← Whittle

Privacy Policy

Last updated: July 9, 2026

Whittle is a personal productivity tool that connects to sources you choose — Canvas, Google Calendar, and Gmail — and reduces them into a short list of clear, actionable steps. This policy explains exactly what data Whittle accesses, how it's used, where it's stored, and how you can remove it. "We," "us," and "Whittle" refer to the operator of this app; "you" refers to the person using it.

Information we access

We only access what you explicitly connect, and we request the minimum permissions needed:

  • Canvas. A personal access token and your school's Canvas URL that you paste in. We use these to read your assignments, to-dos, and calendar items. We never receive your Canvas password.
  • Google Calendar (read-only). We read event titles, times, and recurrence so we can surface what's coming up.
  • Gmail (read-only). We read recent inbox messages only to detect actionable items (e.g. deadlines, requests) and turn them into to-dos. We do not read your entire mailbox history, and we never send, modify, label, or delete your email.

We do not collect analytics, advertising identifiers, contacts, or location, and we do not track you across other sites.

How we use your data

Your data is used for one purpose: to generate your reduced action list. To do this, the text of your Canvas, Calendar, and Gmail items is sent to Google's Gemini API, which summarizes and prioritizes them. We do not use your data to train models, we do not sell or rent it, and we do not use it for advertising.

Storage & security

  • All connections use HTTPS. Your source credentials (Canvas token, Google refresh tokens) are encrypted at rest with AES-256-GCM and are never stored in plaintext.
  • Data is stored using Upstash (a managed Redis database) and the app runs on Vercel. Your reduced list and any to-dos extracted from email are cached so the app loads quickly; email-derived items are automatically pruned after 30 days.
  • We store the minimum needed to run the feature and do not build a profile of you.

Who we share it with

We do not share your data with third parties except the service providers strictly required to operate Whittle:

  • Google — the Gemini API processes your items to produce summaries; Google OAuth authenticates your account.
  • Vercel — application hosting.
  • Upstash — encrypted data storage.

Google user data — Limited Use

Whittle's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google user data is used only to provide and improve the user-facing features of Whittle, is not transferred or sold for advertising or any unrelated purpose, and is not read by humans except where you have given consent, for security purposes, to comply with applicable law, or as part of aggregated and anonymized operations.

Retention & deleting your data

  • Disconnect any source on the Sources screen to stop access and delete that source's stored credentials.
  • Revoke Whittle's access to your Google Account at any time at myaccount.google.com/permissions.
  • You can wipe all data Whittle has stored for you from within the app, or by emailing us — this removes your credentials, stored state, and cached results.

Children

Whittle is not directed to children under 13, and we do not knowingly collect data from them.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above.

Contact

Questions or data requests: help@whittledown.app.

See also our Terms of Service.