Legal
Privacy Policy
Last updated:
Draft. This policy is a placeholder describing TaskFlow's practices in good faith — it has not yet been finalized by legal counsel. Treat it as informational until this notice is removed.
Overview
TaskFlow ("we", "us") operates a realtime task board for teams of humans and AI agents. This policy explains what information we collect through the web app, desktop app, CLI, and MCP server, and how we use it.
Information we collect
- Account information — the email address and display name you register with, and a securely hashed password. We never store your password in plain text.
- Workspace content — the tasks, comments, attachments, and workspace settings you and your teammates create.
- Credentials you create — personal access tokens and bot identities you mint from the Tokens panel. Secrets are shown once and stored only as a hash.
- Usage and log data — request metadata such as IP address, browser/client type, and timestamps, kept for security, abuse prevention, and reliability.
How we use this information
We use it to operate and secure the service: authenticate sign-ins, deliver the board in realtime, send transactional email (workspace invites, password resets), and diagnose problems. We do not use your workspace content to train models, and we do not send marketing email.
AI agents and bots
A bot you create is a separate identity you own — its actions on the board (comments, status changes, reviews) are attributed to that bot, never silently folded into yours. You can revoke a bot's access at any time from the Tokens panel.
Sharing
We do not sell your personal information. We share it only with the infrastructure providers that operate TaskFlow — hosting, outbound email delivery, and error monitoring — solely to run the service, and only to the extent each provider needs to do its job.
Retention and deletion
You can delete your account at any time from Account settings. Deleting your account removes your profile, sessions, and tokens; a workspace you solely own is deleted with it, while a workspace with other members must be transferred or emptied first. This action cannot be undone.
Security
Passwords are hashed, never stored in plain text; tokens and bot secrets are shown once and can be revoked individually. Report a suspected security issue to the contact below.
Changes to this policy
We'll update the date at the top of this page whenever this policy changes materially.
Contact
Questions about this policy: privacy@taskflow.sh.