Privacy policy

Effective 7 September 2026. Covers the Spiro Android app and this website.

The short version. Spiro keeps everything on your phone. It has no server, no account of its own, no analytics and no advertising, and the people who build it cannot see anything you put into it. Two things can copy your data off the device, and you control both: Android's own backup, which works the same way it does for every app you have, and the optional Google Tasks connection you switch on yourself.

Who this covers

Spiro is an Android app for tasks, habits, mood, prepaid electricity, petrol and recurring costs. It is not distributed through an app store; it is installed directly from a file. This policy describes what the app does with data, in plain terms, so that anyone who installs it and anyone reviewing its Google sign-in can see exactly what is and is not involved.

What the app stores, and where

Everything you enter goes into a database on your phone, inside the private storage Android reserves for the app. That includes:

Spiro has no backend service, creates no account for you, and contains no analytics, crash reporting, advertising or tracking library of any kind. Nothing is transmitted to the people who build the app, and there is no mechanism by which they could retrieve it.

Android's own backup

Spiro takes part in Android Auto Backup, the platform feature that copies an app's data to your own Google account and restores it when you reinstall the app or set up a new phone. This is deliberate: your phone holds the only working copy of your data, and a backup you do not have to remember to make is worth having.

What that means in practice:

Permissions the app asks for

Each Android permission Spiro requests is used for one visible purpose:

PermissionUsed for
Notifications Task and habit reminders, and the running timer for a timed habit.
Exact alarms Firing a reminder at the minute you set rather than whenever the system gets to it.
Run after restart Rescheduling your reminders after the phone reboots.
Calendar (read and write) Optional. With calendar sync on, Spiro writes your tasks as events into a calendar on the device and shows that calendar's other events beside your tasks. This uses Android's own calendar provider on the phone; Spiro never talks to a calendar service directly. Any syncing of that calendar to the cloud is done by whichever calendar account you already have on the phone, under its own terms.
Vibrate Haptic feedback when you tap a ring or tick something off.
Internet Only the Google Tasks connection described below. Nothing else in the app uses the network.

Google Tasks and your Google account

Spiro has one optional feature that leaves the phone: importing tasks from Google Tasks, so that something you say to Google Assistant or Gemini ("remind me to buy electricity") arrives in Spiro. It is off until you turn it on in Settings and sign in with Google.

What Spiro asks Google for

When you sign in, Google shows you a consent screen for one scope, https://www.googleapis.com/auth/tasks, which allows an app to view, create, edit and delete your Google Tasks. Spiro uses that access for exactly two operations:

Spiro does not create or edit tasks in Google Tasks, does not read any other part of your Google account, and does not use the connection for anything beyond this import. The import runs periodically in the background while the feature is on, and you can trigger it by hand from Settings.

What Spiro receives and keeps

Signing in gives the app an access token and a refresh token, and nothing else: Spiro does not ask for your email address, name or profile, and Settings shows only that an account is signed in. The tokens are held in encrypted storage on your phone and are sent only to Google, to authenticate the requests above. Imported tasks become ordinary Spiro tasks on the device. Nothing from your Google account is stored anywhere other than your phone, and nothing is shared with anyone.

Google's rules for this kind of access

Spiro's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data from your Google account is used only to provide the import described above, is never sold, is never used for advertising, and is never transferred to anyone else.

Disconnecting

You can stop the connection at any time, in either of two places:

Tasks that were already imported stay in Spiro, because by then they are your Spiro tasks. Delete them there if you no longer want them.

Backup files you export

Separately from Android's backup, Spiro can write everything it stores into a single file, and read one back later. The file goes wherever you choose through Android's file picker: a folder on the phone, or a cloud drive you already use. Spiro keeps no copy and sends it nowhere. Anything that happens to that file afterwards, including syncing by a cloud drive app, falls under that app's terms rather than this policy. Treat the file as you would the app itself: it holds all of your data, unencrypted.

Deleting your data

There is nothing to request from us, because we hold nothing.

This website

This site is two static pages. It sets no cookies, runs no analytics and has no forms. It is served by Cloudflare, which, like any web host, sees the ordinary technical details of a request (your IP address, your browser and the page you asked for) in order to deliver the page and protect the site; Cloudflare's handling of that is described in its own privacy policy. Those logs are not read by us.

Children

Spiro is not directed at children and is not offered to anyone under 13.

Changes to this policy

If the app gains a new way of handling data, this page changes first and the effective date at the top moves. The current version is always at spiro-app.com/privacy.

Contact

Questions about this policy or about the app go to hello@spiro-app.com.