CabinKit_Tasks — last updated 16 September 2026
CabinKit_Tasks is a private application that displays one household's shared Google Tasks lists on a wall-mounted panel inside that household. This policy describes exactly what it accesses and what becomes of it.
CabinKit_Tasks requests two OAuth scopes:
https://www.googleapis.com/auth/tasks — read and write
access to the Google Tasks lists of the connected account.https://www.googleapis.com/auth/calendar.readonly —
read-only access to the calendars of the connected account, and
to calendars others have shared with it.From Tasks it reads: the names and identifiers of the task lists on the account; and for each task, its title, notes, due date, completion state, parent task and position. It writes only when somebody presses something on the panel: marking a task complete or incomplete, adding a task, renaming one, changing its notes or due date, or deleting one.
From Calendar it reads only: the names and colours of the calendars shown in that account, and for each event in the window being displayed, its title, location, start and end. It never writes to a calendar. The scope it holds is read-only, so it could not create, change, move or delete an event even if asked to.
No other scope is requested. CabinKit_Tasks therefore cannot access Gmail, Google Drive, Google Photos, Contacts, location history or any other Google service, and does not read your profile or email address.
Solely to draw the task lists on the panel and to apply the changes made on it. The data is not analysed, profiled, mined, or used to train any model. There is no advertising of any kind.
All of this lives on hardware inside the home. There is no server, no database, no cloud component and no operator with access to it.
It is not. CabinKit_Tasks transmits data to exactly one destination — Google's own Tasks API — and to no one else. No data is sold, rented, disclosed to third parties, or transferred outside the household. There are no analytics, telemetry, crash reporting or tracking of any kind.
CabinKit_Tasks's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect CabinKit_Tasks at any time at myaccount.google.com/permissions. Access stops immediately. To remove the stored token as well, delete the credentials file from the panel; deleting it is sufficient, as nothing is retained anywhere else.
CabinKit_Tasks is not directed at children and collects nothing from anyone who has not connected their own account to it deliberately.
If this policy changes, the date at the top of this page changes with it.
Questions about this policy: me@tobiasmann.com.