Last updated 22 September 2026
Privacy policy
Ok Donkey is a mobile app that reminds you until a task is marked done. This notice says what we hold, why, and where it lives.
The controller is Mesamigos Ltd, 128 City Road, London, EC1V 2NX, United Kingdom, company number 15765239. Email hello@mesamigos.com.
Data minimisation
We keep only what the reminder needs. We do not run advertising, and we do not sell personal data.
- Your email address, so we can sign you in.
- A one-time sign-in code, stored only as a salted hash. It expires after 10 minutes. We never store a password.
- A sign-in token on your phone, valid for 30 days. It holds your account id and email.
- Events: title, optional note, an optional shared photo, schedule, time zone, repeat rule, grace period, and who is nagged first.
- Who is on an event, and whether they are the lead.
- When an occurrence is marked done or skipped, and how many seconds after the reminder that was. The timing is used only to nag whoever usually finishes first, when that option is on.
- A push token and the platform (iOS or Android), and only if this phone is registered for a remote reminder.
- A phone number, only on a paid account, and only if you add one for text messages or for break-silent calls. No call is placed until a calling provider is agreed in writing. The number is deleted when the account is deleted or when you clear it.
What we do not collect
- No password or payment card.
- No GPS or other location. The time zone on an event, such as Europe/Brussels, is there so the reminder fires at the right local time. It is not where you are standing.
- No address book. Invites are an email address you type. The app does not read your contacts.
- No advertising identifier, analytics profile, or third-party tracking SDK.
If you type health or other sensitive details into a title or note, or add a photo showing them, we store that so the reminder can be shown to you and to the people on that event. We do not ask for it, and we do not use it for anything else. Write and share only what those people need.
Why we use it
- To run the account and the events you create, including the sign-in code and showing an event to the people on it. The lawful basis is the contract for the app.
- To keep the service secure. Short operational logs may be created by the hosting platform. The lawful basis is our legitimate interest in running a reliable service. We do not use those logs to profile you.
- We do not run marketing campaigns, and we do not sell your data. Emails we already send, such as the sign-in code, include a short note about donating to keep the servers running.
Where it is stored
The API runs on Amazon Web Services in the European Union, in region eu-central-1 (Frankfurt, Germany). Account and event data is stored in PostgreSQL in the European Union. The deploy is refused if it targets any other AWS region, so this service is not placed outside the EU.
The connection to the API uses TLS. Storage at rest uses the encryption provided for that EU database.
Mesamigos Ltd is established in the United Kingdom. The UK is covered by a European Commission adequacy decision, so EU personal data can be handled by us on that basis.
The sign-in code is emailed with Amazon Simple Email Service in eu-central-1. Your own email provider then receives the message. In production the code is not written to our logs. Only the hash is stored.
Who else sees it
People you add to an event can see its title, note, photo, schedule, and whether it is still open, done, or skipped, including who marked it.
Amazon Web Services processes the data in Frankfurt to host the API, the database, delivery of the sign-in email, and operational logs. API logs are kept for 14 days in the same region.
A reminder on your own phone is scheduled on the device. It does not leave the phone to fire. When a remote reminder is sent to someone else, Apple Push Notification service or Google Firebase Cloud Messaging delivers it. Those services are operated from the United States. They receive a device token and a short reminder, not your account record and not your email. There is no separate advertising or analytics vendor.
How long we keep it
- The sign-in code hash lasts until it expires (10 minutes) or is used, and is removed when the account is deleted.
- The sign-in token on the phone lasts 30 days.
- Account, event, and completion data is kept until the account is deleted.
- API logs are kept for 14 days.
Deleting the account removes your email, the events you own and any photo on them, your place on other people’s events, any device token, and your completion history.
You can delete the account in the app, or by emailing hello@mesamigos.com.
Your rights
If you are in the UK or the EEA you can ask for access, correction, deletion, restriction, or a portable copy, and you can object to a use based on legitimate interests. Email hello@mesamigos.com from the address on the account, or write to the postal address above. We reply within one month.
You can complain to the Information Commissioner’s Office (ico.org.uk), because we are established in the UK. If you live in the EEA you can also complain to the authority in your country. In Belgium that is the Gegevensbeschermingsautoriteit / Autorité de protection des données (gegevensbeschermingsautoriteit.be).
Security and children
Sign-in uses a one-time code rather than a reusable password. The code is hashed before it is stored. The session token is signed. Database access is limited to the API.
Ok Donkey is not directed at children. You need to be at least 16 to create an account. If we learn an account is for a child under 16, we will delete it.
Changes
If this notice changes, we update the date at the top and publish the new version on this page and in the app.
Mesamigos Ltd, 128 City Road, London, EC1V 2NX, United Kingdom. hello@mesamigos.com.