Hi Dmitry, thank you for your feedback.
The code is not public and I don't have plans to share it publicly. About it, I can assure you that the database doesn't save anything about your issues/repository/Todoist projects/Todoist tasks. The only thing the software save on the database is the relation between a GitHub Project ID and a Todoist Project ID where are linked a set of options that you can configure in TodoDev. For the rest, everything works thanks to GitHub/Todoist events.
I tried to restrict the scope of the permissions as much as I could. But some things are simply necessary... Please, can let me know what permissions worrying you so much? Maybe is something that I missed and I can simply remove from permissions list.