Privacy Policy

Last updated: September 29, 2026

Introduction

Your privacy is important to us at Neural Lab. This Privacy Policy explains what data Todo Bot collects, why it collects it, where it is stored, and how you can get it removed. It covers both this website and the Todo Bot Discord application.

Information We Collect

Todo Bot only receives data that Discord sends us when you use one of its commands or press one of its buttons. We do not read your messages, and the bot requests no privileged intents. What we store is:

Todo list content

  • List titles and the text of every item you add
  • Item status (active, completed or removed) and the order of items in a list
  • The Discord message, channel and server IDs a list lives in, so the list can be found again when a button is pressed
  • Who a list or item is assigned to — Discord user IDs and role IDs
  • Who completed an item and when, plus creation and update timestamps

Account and server details

  • Your Discord user ID, username, and server nickname or display name, so the bot can show names on a list instead of raw IDs
  • The time you last used the bot, so we can tell active records from stale ones
  • The ID and name of servers the bot is used in

Interaction log

For every command, button, dropdown and modal, we write one row recording the Discord interaction ID, the type of interaction, your user ID, and the server and channel IDs it came from. This log lets us debug failures, detect abuse and avoid processing the same interaction twice. It does not contain your message content.

Feedback form

If you choose to submit the feedback form, we receive the email address you enter, the reason you select, your message, and the Discord username, server and list you submitted it from. Feedback is delivered to a private channel in our own Discord server. The form is optional — the bot works fully without it.

How We Use Your Information

We use the collected information to:

  • Maintain your todo lists and keep them working across restarts and redeploys
  • Show who a task is assigned to and who completed it
  • Diagnose errors, prevent abuse, and keep the service reliable
  • Respond to you if you contact us or send feedback

We do not sell your data, we do not share it with advertisers, and we do not use it to train machine learning models.

Where Your Data Is Stored

Data is held in a Neon-hosted PostgreSQL database and the application runs on Vercel. Access to the database is restricted to a server-side connection string; the database is not reachable from the browser. These providers process data on our behalf:

  • Neon — database hosting
  • Vercel — application hosting
  • Discord — delivers every interaction to us and receives our replies

Cookies and Analytics

This website sets no cookies and runs no analytics or tracking scripts. We do not build advertising profiles of visitors.

Data Retention

Please read this section carefully, because it describes what actually happens rather than what you might assume:

  • Deleting a list or an item in Discord marks the record as deleted and hides it from the list. The underlying row is retained in our database so that lists can be restored after an accidental deletion.
  • Removing the bot from your server stops it collecting anything further, but it does not by itself erase data already stored. To have that data erased, send us a deletion request using the contact details below.
  • Interaction log rows are retained for operational and abuse prevention purposes.

When you ask us to erase data, we permanently delete it from our database within 30 days, except where we are required to keep it by law.

Your Rights

You have the right to:

  • Request a copy of the data we hold about you or your server
  • Ask us to correct data that is inaccurate
  • Ask us to permanently erase your data, or all data belonging to a server you administer
  • Withdraw consent by removing the bot and asking us to erase your data

To exercise any of these, email us from the address below and include your Discord user ID, or the server ID if you are a server administrator asking on behalf of a server. We may ask you to verify ownership before acting on a request.

Children's Privacy

Todo Bot is not directed at children. Discord requires its users to be at least 13 years old, or older where local law sets a higher minimum age. If we learn that we hold data from someone below that age, we will delete it.

Changes to This Policy

We may update this Privacy Policy as the bot changes. The "Last updated" date at the top of this page always reflects the current version, and material changes will be announced in our support server.

Contact Us

For any privacy-related questions, or to make a data access or deletion request, please contact us at hello@theneurallab.com

Updates to This Policy

We periodically review and may update this Privacy Policy to accurately reflect any changes in our practices, technologies, services, or applicable legal requirements. We encourage you to regularly revisit this page for any updates, which will be indicated by the  date displayed at the top of this Privacy Policy.