Privacy

What we collect, and why.

Last updated: August 2026

Toranu is a free planner. There is no signup wall, no advertising, and we don't sell or share your data. This page explains exactly what we record and how to turn it off.

Things you publish are public.

When you publish a timeline or a checklist you get a shareable URL. The JSON behind that URL is hosted on public storage, so anyone with the link can read it. Sharing is the intent of publishing, and the URL itself is the access control. Please avoid putting anything in something you publish that you wouldn't want a stranger to see.

Ticking off a shared checklist.

When you tick items on a checklist someone shared with you, those ticks are saved in your own browser and are never sent to us. Nobody else — including whoever shared it — can see them, and published checklists are immutable, so your ticks never change what other people see. That is also why everyone who opens the same packing list gets their own copy of the ticking without needing an account. Clearing your browser storage clears them.

If you sign in.

Sign-in is only required for personal lists and bookmarks. We use GitHub or Google as the identity provider. From them we receive a provider-supplied user identifier (such as an email address or username), a stable user id, and the identity provider name. We store those alongside your bookmarked timeline ids so we can show your dashboard. We never share, sell, or use that identifier for marketing. Sign out at any time from the user menu — that revokes the session cookie immediately.

Analytics.

We run two first-party analytics tools so we can understand how the product is used and fix what isn't working:

No third-party advertising trackers. No Google Analytics. No Facebook pixel.

AI generation.

The "describe your project" prompt is sent to Azure OpenAI to draft a timeline structure. Azure OpenAI does not use prompts to train models and discards inputs after processing. We log the prompt's outcome (success / failure / quota) and store a truncated copy of the prompt text with the associated AI event record.

Cookies.

The only cookie we set ourselves is the OAuth session cookie after you sign in (scoped to toranu.com, deleted on sign-out). Third-party SDKs set additional first-party cookies: Microsoft Clarity sets cookies for visitor identification, and the Application Insights browser SDK sets ai_user and ai_session cookies to correlate page-view and error events across requests. None of these cookies contain personally identifiable information.

Feedback you send us.

The Feedback link in the footer opens a short form. If you use it, we store what you wrote, the optional category you picked, and the page you sent it from. Nothing else — we don't record your IP address, your browser's user agent, or your account, even if you happen to be signed in.

An email address is optional and never assumed. The field only appears once you tick the separate permission box, and we store the address only alongside a record of the exact wording you agreed to and when. We use it to reply to that piece of feedback and nothing else: no marketing, no mailing list, no sharing. Withdraw permission or ask us to delete the address any time by emailing contact@toranu.com.

Feedback is deleted automatically after about 13 months. To stop spam we count submissions against a salted, irreversible fingerprint of the sending network address; that counter resets daily and is never stored on your feedback itself. Please don't include personal or confidential details in the message — we ask for none of it.

Get in touch.

Questions, deletion requests, or anything else, please email contact@toranu.com.