Privacy Policy
Divit for GTD · Last updated 27 August 2026
Divit is a local-first app. Your tasks live on your iPhone or iPad. There is no Divit account, no Divit server, no advertising, and no product analytics — nothing tracks which features you use or what you keep in the app.
Two things can leave your device, and this policy sets out exactly what and when: optional AI suggestions, which are off until you turn them on and supply your own OpenAI key, and crash reporting, which includes a small record of each app launch.
Who is responsible
Ripul Goyal, an individual developer based in India, is the data controller for Divit for GTD. You can reach me at gripul@gmail.com.
What Divit stores on your device
Everything you put into Divit stays in the app’s private storage on your device: your captures, next actions, projects, waiting-for items, calendar commitments, someday/maybe items, reference items, contexts, and any AI suggestions attached to them.
Alongside that, Divit stores a few small preferences — whether you have finished onboarding, when you last ran a Daily Reset or Weekly Review, and whether you have allowed AI processing.
Divit also keeps up to three small items in the iOS Keychain:
- your OpenAI API key, if you choose to add one
- a trial record — when your 14-day trial started and when the app last ran — so that deleting and reinstalling does not hand out a fresh trial
- a note that you bought the one-time unlock, so a reinstall does not lose what you paid for
Keychain items behave differently from everything else here: they deliberately outlive deleting the app. See Your rights below.
None of this is sent to me, and I have no way to access it.
What can leave your device
1. OpenAI — only if you turn it on
This is off by default and requires two deliberate steps: you supply your own OpenAI API key, and you explicitly allow AI suggestions when Divit asks.
While both are true, each capture you save is sent to OpenAI’s API. The request contains:
- the text of that capture
- today’s date and weekday, resolved in your device’s time zone
- the names and internal identifiers of up to 15 of your active projects, most recently worked on first
- the names and internal identifiers of up to 15 of your contexts
Your projects and contexts are included so the AI can match a capture to something you already have, rather than inventing a new one. Both lists are capped at 15, so a capture never carries your whole project list no matter how many you keep.
The request is authenticated with your own API key and billed to your own OpenAI account. It travels from your device directly to OpenAI — Divit has no server in between. I never receive your captures, and I never receive your key.
What OpenAI does with that data is governed by their terms, not mine. At the time of writing, OpenAI does not use data submitted through their API to train their models by default, and retains it for up to 30 days for abuse monitoring. See OpenAI’s privacy policy.
You can withdraw this at any time in Settings → AI → AI suggestions. Interpretation stops immediately, and your key stays saved unless you remove it.
2. Sentry — crash and diagnostic reports
Divit sends crash reports and error diagnostics to Sentry so that I can fix problems I cannot reproduce on my own device. A report carries a random identifier generated when you first launch the app, your device model and iOS version, the app version, and a short trail of which screens were visited before the problem.
It does not carry your task content. Screenshots and view-hierarchy capture are switched off, personally identifying information is switched off, network requests are not recorded at all — neither the addresses contacted nor any request or response body — tap-level interaction tracking is switched off, and screen names that would otherwise include your own project titles are redacted before anything is sent.
Alongside crash reports, the Sentry SDK sends one short session record each time you open the app — including when you return to it after it has spent a while in the background. This is release health: it lets me see what fraction of launches on a given app version crashed, which is the only way I can tell a bad release from a quiet one. A session record carries the same random identifier, the app and iOS version, when the session started and ended, and whether it ended in a crash. It carries no task content and nothing about what you did in the app — not which screens you opened, not which features you used, not how many items you have.
The random identifier is not linked to your name, your email, or any account, because Divit has none. See Sentry’s privacy policy.
What Divit never does
No advertising. No product or usage analytics: apart from the crash and session records described above, nothing is recorded about how you use the app. No tracking of you across other apps or websites. Divit does not ask for an account, an email address, your location, your contacts, your photos, or health data — and it does not sell or share personal information.
Backups
Divit’s data is included in your device’s normal iCloud or computer backup, which is how your tasks survive replacing a phone. Whether that backup is encrypted is controlled by your own Apple and device settings, not by Divit.
Your OpenAI API key is the exception: it is stored so that it never leaves this device, so it is not carried in backups and does not travel to a replacement device. If you restore onto a new phone you will need to paste the key in again.
Two small records deliberately do the opposite. Your trial record — when the trial started and when the app last ran — and the note that you have unlocked Divit are both stored so that they are carried in your backup and do travel to a replacement device. That is on purpose in both directions: it is what lets a new phone recognise an unlock you already paid for, and what stops erase-and-restore handing out a fresh 14-day trial. Neither record contains any task content, and neither identifies you.
Your rights
Because your data lives on your device and I hold none of it, you exercise most rights directly in the app:
- Access — everything Divit holds about you is visible in the app itself.
- Erasure — deleting an item removes it. Deleting the app removes its entire database and all of its preferences.
- Withdrawing consent — Settings → AI → AI suggestions.
The three Keychain items are the deliberate exception. On iOS, Keychain items are not stored inside the app and are not removed when the app is deleted, so your OpenAI API key, your trial record, and your purchase note all survive deleting and reinstalling Divit. That is on purpose for the trial record and the purchase note: it is what stops a reinstall from granting a fresh 14 days, and what lets a reinstall restore an unlock you already paid for.
You can remove the API key yourself at any time with Settings → AI → Remove Key, which deletes it from the Keychain and clears your AI consent. Do that before deleting the app if you want it gone. Erasing the device removes all three.
Crash diagnostics are the one category I do receive. If you would like reports from your device deleted, email gripul@gmail.com and I will remove them.
Depending on where you live you may have additional rights — under India’s Digital Personal Data Protection Act, 2023, the GDPR, the UK GDPR, or the CCPA — including access, correction, erasure, portability, and the right to complain to a supervisory authority. The same address reaches me for any of them, and I will respond within the period the applicable law requires.
For data sent to OpenAI under your own account, OpenAI is the controller and their policy and account controls apply.
Children
Divit is not directed at children and does not knowingly collect data from them.
Changes to this policy
If this policy changes in a way that matters, the updated version will be posted here with a new date. Where a change affects what can leave your device, Divit will ask you again in the app before anything new is sent.