← Back to TaskivePrivacy Policy
Last updated: July 4, 2026 | Version: 1.1 | Draft — pending legal review before commercial launch
1. Introduction
Taskive is operated by [Your Name/Entity] (“we”, “us”, “our”). This policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.
2. Data We Collect
- Profile data: name, email address, avatar image, timezone
- Task and project data: titles, descriptions, status, assignments, due dates, comments
- Knowledge base data: context entries you add to your personal or team knowledge base (stored as text and vector embeddings)
- AI usage data: model name, token counts, cost (USD) — prompt and response content is not stored by Taskive, though it is processed by AI sub-processors (see Section 4)
- Technical data: IP address (used for rate limiting; not stored long-term), session tokens
- GitHub data: GitHub username (if you connect your account), pull request links
3. How We Use Your Data
- Providing and operating the task management service
- AI-powered features: risk scoring, burnout signal detection, focus mode, task extraction, and knowledge base semantic search — processed using task metadata and knowledge base content via AI sub-processors. Prompt and response content is not stored by Taskive after processing.
- Security and fraud prevention (rate limiting, row-level security isolation)
- Sending transactional emails: account invitations, password resets, email change verification, and notification emails via MailerSend (see Section 4)
- Service improvement and performance monitoring
4. Data Processors
We use the following sub-processors to operate Taskive:
| Processor | Purpose | Location | Safeguards |
|---|
| Railway (Railway Corp.) | Backend application hosting and PostgreSQL database — runs the Taskive API server and stores all application data including user profiles, tasks, projects, and knowledge base entries | US | Standard Contractual Clauses |
| Cloudflare R2 | File and attachment storage (uploaded documents and images) | US / Global edge | EU–US Data Privacy Framework |
| Vercel Inc. | Frontend application hosting | US / Global edge | Standard Contractual Clauses |
| OpenAI (via LiteLLM) | AI features: risk scoring, burnout signal detection, focus mode ranking, task extraction, and knowledge base semantic search. The AI model used may vary by organization configuration (e.g. GPT-4o, Claude, Gemini). Prompt content is processed but not used to train models under standard API terms. | US | OpenAI Data Processing Addendum; no training on your data by default |
| MailerSend | Transactional email — account invitations, password resets, email change verification, and notification emails. Only your email address and name are passed to MailerSend. | EU / US | Standard Contractual Clauses; GDPR-compliant |
4a. Cookies & Analytics
We use essential cookies to keep you signed in and secure, and — only with your consent — Google Analytics 4 to measure aggregate, pseudonymous usage. On your first visit a banner lets you accept or decline analytics cookies; until you accept, Google Consent Mode keeps all analytics and advertising storage disabled. We do not use advertising or cross-site tracking cookies. For the full list of cookies, retention periods, and how to change your choice, see our Cookie Policy.
5. Data Retention
- Active accounts: data retained while your account is active
- Deleted accounts: your profile information (name, email, avatar) is anonymized immediately when you delete your account; task and project data is preserved with anonymized attribution for org continuity
- AI usage logs: retained for 90 days, then automatically purged
- Session tokens: expire after 30 days of inactivity
- Beta note: during the beta period, data may be reset with reasonable advance notice due to schema migrations or infrastructure changes. See our Terms of Service.
6. Your Rights
Under GDPR Articles 15–22, you have the following rights:
- Right of access (Art. 15): Download all your personal data — profile, tasks assigned to you, comments you wrote, and AI usage logs — via Settings → Account → Download my data. This generates a JSON file via the
GET /api/v1/users/me/export endpoint, which explicitly excludes your password hash. - Right to erasure (Art. 17): Delete your account via Settings → Account → Delete Account. This anonymizes your profile PII immediately (email, name, avatar) and invalidates all active sessions. Requires password confirmation. Note: accounts created via Google or GitHub OAuth (without a password set) currently cannot use this self-service deletion flow — please contact us at coms@taskive.ai to request manual erasure.
- Right to data portability (Art. 20): Export your data as JSON via the download feature above (Settings → Account → Download my data)
- Right to rectification (Art. 16): Update your profile via Settings → Profile
- Right to object (Art. 21): Contact us at the address below
7. Contact & DSAR Requests
To exercise your rights or submit a Data Subject Access Request (DSAR), contact us at: coms@taskive.ai
We will respond within 30 days as required by GDPR Article 12.
Last updated: July 4, 2026 | Version: 1.1 | Beta draft — subject to change. Pending legal review before commercial launch. Operator name and jurisdiction placeholders must be completed before launch.