Privacy Policy
Last updated: October 7, 2026
This policy explains what personal data TaskDeck (“TaskDeck”, “we”, “us”) processes when you visit our website or use the TaskDeck service, why we do it, who we share it with, and the choices and rights you have.
1. Scope and roles
This policy covers:
- this website, web.taskdeck.app;
- the TaskDeck web app at www.taskdeck.app, including its installable (PWA) version;
- the KAI assistant, the TaskDeck MCP server used from Claude, and the Alerts API.
For your account data (for example your name and email) TaskDeck is the controller. For the content a workspace stores about its own clients and work (clients, projects, tasks, updates, attachments, time entries and reports), the workspace owner decides what is stored and why; for that content TaskDeck acts on the owner’s behalf, as a processor (“operador” under Brazil’s LGPD).
2. Data we collect
Account data
- Name, email address and password when you register. Passwords are handled by our authentication provider and are never stored by us in readable form.
- An optional profile picture.
- Your workspace memberships and role (Owner, Admin or Member), and invitations you send or receive (including the invitee’s email address).
Workspace content
- Clients and their details as entered by the workspace (for example names, contact, billing and address information), projects, tasks, checklists and task types.
- Task updates and their attachments (images, video, files and links).
- Time entries (start and end times, descriptions) and, where an owner enters them, member pay rates and billing rates.
- Reports and export files (HTML, PDF and CSV), and share links created for report attachments.
KAI (AI assistant)
- The text and images you send to KAI are transmitted to our AI provider to generate a response and a task draft. Images attached in the chat are kept only in your browser session and are not stored by us.
- When KAI creates a task, the workspace can save your original request (your text and images, not KAI’s replies) to the task as an update. This is on by default and can be turned off by the workspace owner in the app’s AI settings.
Claude (MCP) and the Alerts API
- If you connect Claude to TaskDeck, we record the OAuth authorization and process the requests Claude makes on your behalf (listing, searching, creating and updating tasks) within your permissions. What Claude does with the data it receives is governed by your agreement with Anthropic.
- Alerts sent to the Alerts API by your systems (title, description, details, source) are stored in your workspace. API keys are stored only as a cryptographic hash.
Notifications
- If you enable Web Push on a device, we store that device’s push subscription (endpoint and keys) and its browser user agent so we can deliver alert notifications.
Technical data
- Our hosting provider processes standard request data (such as IP address, browser user agent and timestamps) to serve the site and app and to keep them secure.
- The app uses Vercel Web Analytics to measure aggregate page views. It is designed to work without cookies. This marketing website does not use analytics.
3. Cookies and browser storage
- Essential cookies (app): authentication cookies keep you signed in. The app does not work without them, and they are not used for advertising.
- Local storage (app): preferences such as theme, the selected workspace, view and layout settings, and privacy mode.
- IndexedDB and service worker (app): a local queue of pending changes so your edits survive a flaky connection, plus a service worker that makes the app installable and delivers push notifications.
- This website: no cookies. It stores only your light/dark theme choice in local storage.
4. How we use data and legal bases
We use personal data only for the purposes below, relying on the corresponding legal bases under the LGPD (art. 7) and, where applicable, the GDPR (art. 6):
- Providing the service (accounts, workspaces, tasks, time tracking, reports, KAI, MCP, alerts): performance of a contract.
- Security, abuse prevention and service reliability: our legitimate interests.
- Transactional messages such as invitations and password resets: performance of a contract.
- Push notifications: your consent, given per device and revocable at any time in the app or your browser settings.
- Legal obligations and the exercise of rights in legal proceedings.
We do not sell personal data and do not use it for advertising.
5. Service providers
We rely on the following providers to run TaskDeck. Locations reflect our current configuration and may change; we will update this list when they do.
- Supabase — database and authentication, including password-reset emails (São Paulo, Brazil).
- Vercel — hosting, serverless functions (São Paulo, Brazil) and global content delivery; web analytics for the app.
- Amazon Web Services — file storage with Amazon S3 for avatars, attachments and report exports, and transactional email with Amazon SES for invitations (London, United Kingdom).
- OpenRouter — routes KAI requests to the AI model selected for your workspace and its model provider, which may process data in the United States or other countries.
- Browser push services (operated by your browser or device vendor) — deliver push notifications you enabled.
If you connect Claude through the MCP server, Anthropic receives the data returned to Claude under your own account and terms with Anthropic.
6. International transfers
Some providers store or process data outside your country, including in the United Kingdom and the United States. When data is transferred internationally we rely on the mechanisms permitted by applicable law, such as standard contractual clauses or equivalent safeguards offered by our providers (LGPD art. 33; GDPR chapter V).
7. Sharing
- Within your workspace: other members see content according to their role.
- Links you create: anyone holding a report attachment share link can download that file until the link expires or is revoked.
- Service providers listed above, only as needed to provide the service.
- Authorities when required by law, or to protect rights, safety and the integrity of the service.
- Business transfers: in a merger, acquisition or similar transaction, subject to this policy.
8. Retention
- Account data is kept while your account is active.
- Workspace content is kept until it is deleted by the workspace or the workspace is closed.
- Report export files are deleted automatically about 30 days after they are generated.
- KAI chat history lives only in your browser session; we keep only what is saved to a task as described above.
- After an account or workspace is closed we delete or anonymize its data within a reasonable period, except where we must keep it to comply with the law or to exercise rights in legal proceedings. Provider backups and logs expire on their own schedules.
9. Security
We protect data with encryption in transit (HTTPS), role-based access control, database row-level security, hashed API keys and short-lived signed URLs for files. No system is perfectly secure; if we become aware of a security incident that affects your data, we will notify you and the competent authorities as required by law.
10. Your rights
Under the LGPD (art. 18), and the GDPR where it applies, you may request:
- confirmation that we process your data, and access to it;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or unlawfully processed data;
- portability of your data to another provider;
- deletion of data processed with your consent, and withdrawal of that consent;
- information about who we share your data with;
- restriction of, or objection to, certain processing.
To exercise these rights, email support@taskdeck.app. We may need to confirm your identity first. If your request concerns content a workspace stores about you (for example as one of its clients), we will forward it to that workspace’s owner and assist them. You also have the right to complain to a data protection authority, such as Brazil’s ANPD or the authority where you live.
11. Children
TaskDeck is a business tool and is not directed to children. You must be at least 18 years old to create an account, and we do not knowingly collect data from children.
12. Changes to this policy
We may update this policy. The “Last updated” date above shows the latest version. If a change is material, we will let you know in the app or by email before it takes effect.
13. Contact
TaskDeck is responsible for this policy. For privacy questions or requests, including to reach our data protection contact (“encarregado” under the LGPD), email support@taskdeck.app.