Privacy Policy
Last updated: 6 June 2026
This Privacy Policy explains how Taskly ("we", "us") collects, uses, and protects information when you use our task-management application and website (the "Service").
1. Information we collect
Account information
- Your name, email address, and (for email sign-up) a hashed password.
- If you sign in with Google, basic profile information (name, email, avatar) provided by Google.
Content you create
- Workspaces, projects, tasks, subtasks, comments, references and related metadata you add to the Service.
- Messages you send to the AI assistant ("Otto").
Usage & technical data
- Basic technical data such as IP address, browser type, and timestamps, used to operate and secure the Service.
- Authentication session cookies (essential for keeping you signed in).
2. How we use information
- To provide, maintain and improve the Service.
- To authenticate you and secure your account and workspace.
- To process your AI requests and create/edit tasks you approve.
- To send essential transactional emails (e.g. confirmation, invitations, assignment notifications).
- To detect, prevent and address abuse, fraud, or security issues.
3. Legal bases (where applicable, e.g. EEA/UK)
We process personal data to perform our contract with you (providing the Service), based on our legitimate interests (securing and improving the Service), to comply with legal obligations, and/or with your consent where required.
4. How information is shared
We do not sell your personal data. We share data only with service providers ("subprocessors") that help us run Taskly, under appropriate agreements:
- Supabase — database, authentication, realtime.
- Vercel — application hosting.
- OpenRouter — AI processing for Otto (receives the text needed to fulfil your request).
- Google — if you choose Google sign-in.
- Resend — transactional email delivery, when enabled.
We may also disclose information if required by law, or to protect the rights, safety and security of our users and the Service.
5. Data retention
We retain your information for as long as your account is active or as needed to provide the Service. You can delete tasks and content at any time; when you delete your account, we delete or anonymise associated personal data within a reasonable period, except where retention is required by law.
6. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@taskly.app.
7. Security
We protect your data with database-level isolation (row-level security), encryption in transit, hashed passwords, and access controls. See our Security page for details. No system is perfectly secure, but we work hard to safeguard your information.
8. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
9. International transfers
Your data may be processed in countries other than your own by our subprocessors. Where required, we rely on appropriate safeguards for such transfers.
10. Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the "Last updated" date above.
11. Contact
Questions about this policy? Email privacy@taskly.app.