Local · Markdown is the single source of truth
Your task list,checked against your code.
Push a repository forward with an agent and the task list soon stops looking like the code: finished work left unticked, ticked items that aren't really done, and an agent that reads a stale line and does completed work all over again. Virgo gathers the project's TODO.md files into one view, looks for evidence of each item in your Git history and reports only the differences — whether something is done is still your call.
The launch notice is a single email, not a subscription.
Thirty seconds to line the list up with the code.
-
Open a project folder.
Virgo finds every
TODO.mdin it (plus any Markdown that declarestodo-spec) and lists them by source. No sign-in, no network. -
Read the reconciliation.
Next to each item is the evidence Git can find: which changes, which commit range. Items with no evidence, or whose evidence doesn't match their status, are flagged.
-
Write the outcome in place.
Done, partly done (
◐) and failed (⚠) are all written on that line, with a one-line note. Virgo writes back only the bytes it recognises; everything else in the file stays byte-for-byte the same. -
Your agent reads the same file.
Run
todo hooks install --agent claude|codex|deepseek-harnessand the list it reads at the start of each session is the one you just reconciled.
It reports. It doesn't decide for you.
The file is the fact; the app is a view.
SQLite is only a derived index and can be rebuilt from the Markdown at any time. Delete Virgo and your
TODO.mdis still plain Markdown that any editor opens.Evidence shows a change exists, not that a task is done.
Reconciliation tells you whether an item has matching changes in Git. Ticking it off is always a person's decision.
A restore point before every write.
.todo/history/keeps 200 by default. Whole-file rewrites (scan imports, version restores) show a side-by-side diff before you confirm; if someone changes the file while you're previewing, the write is refused and you're asked to retry.No network, no sign-in.
In local mode you open a folder and start. Semantic reconciliation is off by default; turning it on takes your own LLM key, and requests go straight from your machine to the provider you choose — never through our servers.
Anonymous usage statistics, and a switch for them.
By default the desktop app reports which view you open and which features you use, plus the app version and OS. Never task text, file paths or project names. Turn it off in Settings → Usage statistics.
Personal captures stay out of the repo.
Whatever you jot in the quick-capture window (⌘⇧Space) lives in
~/.todo/inbox.md. It isn't covered by project restore points and is never committed.
Four views, one file.
- Goal
- In progress, queued and done on one surface; one in-progress item open by default, up to five.
- Quadrant
- Drag items into four cells by
!1–!4. Only that line's!marker is written back; unranked items wait in the tray. - Capture
- Your personal inbox, and triage. ⌘⇧Space to jot something down, ⌘⏎ to save.
- Scan & history
- Scan the whole repository for untracked work and review the diff before importing; browse and restore restore points.
- [ ] Task !2 ◐ ↳ note 🔗 a1b2c3..d4e5f6 <!-- id --> — priority, partial completion, note, evidence and a stable ID are all plain characters in the file. The todo CLI and the desktop app read and write the same format.
Launch day isn't here yet.
The macOS build is going through Developer ID signing and notarization. Until it's signed we won't post an installer — not even an unsigned “use it for now” build. Other platforms come after macOS; nothing is promised for them yet.
Leave an email and we'll write back on launch day. No sign-up and no mailing list — just one email, and the body can be empty.
| Platform | Status |
|---|---|
| macOS · Apple Silicon | Coming soon |