Privacy-Friendly Productivity Apps That Don't Sell Your Data

Encrypted, self-hosted or simply not monetised are three different promises. What a privacy friendly productivity app really protects, and eight worth knowing.

10 min read

Most productivity apps ask you to type your life into them. Tasks are dull enough, but the journal entry, the medical appointment, the note about a difficult conversation at work and the thing you are worried about at 2am all end up in the same box. Then you notice the app is free, and you start wondering how it pays for itself.

Looking for a privacy friendly productivity app is harder than it should be, because the phrase covers at least three promises that have almost nothing to do with each other. An app can be end-to-end encrypted and still be run by a company you have to trust for everything else. An app can swear it will never sell your data while a dozen third-party scripts watch you work.

So this list sorts them by what they actually protect. Full disclosure first: we make one of the apps below, Lullim, and it sits in the least impressive of the three groups. Everything here was checked against first-party documentation on 10 August 2026.

What a privacy friendly productivity app is actually promising

There are three separate claims hiding inside the phrase. It helps to know which one you want before you pick.

Nobody but you can read it. This is confidentiality, and it comes from encryption or from the data never leaving your machine. It is the strongest claim and the rarest.

Nobody is making money from it. This is about the business model: no advertising, no data brokering, no third-party analytics watching you work. Your data sits on a company's server in readable form, and their promise is that they leave it alone.

Nobody can lock it away from you. This is portability: open file formats, a working export, the option to host it yourself. It matters most on the day you want to leave.

They are independent. Plenty of apps offer the second without the first, and a few offer the first while making the third painful. Most privacy listicles blur all three, which is how a note app with a good marketing page ends up recommended beside a genuinely encrypted one.

The ones you hold yourself

The strongest privacy guarantee is architectural. If the data is on your disk, no policy change, acquisition or breach at a company you have never met can reach it.

Obsidian

Free for personal use, with no sign-up at all. Your notes are plain markdown files in a folder on your computer, which is the whole design. Obsidian cannot read them because Obsidian never receives them.

If you want syncing across devices, Obsidian Sync is $4 a month billed annually or $5 monthly, with AES-256 end-to-end encryption. A commercial licence is $50 per user per year.

The honest limit: it is a notes tool with task plugins bolted on, not a planner. There is no real calendar, and building a daily planning system out of community plugins is a hobby in itself. Lovely if you enjoy that. Exhausting if you wanted to just plan Tuesday.

Super Productivity

Free, open source under an MIT licence, and it states plainly that it collects no analytics or telemetry and requires no account. Tasks, time tracking and notes stay on your device in plain JSON, and it works fully offline. If you want sync, you point it at your own Dropbox, Google Drive or WebDAV, and your provider only ever sees encrypted files.

The limit is one we flagged when we looked at the apps that keep score: it is built around detailed time tracking. That is information rather than judgement, but it is a lot of information, and it is not a calm tool for everyone.

Joplin

Open source, on Windows, macOS, Linux, Android, iOS and the terminal, with end-to-end encryption and to-dos alongside notes. You choose where it syncs: your own Dropbox or OneDrive costs nothing, or there is a paid Joplin Cloud hosted in France if you would rather not manage it. Its real strength is that your notes stay in an open format you could read with anything. It is a filing system rather than a way to plan a day.

Vikunja

The self-hosting option. Vikunja is licensed under the AGPLv3 and free to run on your own server, with list, kanban, table and gantt views, and importers from Todoist, Trello and Microsoft To Do. If you would rather they ran it, Vikunja Cloud's personal plan is 4 euros a month, or 40 euros a year, with a 14-day trial.

The limit is the obvious one: self-hosting makes you responsible for backups, updates and the day the server stops. Privacy bought with an unmaintained server is not privacy.

Hosted for you, but encrypted so they cannot read it

If running your own infrastructure is not appealing, the next best arrangement is a company that holds your data but has deliberately made itself unable to read it.

Standard Notes

The free plan is genuinely free at $0 a year and includes end-to-end encryption, unlimited device sync across web, desktop and mobile, offline access, tags, two-factor authentication and full data export in encrypted or plain text. That is an unusually generous floor.

The catch is the editor. Free notes are plain text; markdown, rich text, checklists and spreadsheets need the Productivity plan at $90 a year, and Professional with 100GB of encrypted file storage is $120 a year. It was acquired by Proton in 2024 and still runs as its own product with its own pricing. And it is a notes app rather than a planner: no calendar, no day view.

Lunatask

The closest thing here to an all-in-one that is still encrypted: tasks, habits, journaling and notes together, on Windows, macOS, Linux, iOS and Android. Its documentation says everything you type is encrypted on your device before it is sent, and that they collect no usage telemetry at all, relying on emailed feedback instead.

They are also specific about the limits, which is a good sign. Task metadata such as status, priority and dates is stored unencrypted, on the reasoning that a date with no title tells you very little. Their marketing website uses Plausible analytics, though the app does not.

There is a free plan with caps of two areas of life and seven daily habits, Premium is $6 a month billed annually or $8 monthly, and there is a $300 lifetime option.

Apple Reminders and Notes, but only with a setting turned on

Worth including because so many people already have it and assume it is covered. It is not, by default.

Advanced Data Protection for iCloud is an optional setting you have to switch on yourself. With it off, 14 categories of iCloud data are end-to-end encrypted. With it on, 23 are, and Notes moves into the protected group.

Read the sentence after that one carefully, though, because it changes the whole picture for planning.

Why isn't the calendar end-to-end encrypted?

Apple's own documentation answers this: iCloud Calendar, Contacts and Mail are not end-to-end encrypted even with Advanced Data Protection enabled, "because of the need to interoperate with the global email, contacts, and calendar systems".

That is not Apple being lazy. It is what calendars are. An invitation has to reach someone at another company, a free/busy lookup has to be answered by a server, CalDAV clients have to read event times. A calendar only you can decrypt cannot do any of that, which is why essentially no mainstream calendar is end-to-end encrypted, Google's included.

This matters if you want your tasks and your calendar in one view, which is the arrangement that makes daily planning honest. You can have full encryption or a calendar that talks to other people's calendars. Nobody has both.

So sort by sensitivity instead of chasing a guarantee that does not exist. Journals, medical notes and anything about other people belong somewhere encrypted. Meetings and errands are already visible to whoever you scheduled them with.

Readable, but not for sale

This is where nearly every mainstream planner sits, ours included, and it deserves to be named as its own category rather than smuggled in alongside the encrypted ones.

The data is on a server in readable form. The company could technically look at it. What you are buying is a business model with no reason to, plus the absence of the machinery that usually does the looking.

Lullim

Ours, so weigh it accordingly, and it does not belong in either group above.

Your content sits in a hosted database and it is not end-to-end encrypted, so in principle we could read it. We do not, we do not sell it, and we do not build a profile from it, which is stated plainly in our privacy policy rather than only in marketing copy.

What we can be concrete about is what is absent. There are no third-party analytics, no advertising SDKs and no tracking pixels anywhere in the app: not one third-party script runs when you use it. There is a single first-party httpOnly session cookie, which is why you never see a cookie banner, because there is nothing to ask you to consent to. Passwords are bcrypt-hashed. If you connect Google Calendar the scope is read-only, your events are read live and displayed as an overlay rather than copied onto our servers, and the access tokens are encrypted at rest with AES-256-GCM. Disconnecting deletes them.

Two limits worth stating, because they are exactly the kind of thing this article is about. Export and account deletion are handled by emailing us rather than by a button in the app, which is slower and more trust-dependent than it should be. And the whole thing runs in a browser, so there is no offline-first local copy the way there is with Obsidian or Super Productivity.

What you get in exchange is the thing the encrypted apps mostly do not do: tasks and calendar side by side in a day that is already planned when you open it, with no scoreboard attached.

How do you check an app yourself?

Take five minutes before you commit. All three checks are things anyone can do.

Read the sharing section of the privacy policy, not the headline. Search the page for "sell", "share", "advertising" and "third party". A good policy names its processors specifically, says what each one does, and is short. A policy that reserves the right to share data with unnamed "partners" for "marketing purposes" has told you the answer.

Look at the store privacy label. App Store listings and Google Play data-safety sections have to declare what is collected and whether it is linked to your identity. A to-do list that collects advertising identifiers and location has a second business.

Watch the network tab. Open the web app, open your browser's developer tools, and look at the requests. Every domain that is not the app's own is another company receiving something about your session. This is the check that catches the apps whose policy is fine but whose page loads five analytics vendors.

One more tell, once you are inside: find the export button. An app that makes it easy to take everything and leave is an app that expects to keep you on merit. An app where export is a support ticket is telling you something, and yes, that includes us.

What you are actually choosing

Nothing here is a moral test. Encryption is not virtue and a hosted database is not a betrayal. They are trade-offs, and the right one depends entirely on what you are about to type.

If that is genuinely sensitive, take the friction: Standard Notes or Lunatask for encrypted content, Obsidian or Super Productivity for files you keep, Vikunja if you will actually maintain a server. If it is your errands, your meetings and the shape of your week, what matters is a company with no advertising business, no third-party scripts, a real export route and a policy you can read in one sitting.

The useful question is the quiet version: not "is this app private", but "who else is in the room, and what are they doing here". Most of the time you can just look. Then judge whatever you pick the way you would judge any tool you plan to keep, by whether opening it still feels calm a month from now.

Common questions

Do to-do list apps sell your data?
The large free ones are the ones to check, because a free app with no subscription has to make money somewhere. Most paid task apps do not sell data, but plenty still run third-party analytics and advertising SDKs, which is a smaller version of the same thing. The answer is always in the privacy policy: search it for the words sell, share and advertising.
What is the most private to-do list app?
For content nobody but you can read, an end-to-end encrypted app like Standard Notes or Lunatask, or a local-first one like Obsidian or Super Productivity where the file never leaves your machine unless you sync it. For total control, self-host something like Vikunja. The most private option is the one you will actually keep using, so weigh it against how much friction you can live with.
Does a task app really need end-to-end encryption?
It depends what you put in it. A journal, therapy notes, medical appointments or anything about other people is worth encrypting. A list that says buy milk and call the plumber is not a meaningful secret, and paying for encryption with a worse app is a bad trade. Decide by content, not by principle.
Why can't my calendar be end-to-end encrypted?
Because calendars have to interoperate. Invitations, availability lookups and CalDAV sync all require a server that can read event times. Apple says this directly: iCloud Calendar, Contacts and Mail are not end-to-end encrypted even with Advanced Data Protection turned on, because of the need to work with the global email, contacts and calendar systems.
How can I tell if an app is tracking me before I sign up?
Three quick checks. Read the privacy policy's sharing section and see who is named. Look at the App Store or Google Play data-safety label, which has to declare linked data. And open the app in a browser with the network tab showing, then look for requests going to domains that are not the app's own. Trackers are visible if you look.