TodoPin Privacy Policy
Last updated: 6 October 2026
TodoPin is a browser extension that creates Trello cards from Gmail emails. This policy explains what the extension does with your data. The short version: TodoPin has no server of its own, and the content of an email leaves your browser only when you ask TodoPin to turn that email into a Trello card, and then it goes only to Trello.
Who is responsible
TodoPin is developed by Pavel Rabau. Questions about this policy: support@todopin.app
What TodoPin does with email content
TodoPin reads the content of an email only when you click one of its buttons for that email, and sends it only to Trello. There are two ways to start from an email, and they read different things.
From an open email. When you click a TodoPin button on an open email, create a card with the dialog (from the toolbar icon's "Create card from this email" or the keyboard shortcut), add the email as a comment, or add the email's text to a card, the extension reads from the open Gmail page:
- the subject, the text of the message, the sender, the recipients and the date;
- the names of the message's file attachments, and the files you choose to attach.
It sends this to Trello to create the card or comment you asked for, or to add the text to the card.
From the inbox list. You can also create cards from emails in Gmail's inbox list without opening them: with the TodoPin button on a row, or by ticking rows and clicking TodoPin's toolbar button or using its keyboard shortcut. The extension then reads from each of those rows only what the row shows: the subject, the names and email addresses of the people shown (the senders, or the recipients in Sent and Drafts) and the date. It reads them when you click, shows them to you in a confirmation popup, and sends them to Trello when you confirm (or at your click, if you switched the confirmation off for a single email). Trello receives them as the card's title and a short footer with the people, the date and a link back to the email. If you cancel, nothing is sent. The text and the attachments of these emails are not read, so they are not sent. If you open such an email later and choose "Add email text", TodoPin reads the text and attachments of that email as described above and adds them to the card.
When you press TodoPin's toolbar button or use its shortcut, the extension also reads which rows of the list are ticked. To leave your own address out of the people shown, it reads your Gmail address from the page, and it reads which Gmail view is shown (Inbox, Sent and so on) to tell senders from recipients. Neither is stored or sent anywhere.
The content of an email is sent only when you ask for it with one of these actions.
For the emails you do not act on, TodoPin reads one thing: the Gmail conversation identifier of each conversation shown on the page. It compares that identifier, inside your browser, with the list of emails you already turned into cards, so it can mark them. The identifier is not sent anywhere. The subject, text, people, date and attachments of those emails are not read.
Two actions make extra requests to Trello, always with your Trello access token and never with email content. When you choose "Add email text", TodoPin first asks Trello for the card's current description, to see whether you edited the card. If an "Add as comment" or an "Add email text" is interrupted and resumed, TodoPin may also ask Trello for the card's most recent comments (up to 50, which can include text written by other people on the board) to check whether its own comment was already posted, so that it does not post twice. The description and the comments are compared in memory and are not stored.
When you choose "Find existing card", TodoPin asks Trello for the open cards of your default board and your recently used boards (up to six), reads their names and descriptions to find the card made from the open email, and compares them in memory. Nothing is stored except the link to the card it finds. The request carries your Trello access token and no email content.
There is one request that TodoPin makes without a click. When you open an email that already has a card, TodoPin asks Trello where that card is now (its board and list, and whether it was archived or deleted), so that the label and the notice stay correct after you move the card in Trello. This request carries only the card's identifier and your Trello access token. It contains no email content, and TodoPin makes it normally at most once every 10 minutes for each email. If your Trello sign-in has to be renewed at that moment, the request is repeated once, as for any other Trello request. It is made only while Trello is connected.
TodoPin does not send email content, or anything derived from it, to the developer or to any analytics, advertising or AI service.
What is stored in your browser
TodoPin stores the following in the browser's extension storage on your device:
- your Trello connection: an access token and a refresh token issued by Atlassian, and your Trello name and username;
- cached names of your Trello workspaces, boards, lists, labels and board members, so the pickers open quickly;
- for each email you turned into a card: the Gmail conversation identifier, and the card's identifier, link, title, list name, the board's name and colour, and whether the card is archived, so TodoPin can show that a card exists and where it is, and, for the 200 emails opened most recently, when TodoPin last asked Trello about the card;
- the cards being created at this moment, including the text being sent. Finished and undone entries are removed after 24 hours. An entry that failed, or that is waiting for you to reconnect Trello, stays with its text until it succeeds or you dismiss it;
- the boards and lists you used recently;
- for a card you created from the inbox list: a note that the card has no email text yet (removed when you add the text), and a fingerprint of the card's original description (a one-way hash, not the text itself), so TodoPin can tell whether you edited the card in Trello. They are kept with the email's record described above;
- while an "Add email text" can still be undone: the card's previous description, which for a card created from the inbox list is only its footer (the people, the date and the link to the email). It is kept in a part of the extension's storage that neither the Gmail page nor the extension's own pages can read. It is deleted when you undo, when you dismiss the result, or together with the finished entry 24 hours after it finished. If the action failed, it stays until the action succeeds or you dismiss it. Resetting or removing the extension deletes it too.
Your settings (default board and list, and preferences, such as whether to ask before creating a card from the inbox list for a single email) are stored in the browser's synchronised extension storage. If you use Chrome sync, Google synchronises them between your browsers as part of your Google account. They contain no email content and no Trello token.
Removing the extension deletes all of this from the browser. "Disconnect" in the extension's settings deletes the Trello tokens. You can also revoke TodoPin's access at any time in your Atlassian account, under connected apps.
Services TodoPin talks to
| Service | When | What is sent |
|---|---|---|
Trello (Atlassian), trello.com | When you create a card or comment, add email text to a card, when you choose "Find existing card", and when the extension loads your boards and lists | Your Trello access token, and the card content described above. To add email text or to resume a comment, TodoPin also reads the card's description or recent comments from Trello |
Trello (Atlassian), trello.com | When you open an email that already has a card, without a click, normally at most once every 10 minutes for each email; repeated once if your Trello sign-in has to be renewed at that moment | Your Trello access token and the card's identifier only, to ask where the card is (board, list, archived or deleted). No email content |
Atlassian sign-in, auth.atlassian.com | When you connect Trello, and about once an hour to renew the connection | The sign-in codes and tokens of the standard OAuth 2.0 flow. TodoPin never sees your Atlassian password |
| Google, Gmail attachment servers | When you attach a file to a card | Your browser downloads the attachment from Google, exactly as when you download it yourself, and TodoPin uploads it to Trello |
The TodoPin website, todopin.app (hosted by Cloudflare) | When you open this policy or the help page from the extension, and once when you remove the extension (the browser opens a short goodbye page) | An ordinary page request from your browser. No TodoPin data is attached. Cloudflare, as the host, sees the request and your IP address like any web server. The website sets no cookies and uses no analytics |
InboxSDK error reporting (Streak), api.inboxsdk.com | Only if the InboxSDK library, which TodoPin uses to add buttons to Gmail, hits an internal error | See the next section |
Trello's and Atlassian's handling of your data is governed by Atlassian's privacy policy. Google's is governed by Google's, and GitHub's by GitHub's.
The InboxSDK library
TodoPin uses the open-source InboxSDK library, made by Streak, to place its buttons in Gmail. InboxSDK can report usage statistics and page errors to Streak. TodoPin switches both of these off.
One thing cannot be switched off: when InboxSDK itself fails internally, it sends an error report to Streak. Such a report contains the error message and technical stack trace, the identifiers of the TodoPin extension, the versions of the library, and a one-way hash of your Gmail address. It does not contain the content of your emails. TodoPin's developer does not receive these reports.
What TodoPin does not do
- It does not collect analytics or usage statistics.
- It does not show advertising, and does not sell or share data with anyone for advertising or profiling.
- It does not use your data to determine creditworthiness or for lending.
- It does not transfer your data to anyone except as described above, which is the single purpose of the extension: creating the Trello cards you ask for.
Permissions the extension requests
| Permission | Why |
|---|---|
Access to mail.google.com | To add the TodoPin buttons to Gmail and read the email you choose to send to Trello |
Access to mail-attachment.googleusercontent.com | To download the attachments you choose to add to a card |
| Storage, unlimited storage | To keep the data listed above in your browser. "Unlimited" only lifts the browser's default size limit, so the list of emails that already have a card can grow |
| Identity | To open the Atlassian sign-in window when you connect Trello |
| Scripting | Required by the InboxSDK library to integrate with the Gmail page |
| Context menus | For the "Send selection to Trello" item in the right-click menu on Gmail |
| Alarms | To retry a card that could not be created, for example when you were offline, and to continue a batch of cards |
Children
TodoPin is not directed at children under 13.
Changes
If this policy changes, the date at the top changes, and material changes are noted in the extension's release notes.