Last updated: May 18, 2026.
PebbleTasks is a hobby project developed by Shan Srini. Source code, including the OAuth helper server that hosts this privacy policy, is open and available at https://github.com/shan-srini/PebbleTasks. This privacy policy applies to the PebbleTasks application (Pebble watchapp and companion) and to the OAuth helper website at pebbletasks.shansrini.com.
Note (May 2026): This policy includes explicit disclosures of what Google user data PebbleTasks requests, accesses, and processes when you enable Google Tasks integration, as well as how that data is used, shared, protected, retained, and deleted.
When you choose Google mode and sign in, PebbleTasks requests the OAuth scope https://www.googleapis.com/auth/tasks (Google Tasks only). We do not request access to your Google profile, Gmail, Calendar, Drive, Contacts, or other Google services.
The data we access from your Google account is limited to what is needed for Google Tasks on your watch and phone. We do not ask you to provide your name, cell phone number, mailing address, or similar contact details to PebbleTasks, and we do not use Google sign-in to build a marketing profile about you.
We may collect, access, or process on your behalf the following categories of Google user data when you use or interact with PebbleTasks with Google integration enabled:
access_token, refresh_token (when Google issues one), expires_in, and token_type. Used only so the app can call the Google Tasks API on your device. Our public OAuth helper server does not persist these tokens; the companion app may store them locally on your phone.needsAction / completed), due dates, and ordering/position fields needed to display, complete, reopen, set or clear due dates, and delete tasks. Task notes and other Tasks fields are not read or displayed by this app.Google user data we do not collect or access: your Google account password; your name, email address, phone number, or postal address from Google People/Profile APIs; Gmail messages; Calendar events; Drive files; location data; or any Google data outside the Tasks scope listed above.
Where this data is processed: Google Tasks API calls are made from the Pebble companion app on your phone using the stored OAuth token. Task content is shown on your watch via the companion link. Our OAuth helper website exchanges authorization codes and optional refresh requests in memory only; it does not maintain a server database of your tasks or tokens.
We use information from your Google account only to provide the functionality you asked for: viewing and editing your Google Tasks through the Pebble companion app and watch. We do not use Google user data for unrelated features (for example, we do not use it for email newsletters, marketing lists, or broad “analytics” profiles).
We do not sell your data. We may share it only with parties that are strictly necessary to deliver the service you requested—principally Google (OAuth sign-in and the Google Tasks API), your device software (Pebble companion and watch), and ordinary infrastructure providers that only see encrypted HTTPS traffic in transit (for example hosting, DNS, and TLS). Those providers do not receive your data for their own purposes beyond carrying the connection.
We do not persist OAuth tokens, refresh tokens, or Google Tasks data on this server. The only long-lived items involved in sign-in are short-lived OAuth state values kept in memory to match the callback to your session, then discarded. For the exact behavior, see the open-source server and the note on the settings page.
state values used during sign-in are short-lived and discarded after the callback.PebbleTasks’ use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not use Google user data for any of the following purposes:
Our use of Google Tasks data is limited to providing and improving the user-facing functionality of PebbleTasks (viewing and editing your Google Tasks on your Pebble watch and phone).
https://www.googleapis.com/auth/tasks scope. No profile, email, contacts, calendar, Drive, or other Google scopes are requested.state values to mitigate CSRF, and refresh tokens issued by Google are used to obtain new access tokens without re-prompting.No method of transmission or storage is 100% secure on the internet; however, the practices above are designed to keep Google user data confidential and minimize exposure.
PebbleTasks depends on third-party services and software (including Google APIs, Rebble/Pebble companion behavior, hosting, DNS, and network providers). Their outages, policy changes, or platform behavior can affect functionality. These providers act only as conduits for encrypted HTTPS traffic and do not receive Google user data for their own independent purposes.
If you connect Google, you can revoke PebbleTasks access at any time from your Google account permissions page.
You retain ownership of your task data. PebbleTasks does not claim ownership of your content.
This is an as-is hobby project. No guarantees are made about availability, security, fitness for any purpose, or data retention.
This policy may be updated at any time. The “Last updated” date at the top of this page reflects the most recent revision. Material changes to how PebbleTasks uses Google user data will be reflected here. Continued use after updates means you accept the revised policy.
For privacy questions, data requests, or to report a concern about PebbleTasks’ handling of Google user data, please open an issue on the project repository: https://github.com/shan-srini/PebbleTasks/issues.
Last updated: 2026-09-30