Legal
Privacy Policy
Last updated August 18, 2026
This Privacy Policy explains how task'd ("task'd," "we," "us") collects, uses, shares, and retains personal information when you visit our websites, create an account, or use the product.
We wrote it to match how the product actually works — including Google sign-in, Stripe billing, Supabase hosting, and account deletion — so you can make an informed choice. If anything here is unclear, email hello@taskdboard.com or use the contact page.
1. Who we are
task'd is a personal task board operated by the developer of the service doing business as task'd. For the current operator identity and a mailing address, email hello@taskdboard.com.
For GDPR and UK GDPR, the operator of task'd is the data controller of personal data processed to provide the service. Processors we use are listed in How we share information.
2. Scope
This policy applies to:
- taskdboard.com (and taskdboard.vercel.app as a predecessor / preview host)
- The web app, including the installable PWA
- Accounts, billing, support, and related communications
- Public share-card pages you choose to create
It does not apply to third-party sites we link to (Google, Stripe Checkout, processor privacy pages) — those have their own policies.
3. Information we collect
Account and identity
When you sign up with email and password or continue with Google, we store an authentication record and a profile. That typically includes:
- Email address
- Display name (and, for Google, the name Google provides)
- Password hash if you use email sign-in (we never store the plaintext password)
- Profile photo URL if Google provides one
- Preferences such as theme, accent, board sort, meeting day, and onboarding state
- A unique referral code if you use invites
Content you create
Boards, tasks, descriptions, people fields, comments/updates, timers, meeting notes, recap history, streaks/XP, categories, and similar board data are stored so the product can sync across your devices. This is your content. You decide what to put in it.
Billing
If you start a paid plan, we store Stripe customer and subscription identifiers, plan tier (free / pro / lifetime), status, and current period end. We do not receive or store full card numbers, CVC, or bank account numbers — Stripe does.
Trial-abuse prevention
First-time accounts receive a 14-day no-card Pro trial. To stop repeat trials after delete-and-re-signup, we store a one-way hash of your email and of an anonymous browser identifier. Those hashes are not tied to your user id and survive account deletion. They are not used for advertising.
Referrals
If you arrive on an invite link, we store the referral code in a cookie and, if you sign up, a referral record linking referrer and referee (status, timestamps). That is how a gifted Pro month is attributed.
Device, logs, and security
We and our processors may process IP address, user-agent, timestamps, approximate location derived from IP, and request paths to operate the site, debug errors, and rate-limit abuse. Error reports sent to Sentry are configured not to send default PII; they may still include a stack trace and the URL of the failing request.
Information we do not collect
- We do not run advertising pixels or sell lists
- We do not ask for government ID, date of birth, or payment card PAN
- We do not use your Google account to read Gmail, Drive, or contacts — sign-in only
- We do not train public AI models on your boards or notes
4. Google account data
If you choose Continue with Google, Google authenticates you and shares the basic profile needed to create a task'd account. In practice that is:
- Email address
- Name
- Profile photo (if your Google account has one)
- A stable Google user identifier used for sign-in
We use that information only to create and authenticate your account, show your name/initials in the product, and email you about the account (for example security notices). We do not use Google user data for ads, scoring, or resale.
task'd's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google sign-in by deleting your task'd account (Account → Delete account) and, separately, by removing task'd from your Google Account permissions at myaccount.google.com/permissions.
5. How we use information
We use personal information to:
- Provide, sync, and secure the product
- Create and authenticate accounts (email or Google)
- Send transactional mail (confirm signup, reset password, security notices)
- Process subscriptions, trials, Founder Pro, and invoices via Stripe
- Prevent fraud, trial abuse, spam, and attacks
- Measure aggregate product usage (Vercel Analytics)
- Diagnose crashes and errors (Sentry)
- Attribute referrals you choose to share
- Respond to support, privacy, and legal requests
- Comply with law and enforce our Terms
Legal bases (GDPR / UK GDPR)
Where those laws apply, we rely on:
- Contract — to provide the account, board, and paid features you request
- Legitimate interests — security, trial-abuse prevention, aggregate analytics, product improvement, and keeping the service reliable. You may object; see Your rights
- Consent — where we ask for it, or where a non-essential cookie requires it. You can withdraw consent anytime
- Legal obligation — tax, accounting, and responding to lawful requests
8. Analytics
We use Vercel Web Analytics for privacy-oriented page-view and performance metrics. It is designed to work without advertising cookies and without identifying you across unrelated sites. We use it to understand which marketing pages are useful and whether the app is healthy — not to build a sales profile.
We do not use Google Analytics, Meta Pixel, or similar ad trackers.
9. Payments
Paid plans are processed by Stripe. When you check out or open the customer portal, you provide payment details to Stripe. We store the resulting customer id, subscription id, tier, and status in Supabase so the app can unlock Pro features.
If you delete your account, we attempt to cancel any live Stripe subscription first and keep a cancellation ledger (subscription id, outcome, timestamps) so we can finish that cancellation if the first attempt fails. That ledger is not your board content.
10. How long we keep information
- Account and board content — until you delete the account or the specific content. Deleting the auth user cascades boards, tasks, notes, comments, activity, series, profile, and the subscription row.
- Trial hashes — kept after deletion so a new signup from the same email or browser does not receive another no-card trial. They are not a backup of your tasks.
- Stripe cancellation records — kept as needed to finish canceling billing and for accounting/security.
- Share-card links — encoded stats expire (currently 90 days). Anyone with the link can view it until then.
- Logs and error reports— kept for a short operational window, then dropped by the processor's retention settings.
- Backups — infrastructure backups may lag live deletion by a limited period, then age out.
11. Security
We use HTTPS, hashed passwords (via Supabase Auth), row-level security so one account cannot read another's boards, and rate limiting on auth and expensive actions. No method of transmission or storage is 100% secure. If we learn of a breach that affects you, we will notify you and regulators as required by law.
Report suspected vulnerabilities to hello@taskdboard.comwith the subject "Security report — task'd". Please do not file a public issue with exploit details.
12. International transfers
We and our processors may process information in the United States and other countries where they operate. Those countries may not provide the same legal protections as your home country. Where GDPR/UK GDPR requires a transfer mechanism (for example standard contractual clauses used by our processors), we rely on those processor terms.
13. Your rights (GDPR, UK GDPR, CCPA/CPRA)
Depending on where you live, you may have some or all of the following rights:
- Access a copy of personal data we hold about you
- Correct inaccurate data
- Delete data (including by deleting your account)
- Export data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Appeal a decision about a privacy request
- Lodge a complaint with a supervisory authority (for example your EEA DPA, the UK ICO, or the California Attorney General)
California (CCPA/CPRA)
In the last 12 months we have collected the categories described above (identifiers, customer records/billing ids, commercial information about your plan, internet/activity information, and user content). We collect them from you, from Google if you use Google sign-in, from Stripe if you pay, and automatically from your device.
We use them for the business purposes in How we use information. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information for inferring characteristics. We do not have actual knowledge that we sell or share the personal information of consumers under 16.
California residents may request know/access, delete, correct, and limit use of sensitive personal information, and may not be discriminated against for exercising these rights. You may use an authorized agent as permitted by law; we will need to verify you and the agent's authority.
Global Privacy Control
Because we do not sell or share personal information for cross-context behavioral advertising, we treat a Global Privacy Control (GPC) signal as already consistent with our practices. We still honor deletion and access requests.
14. Access, export, and deletion
Delete your account in the product: Account → Delete account. You will type a confirmation phrase and hold to confirm. That permanently deletes the auth user and cascaded board data. We then cancel any live Stripe subscription. Hashed trial claims and the Stripe cancellation ledger are retained as described above — they are not a copy of your tasks.
Export: Pro includes a JSON board export in the product. Regardless of plan, you can request a copy of the personal data we hold by emailing hello@taskdboard.com or using the contact formwith topic "Privacy / data request." We will verify the request (usually via the email on the account) and respond within the time required by applicable law (typically 30 days under GDPR, 45 days under CCPA, extendable as permitted).
We may decline a request that is unfounded, excessive, or that we cannot verify, or retain information we are legally required or permitted to keep (for example the trial hash that only prevents a second free trial).
Privacy requests: hello@taskdboard.com.
15. Children
task'd is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under 16 where that is the digital-consent age). If you believe a child has created an account, email hello@taskdboard.com and we will delete it.
17. Changes to this policy
We may update this policy as the product or the law changes. The "Last updated" date at the top will change. Material changes will be posted on this page; we may also email the address on your account when the change is significant. Continued use after the effective date means the updated policy applies.
18. Contact
Privacy, data-protection, and general questions: hello@taskdboard.com or task'd contact.
If you are in the EEA or UK and we have not resolved your concern, you may contact your local supervisory authority. We do not currently appoint a separate EU/UK representative; email is the right first step.