task'd

Legal

Privacy Policy

Last updated August 18, 2026

This Privacy Policy explains how task'd ("task'd," "we," "us") collects, uses, shares, and retains personal information when you visit our websites, create an account, or use the product.

We wrote it to match how the product actually works — including Google sign-in, Stripe billing, Supabase hosting, and account deletion — so you can make an informed choice. If anything here is unclear, email hello@taskdboard.com or use the contact page.

1. Who we are

task'd is a personal task board operated by the developer of the service doing business as task'd. For the current operator identity and a mailing address, email hello@taskdboard.com.

For GDPR and UK GDPR, the operator of task'd is the data controller of personal data processed to provide the service. Processors we use are listed in How we share information.

2. Scope

This policy applies to:

  • taskdboard.com (and taskdboard.vercel.app as a predecessor / preview host)
  • The web app, including the installable PWA
  • Accounts, billing, support, and related communications
  • Public share-card pages you choose to create

It does not apply to third-party sites we link to (Google, Stripe Checkout, processor privacy pages) — those have their own policies.

3. Information we collect

Account and identity

When you sign up with email and password or continue with Google, we store an authentication record and a profile. That typically includes:

  • Email address
  • Display name (and, for Google, the name Google provides)
  • Password hash if you use email sign-in (we never store the plaintext password)
  • Profile photo URL if Google provides one
  • Preferences such as theme, accent, board sort, meeting day, and onboarding state
  • A unique referral code if you use invites

Content you create

Boards, tasks, descriptions, people fields, comments/updates, timers, meeting notes, recap history, streaks/XP, categories, and similar board data are stored so the product can sync across your devices. This is your content. You decide what to put in it.

Billing

If you start a paid plan, we store Stripe customer and subscription identifiers, plan tier (free / pro / lifetime), status, and current period end. We do not receive or store full card numbers, CVC, or bank account numbers — Stripe does.

Trial-abuse prevention

First-time accounts receive a 14-day no-card Pro trial. To stop repeat trials after delete-and-re-signup, we store a one-way hash of your email and of an anonymous browser identifier. Those hashes are not tied to your user id and survive account deletion. They are not used for advertising.

Referrals

If you arrive on an invite link, we store the referral code in a cookie and, if you sign up, a referral record linking referrer and referee (status, timestamps). That is how a gifted Pro month is attributed.

Device, logs, and security

We and our processors may process IP address, user-agent, timestamps, approximate location derived from IP, and request paths to operate the site, debug errors, and rate-limit abuse. Error reports sent to Sentry are configured not to send default PII; they may still include a stack trace and the URL of the failing request.

Information we do not collect

  • We do not run advertising pixels or sell lists
  • We do not ask for government ID, date of birth, or payment card PAN
  • We do not use your Google account to read Gmail, Drive, or contacts — sign-in only
  • We do not train public AI models on your boards or notes

4. Google account data

If you choose Continue with Google, Google authenticates you and shares the basic profile needed to create a task'd account. In practice that is:

  • Email address
  • Name
  • Profile photo (if your Google account has one)
  • A stable Google user identifier used for sign-in

We use that information only to create and authenticate your account, show your name/initials in the product, and email you about the account (for example security notices). We do not use Google user data for ads, scoring, or resale.

task'd's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Google sign-in by deleting your task'd account (Account → Delete account) and, separately, by removing task'd from your Google Account permissions at myaccount.google.com/permissions.

5. How we use information

We use personal information to:

  • Provide, sync, and secure the product
  • Create and authenticate accounts (email or Google)
  • Send transactional mail (confirm signup, reset password, security notices)
  • Process subscriptions, trials, Founder Pro, and invoices via Stripe
  • Prevent fraud, trial abuse, spam, and attacks
  • Measure aggregate product usage (Vercel Analytics)
  • Diagnose crashes and errors (Sentry)
  • Attribute referrals you choose to share
  • Respond to support, privacy, and legal requests
  • Comply with law and enforce our Terms

Legal bases (GDPR / UK GDPR)

Where those laws apply, we rely on:

  • Contract — to provide the account, board, and paid features you request
  • Legitimate interests — security, trial-abuse prevention, aggregate analytics, product improvement, and keeping the service reliable. You may object; see Your rights
  • Consent — where we ask for it, or where a non-essential cookie requires it. You can withdraw consent anytime
  • Legal obligation — tax, accounting, and responding to lawful requests

6. How we share information

We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose it only as follows:

  • Processors who host or help run the product, under contracts that limit their use of the data
  • You, when you export a board, copy a share card, or send a public share link (share cards contain streak/completion stats you choose to share — not your task titles)
  • Legal and safety — if required by law, to protect rights, or to prevent harm or abuse
  • Business transfer — if we merge, sell, or reorganize, information may transfer under this policy or a successor notice
ProcessorRoleTypical dataPrivacy
SupabaseAuth, Postgres, realtime syncAccount, profile, boards, tasks, notes, billing idsPolicy
StripePayments, Customer Portal, invoicesEmail, customer/subscription ids, payment method (held by Stripe)Policy
VercelHosting, CDN, Web AnalyticsRequest logs, coarse usage metricsPolicy
SentryError monitoringStack traces, request URL, limited diagnosticsPolicy
UpstashRate limitingIP and user-id keys (not board content)Policy
GoogleOptional sign-inEmail, name, photo, Google user idPolicy

Auth and product emails may be delivered by Supabase and/or a configured SMTP provider. Those providers process the recipient address and message content of the email.

7. Cookies and similar technologies

We use cookies, local storage, and a first-party visitor id so the app works, stays signed in, and so a deleted account cannot farm a second free trial from the same browser. We do not use advertising cookies.

NameTypePurposeLife
Supabase auth (sb-*)HttpOnly cookieKeep you signed inSession / refresh window
td_vidHttpOnly cookieAnonymous visitor id for trial-abuse prevention400 days
td_fpCookie + localStorageMirror of the visitor id so Google OAuth / signup still send it400 days
td_refHttpOnly cookieFirst-touch invite code30 days
taskd-viewportCookieRemember desktop vs phone layout1 year
taskd_board_idHttpOnly cookieLast board you had open1 year

The app also stores small preferences in localStorage on your device (sound, last view, tour, share-prompt, card peek, mobile column). Clearing site data removes them. The PWA service worker may cache the app shell for offline-ish loads; it is not used to track you across other sites.

Stripe Checkout and Google's sign-in screens are third-party pages and may set their own cookies according to their policies.

8. Analytics

We use Vercel Web Analytics for privacy-oriented page-view and performance metrics. It is designed to work without advertising cookies and without identifying you across unrelated sites. We use it to understand which marketing pages are useful and whether the app is healthy — not to build a sales profile.

We do not use Google Analytics, Meta Pixel, or similar ad trackers.

9. Payments

Paid plans are processed by Stripe. When you check out or open the customer portal, you provide payment details to Stripe. We store the resulting customer id, subscription id, tier, and status in Supabase so the app can unlock Pro features.

If you delete your account, we attempt to cancel any live Stripe subscription first and keep a cancellation ledger (subscription id, outcome, timestamps) so we can finish that cancellation if the first attempt fails. That ledger is not your board content.

10. How long we keep information

  • Account and board content — until you delete the account or the specific content. Deleting the auth user cascades boards, tasks, notes, comments, activity, series, profile, and the subscription row.
  • Trial hashes — kept after deletion so a new signup from the same email or browser does not receive another no-card trial. They are not a backup of your tasks.
  • Stripe cancellation records — kept as needed to finish canceling billing and for accounting/security.
  • Share-card links — encoded stats expire (currently 90 days). Anyone with the link can view it until then.
  • Logs and error reports— kept for a short operational window, then dropped by the processor's retention settings.
  • Backups — infrastructure backups may lag live deletion by a limited period, then age out.

11. Security

We use HTTPS, hashed passwords (via Supabase Auth), row-level security so one account cannot read another's boards, and rate limiting on auth and expensive actions. No method of transmission or storage is 100% secure. If we learn of a breach that affects you, we will notify you and regulators as required by law.

Report suspected vulnerabilities to hello@taskdboard.comwith the subject "Security report — task'd". Please do not file a public issue with exploit details.

12. International transfers

We and our processors may process information in the United States and other countries where they operate. Those countries may not provide the same legal protections as your home country. Where GDPR/UK GDPR requires a transfer mechanism (for example standard contractual clauses used by our processors), we rely on those processor terms.

13. Your rights (GDPR, UK GDPR, CCPA/CPRA)

Depending on where you live, you may have some or all of the following rights:

  • Access a copy of personal data we hold about you
  • Correct inaccurate data
  • Delete data (including by deleting your account)
  • Export data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based
  • Appeal a decision about a privacy request
  • Lodge a complaint with a supervisory authority (for example your EEA DPA, the UK ICO, or the California Attorney General)

California (CCPA/CPRA)

In the last 12 months we have collected the categories described above (identifiers, customer records/billing ids, commercial information about your plan, internet/activity information, and user content). We collect them from you, from Google if you use Google sign-in, from Stripe if you pay, and automatically from your device.

We use them for the business purposes in How we use information. We do not sell personal information and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information for inferring characteristics. We do not have actual knowledge that we sell or share the personal information of consumers under 16.

California residents may request know/access, delete, correct, and limit use of sensitive personal information, and may not be discriminated against for exercising these rights. You may use an authorized agent as permitted by law; we will need to verify you and the agent's authority.

Global Privacy Control

Because we do not sell or share personal information for cross-context behavioral advertising, we treat a Global Privacy Control (GPC) signal as already consistent with our practices. We still honor deletion and access requests.

14. Access, export, and deletion

Delete your account in the product: Account → Delete account. You will type a confirmation phrase and hold to confirm. That permanently deletes the auth user and cascaded board data. We then cancel any live Stripe subscription. Hashed trial claims and the Stripe cancellation ledger are retained as described above — they are not a copy of your tasks.

Export: Pro includes a JSON board export in the product. Regardless of plan, you can request a copy of the personal data we hold by emailing hello@taskdboard.com or using the contact formwith topic "Privacy / data request." We will verify the request (usually via the email on the account) and respond within the time required by applicable law (typically 30 days under GDPR, 45 days under CCPA, extendable as permitted).

We may decline a request that is unfounded, excessive, or that we cannot verify, or retain information we are legally required or permitted to keep (for example the trial hash that only prevents a second free trial).

Privacy requests: hello@taskdboard.com.

15. Children

task'd is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under 16 where that is the digital-consent age). If you believe a child has created an account, email hello@taskdboard.com and we will delete it.

16. Share cards and other people

Optional share cards encode win stats (for example a streak or tasks finished today) in a signed link. They are meant to be shared by you. Anyone with the URL can view the card until it expires. Do not post a link you want to keep private.

If you type other people's names or notes into a task, you are responsible for having any permission you need. We process that content only to host it for you.

17. Changes to this policy

We may update this policy as the product or the law changes. The "Last updated" date at the top will change. Material changes will be posted on this page; we may also email the address on your account when the change is significant. Continued use after the effective date means the updated policy applies.

18. Contact

Privacy, data-protection, and general questions: hello@taskdboard.com or task'd contact.

If you are in the EEA or UK and we have not resolved your concern, you may contact your local supervisory authority. We do not currently appoint a separate EU/UK representative; email is the right first step.