups and the random Keychain identifier can remain as described above. Before deleting Axelo, you can copy the support ID in Settings > Privacy and email it to us to request deletion of matching anonymous server records
Changes
If this policy ever changes, the new version will be posted at this address with a new effective date.
Contact
Questions about privacy? Email tacticalcodeworks@hotmail.com.