Privacy
Last updated: August 15, 2026
Who we are
Quadro is a desktop task and calendar planner. You can reach us at support@quadro-ai.com about anything on this page, including a request to delete your data.
The short version
Your tasks live on your own computer. We do not sell your data, we do not show ads, we run no analytics, and we do not use your calendar contents for anything except displaying and organising them inside the app you installed. The one thing that ever leaves your device on purpose is a request you make to the optional assistant, which is off until you switch it on — what it sends is listed below, in full.
What we store, and where
- Your tasks, projects, events and settings are stored in a database file on your own device. We keep no copy. Cloud sync does not exist in the current release; if it ships, this page will say so before it does.
- Your account, if you choose to create one, consists of your email address, the display name you choose, and the account identifier your sign-in provider returns. These are held by our authentication provider, Supabase. Signing in is optional — the app is fully usable without an account.
- Your sign-in session is stored encrypted on your device by your operating system's own secure storage — Keychain on macOS, DPAPI on Windows — and is deleted when you sign out.
- Google Calendar data — calendar names, event titles, times and identifiers — is fetched from Google directly to your device and cached locally so the app works offline. It is never transmitted to our servers, because we do not operate a server that stores it.
- Authentication tokens for any calendar account you connect are stored encrypted on your device using the same operating-system secure storage as above.
Signing in with Google
Signing in with Google shares your name, email address and Google account identifier with Quadro. It does not grant access to your calendar. Connecting a calendar is a separate, explicit step inside the app, with its own consent screen.
Why we ask for Google Calendar access
When you connect a Google Calendar, Quadro requests these scopes and uses them as follows:
-
https://www.googleapis.com/auth/calendar.events— to read your events so the app can show your week beside your task matrix, and to create, update and delete only the time blocks Quadro itself creates when you drag a task onto the calendar. Quadro does not modify or delete events it did not create. A read-only scope will not do, because scheduling a task means writing a real event your other devices can see. -
https://www.googleapis.com/auth/calendar.readonly— to list the calendars on your account so you can choose which ones Quadro displays. Without it we cannot show you a list to choose from, and would have to display every calendar or guess.
The assistant
Quadro includes an optional assistant that answers questions about your schedule and suggests when to work on a task. It is off until you turn it on, and turning it on requires you to read and accept a summary of exactly what it sends. Nothing in this section happens until you have done both.
The assistant runs on your own API key, with the provider you choose — Anthropic or OpenAI. Requests go from your device straight to that provider, under the agreement you already have with them. We operate no server in this path and never see your conversations. Your key is encrypted by your operating system's own secure storage, is never written into a backup or an export, and is never sent anywhere except to that provider.
When you send the assistant a message, it receives:
- the message you typed;
- today's date, your timezone, and the working hours you configured;
- task fields — title, status, importance, urgency, due date, estimated duration, and which project a task belongs to. Never the notes on a task.
- your availability, as bare start and end times. Where those times come from a connected calendar — including Google Calendar — the event's title, description, location, attendees, organiser and identifiers are removed before anything leaves your device. The provider is told "busy from 09:00 to 10:00". It is never told what the meeting was.
Every write the assistant makes is visible on the card that made it, and reversible from that card. Creating a task or scheduling a time block writes the instant it is suggested — through the same code path as if you had created it by hand — with Undo and Edit right on that card. Changing an existing task is different: it overwrites fields on a row that already exists rather than adding a new one, so it still waits for you to press Accept.
Anthropic and OpenAI both state that they do not train their models on data submitted through their APIs by default. Because the request is made with your key, on your account, their terms rather than ours govern what happens to it once it arrives. If that matters to you, read the terms of the provider you pick before you enable the assistant.
Voice. If you enable push-to-talk, your microphone is live only while you hold the mic button or between the two presses of the shortcut, and the assistant window shows that it is recording the whole time. Your speech is transcribed on your own computer — the audio is never uploaded, never stored, and is discarded as soon as the words are recognised. Only the resulting text is sent, exactly as if you had typed it. Turning voice on downloads a speech model once from Hugging Face; that download carries nothing about you.
Switching the assistant off stops all of the above. Clearing the key removes it from your device.
Limited Use
Quadro's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not transfer or sell Google user data to third parties, we do not use it for advertising, we do not use it to train machine-learning models, and we do not allow humans to read it except with your explicit permission, to comply with law, or as necessary for security purposes.
This covers the assistant. When you have enabled it, the only Google-derived information that leaves your device is the timing of your busy periods — every piece of event content removed, as described above. That happens solely to provide the scheduling feature you switched on, only after you consented to it in the app, and only to the AI provider you chose, on your own account with them. Google user data is not transferred for any other purpose, is not sold or made available to data brokers or advertisers, and is not used by us to train any model.
What we do not do
No advertising. No sale or transfer of your data. No analytics or telemetry of any kind — the app sends no usage data, and there is no crash reporter. We train no machine-learning models on your data, and we send nothing to any model of our own; the assistant, if you enable it, talks to your provider on your key, and only with what is listed above.
The early-access list
If you join the early-access list on this site, Quadro receives your email address so we can send product updates and launch information. We do not sell it. Ask us at the address below and we will remove it.
Disconnecting and deleting
- Disconnect a calendar account inside the app at any time. This deletes its stored tokens and its cached events from your device.
- Revoke Quadro's access directly at myaccount.google.com/permissions.
- Sign out to delete the stored session. Your local data stays where it is.
- Switch the assistant off, or press Clear beside a saved API key, in Settings → Assistant. Clearing deletes the encrypted key from your device. Conversations are held only in memory while the app runs and are gone when you quit it.
- Uninstalling removes the local database. To delete an account and anything held by our authentication provider, email us and we will do it.
Children
Quadro is not directed at children under 13.
Changes
We will post any change on this page and update the date above.