Privacy Policy
Effective October 5, 2026
Taskr.dev (www.taskr.dev) is a task manager. This policy explains what information Taskr.dev collects, how it's used and shared, and the choices you have. Questions go to support@taskr.dev.
What we collect
- From Google, when you sign in with Google: your Google account's unique ID, your email address, whether Google has verified that email, and your name. Taskr.dev only asks Google for basic sign-in information (the "openid", "email" and "profile" permissions). It can't see your Gmail, Drive, Calendar, contacts or anything else in your Google account.
- From Microsoft, when you sign in with Microsoft: the unique ID Microsoft gives your account for Taskr.dev, your email address if your account has one, and your name. Taskr.dev only asks Microsoft for the same basic sign-in information. It can't see your Outlook mail, OneDrive, Teams, calendar or anything else in your Microsoft account.
- From Apple, when you sign in with Apple: the unique ID Apple gives your account for Taskr.dev, your email address, whether Apple has verified it, and, the first time you sign in, your name. If you choose Apple's Hide My Email, Taskr.dev gets a private relay address that forwards to you instead of your real one. Taskr.dev only asks Apple for your name and email. It can't see your iCloud data, photos, messages or anything else in your Apple Account.
- From GitHub, when you sign in with GitHub: your GitHub account's unique ID, your username, the name on your profile, and your primary email address if GitHub has verified it. Taskr.dev only asks GitHub to read your email addresses (the "user:email" permission); your ID, username and name are public on your profile anyway. It can't see your repositories, code, organizations or anything else in your GitHub account.
- What you put into Taskr.dev: your tasks (titles, descriptions, estimates, deadlines, priority and whether they're done), comments, your display name, and the names of organizations you create.
- Organizations: which organizations you belong to, whether you're an admin, and the invite links admins create.
- Sign-in records: identifiers for the devices you're signed in on, and any agent tokens you create for AI agents or scripts. Agent tokens are stored only in hashed form, with the name you gave them and when they were created and last used.
- AI apps you connect: when you connect an AI app such as Claude or ChatGPT, which app it is (the name and address it gives), the organization or Personal you chose for it, and when it was connected and last used. Its access and refresh tokens are stored only in hashed form. Taskr.dev doesn't receive your conversations with the app, only the requests it makes to Taskr.dev on your behalf.
- Billing, for organizations: Stripe handles payments. Taskr.dev records the organization's Stripe customer and subscription IDs, its billing status, and whether payment details are on file. It never sees card or bank details. When an admin adds payment details, Taskr.dev gives Stripe that admin's email address.
- Search index: the words in your open tasks, so you can search them.
- Technical information: our servers log the requests your browser or agent makes: your IP address, browser details, when, which page or part of the API it was for, and whether it worked. The logs don't record what you send or receive, such as the text of your tasks, what you search for, invite links or sign-in details. To limit abuse, Taskr.dev also counts AI apps' requests per connection, and app registrations per IP address; addresses are counted only as a keyed hash, and the counts are deleted within days.
How we use it
We use this information to run Taskr.dev: to sign you in, store and show your tasks, share them with your organization, make search work, keep the service secure, fix problems, and answer you when you contact us. We don't sell your information, we don't use it for advertising, and we don't build profiles of you.
Who can see your information
- You. Tasks in Personal are visible only to you.
- Your organizations. Taskr.dev is built for teams: members of an organization can see and reorder each other's tasks in that organization, and see each other's display names. Admins can invite and remove members and delete the organization. If you leave or are removed from an organization, your tasks in it stay with the organization.
- Agents and AI apps you authorize. An agent token, or an AI app you connect (such as Claude or ChatGPT), acts as you in the one organization, or Personal, you chose for it: it can read and change your tasks there, and what it reads goes to that app and its provider, under their own terms and privacy policy. It can't change organizations or their members, make tokens, sign you out or delete your account. It works until you revoke the token or disconnect the app, or sign out.
- Service providers. Taskr.dev is hosted on Amazon Web Services, which stores our data and runs our servers. Google, Microsoft, Apple and GitHub handle sign-in with their accounts. Stripe handles organizations' payments. Taskr.dev's pages use Google Fonts, so your browser fetches fonts from Google, which sees your IP address. These providers handle data only to provide their services to us.
- When the law requires it. We may disclose information if required to by law, or to protect Taskr.dev's users or the service from harm.
Information from Google
Taskr.dev's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use the information Google provides only to create and identify your Taskr.dev account and to show your name and email address in Taskr.dev. We don't transfer it to anyone except as needed to run Taskr.dev, to comply with the law, or as part of a merger or acquisition of Taskr.dev. No person reads it except when needed for security, to comply with the law, or with your permission to help you. You can remove Taskr.dev's access at any time from your Google account's third-party connections. That stops future sign-ins with Google but doesn't delete your Taskr.dev data (see below).
Cookies
Taskr.dev uses a cookie to keep you signed in, and a short-lived cookie that protects signing in with Google, Microsoft, Apple or GitHub while it's in progress. We don't use advertising, analytics or tracking cookies.
How long we keep it
We keep your account and tasks while your account exists. Signing out ends every session on every device, revokes all your agent tokens and disconnects all your AI apps. When you delete your account, we delete it along with your Personal tasks, sessions, agent tokens and connected apps. Your tasks in organizations stay with the organization, handed to an admin as when you leave, and comments you wrote on them stay, shown as "Deleted user". When an organization is deleted, we keep a backup of it so it can be restored if it was deleted by mistake; ask us and we'll delete the backup. If an organization's bill goes unpaid, the organization becomes read-only until it's paid; nothing is deleted for non-payment. Server logs are kept only as long as we need them to run and troubleshoot the service.
Your choices
- You can change your display name, create and revoke agent tokens, disconnect AI apps, and delete your account, on your profile page.
- If you sign in with Apple, you can stop using it with Taskr.dev from the Sign in with Apple settings of your Apple Account. Like removing Google's access, that stops future sign-ins but doesn't delete your Taskr.dev data. Deleting your Taskr.dev account also ends Taskr.dev's access to your Apple Account.
- If you sign in with GitHub, you can remove Taskr.dev's access from Authorized OAuth Apps in your GitHub settings. That too stops future sign-ins but doesn't delete your Taskr.dev data.
- To get a copy of your information, or to have anything deleted that deleting your account keeps, email support@taskr.dev.
Security
Taskr.dev is served only over HTTPS, agent tokens and AI apps' tokens are stored only as hashes, and access to our systems is limited. No service can promise perfect security, but we work to protect your information.
Children
Taskr.dev isn't meant for children under 13, and we don't knowingly collect information from them. If you think a child has given us information, contact us and we'll delete it.
Changes to this policy
If we change this policy, we'll post the new version here with a new effective date, and let you know on the site if the change is significant.
Contact
Email support@taskr.dev.