Truetask — Privacy Policy
Last Updated: 2026/06/11
Effective Date: 2026/06/11
1. Introduction
This Privacy Policy describes how Truetask ("the Company," "we," "us," or "our") collects, uses, stores, and protects information when you use our services: hosted Truetask cloud workspaces provisioned under truetask.app or another domain we assign ("Cloud Workspaces"), the website at truetask.io, the Client Portal at portal.truetask.dev, the documentation sites at docs.truetask.io and setup.truetask.io, and the demo instance at demo.truetask.io (collectively, the "Services").
Truetask is available in two deployment models, and they have very different privacy properties. This Policy explains both.
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Key Principle — Two Deployment Models
2.1. Self-hosted: we collect zero data. When you deploy Truetask on your own infrastructure, we collect no data from your instance. The application makes no outbound calls to our servers; there is no telemetry, no usage analytics, no crash reporting, and no phone-home behavior of any kind. License verification runs entirely on your own server. All data in a self-hosted instance stays on your infrastructure, and you are the sole controller of it.
2.2. Cloud Workspaces: we host your data, and only to serve you. When you use a Cloud Workspace, we operate a dedicated, isolated instance for you and store your workspace data in the hosting region you select (currently the United States or the European Union). We host and process that data solely to provide the service. We do not sell it, do not use it for advertising, do not use it to train machine-learning models, and the application itself contains no third-party trackers.
3. Information We Collect
3.1. Cloud Workspaces
When you create and use a Cloud Workspace, we collect and store:
- Signup information: your name, email address, chosen workspace name and address (subdomain), and hosting region.
- Workspace content ("Customer Content"): the data you and your members put into the workspace, including tasks, projects, notes, files, comments, forms and form submissions, time entries, automations, and audit logs. We store this content in your selected region in order to run your workspace; it remains yours (see Section 5).
- Member account data: names, email addresses, and authentication data of users invited to the workspace. Passwords, where used, are stored in hashed form only; sign-in is primarily via one-time email links.
- Technical and security logs: IP addresses, request metadata, and security events, used for operating, securing, and troubleshooting the platform.
- Push notification tokens: if you enable browser notifications, we store the subscription token needed to deliver them.
- Billing data: for paid plans, subscription and seat records. Payment transactions are processed by Stripe; we do not store full card details (see Section 6).
3.2. Client Portal (portal.truetask.dev)
When you create an account on the Client Portal, we collect your name, email address, optionally your company name, hashed authentication data, license and purchase history, partial payment identifiers (such as the last four digits of a card) with transaction records, and IP addresses for security and fraud prevention.
3.3. Marketing Site (truetask.io)
- The marketing site uses self-hosted, cookie-free analytics (Umami, running on our own infrastructure at umami.truetask.io). It collects aggregated, anonymized usage statistics such as page views, referrers, and approximate location derived from IP. It sets no cookies, stores no personal profiles, and shares nothing with third-party analytics or advertising companies.
- If you use the workspace signup form, we collect the information described in Section 3.1.
3.4. Documentation Sites (docs.truetask.io, setup.truetask.io)
These are documentation sites. We do not collect personal information through them.
3.5. Demo Instance (demo.truetask.io)
The demo uses shared access and its contents are reset periodically. Do not enter personal, confidential, or sensitive information into the demo.
3.6. Self-Hosted Instances
We collect no data whatsoever from your self-hosted deployment. See Section 2.1.
4. How We Use Information
4.1. Providing the Services — operating your Cloud Workspace, hosting Customer Content, delivering notifications and transactional email (such as sign-in links and digests), and maintaining the Client Portal.
4.2. Account and subscription management — authentication, billing, license issuance, and plan enforcement.
4.3. AI features — when you invoke managed AI features, processing the relevant content to generate the requested output (see Section 6.3).
4.4. Product communications — service announcements, security notices, and release information relevant to your account.
4.5. Security — detecting and preventing unauthorized access, fraud, and abuse.
4.6. Legal compliance — complying with applicable laws, regulations, and legal process.
4.7. We do not sell or rent personal information, and we do not share it with third parties for their marketing purposes.
5. Customer Content: Ownership and Access
5.1. You own your Customer Content. We host and process it for Cloud Workspaces solely to provide, secure, and improve the operation of your workspace, and as instructed by you.
5.2. Our personnel do not access Customer Content except (a) with your permission for support purposes, (b) as necessary to maintain or secure the Services, or (c) where required by law.
5.3. A full export of your workspace (JSON for workspace data, Markdown for notes) is available at any time, on every plan, from within the application.
5.4. Free workspaces that go inactive are hibernated, not deleted. Hibernation does not alter Customer Content.
6. Third-Party Processors
We use a limited number of third-party providers to operate the Services:
6.1. Infrastructure providers — Cloud Workspaces run on infrastructure provided by data-center operators in the United States and the European Union, corresponding to the region you select. These providers supply compute and network infrastructure; they do not access Customer Content for their own purposes.
6.2. Stripe — payment processing for subscriptions and licenses, in accordance with Stripe's privacy policy (https://stripe.com/privacy). We do not store full payment card details.
6.3. AI infrastructure providers — when you use managed AI features ("Truetask AI"), the relevant content of your request is transmitted to third-party AI model providers acting on our behalf, solely to generate the response. We do not permit the use of your content for their model training under our agreements with them. If you connect your own AI provider (bring-your-own-key or a self-hosted model), that traffic flows under your agreement with that provider, not ours. Self-hosted deployments make no AI calls through us at all.
6.4. Email delivery — transactional email (sign-in links, invitations, notifications, digests) is delivered through an email delivery provider processing recipient addresses and message content for delivery purposes only.
6.5. Cloudflare — DNS and CDN services for the marketing site, which may process technical data such as IP addresses in accordance with its privacy policy (https://www.cloudflare.com/privacypolicy/).
6.6. We do not use third-party advertising or tracking services anywhere in the Services.
7. Cookies
7.1. Marketing site (truetask.io): no cookies. Analytics are cookie-free (see Section 3.3).
7.2. Cloud Workspaces and Client Portal: essential cookies and tokens are used solely for authentication and session management. These are required for the Services to function and do not require consent under applicable privacy regulations (including the GDPR).
7.3. We do not use cookies for advertising, tracking, or cross-site purposes on any of our Services.
8. Data Storage and Security
8.1. Cloud Workspace content is stored in the hosting region you select at workspace creation (currently the United States or the European Union) and stays there. Each workspace runs as an isolated instance with its own database and file storage. Limited account, billing, and operational metadata is processed in the United States.
8.2. Client Portal data is stored on servers located in the United States.
8.3. We implement appropriate technical and organizational measures to protect information, including encryption in transit (TLS/HTTPS), encryption of sensitive settings at rest, hashed password storage, per-workspace isolation, access controls, and tamper-evident audit logging.
8.4. No method of transmission or storage is completely secure; we cannot guarantee absolute security. Suspected vulnerabilities can be reported to [email protected].
9. Data Retention and Deletion
9.1. We retain account data and Customer Content for as long as your account or workspace is active.
9.2. When a Cloud Workspace is terminated or you request its deletion, Customer Content remains exportable for at least thirty (30) days (except where the law requires otherwise), after which it is scheduled for deletion from production systems, with residual copies removed from backups in the ordinary course of backup rotation.
9.3. If you request deletion of your account, we will delete associated personal data within thirty (30) days, subject to legal obligations requiring retention of certain records.
9.4. Transaction records and license purchase history may be retained for accounting and legal compliance even after deletion, in anonymized or aggregated form where possible.
10. Your Rights
You have the following rights regarding your personal information:
10.1. Right of Access
You may request a copy of the personal data we hold about you by contacting [email protected].
10.2. Right to Rectification
You may update your information in the application or Client Portal at any time, or contact us to correct inaccurate data.
10.3. Right to Erasure
You may request deletion of your account, workspace, and associated personal data. We will process the request within thirty (30) days, subject to Section 9.
10.4. Right to Data Portability
Workspace exports are self-serve (Section 5.3). You may additionally request an export of your Client Portal data in a machine-readable format.
10.5. Right to Object
You may object to certain processing of your data. Where we process data based on legitimate interests, we will cease processing upon your objection unless we have compelling legitimate grounds.
10.6. Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at [email protected].
11. GDPR Roles
11.1. For account, billing, and marketing-site data, the Company acts as the data controller.
11.2. For Customer Content in Cloud Workspaces, you (the workspace owner or your organization) are the data controller, and the Company acts as a data processor, processing Customer Content on your documented instructions as described in this Policy and the Terms of Service. Contact us at [email protected] regarding data processing agreements.
11.3. For self-hosted instances, you are the sole controller and we are not a processor: we do not process, access, or store any data from your deployment, and you are responsible for your own compliance with respect to it.
11.4. Our legal bases for processing include performance of a contract (providing the Services), legitimate interests (security, fraud prevention, service communications), and compliance with legal obligations.
12. International Data Transfers
12.1. Cloud Workspace content stays in the region you select (Section 8.1). Account, billing, and operational metadata may be transferred to and processed in the United States.
12.2. Where personal data of individuals in the European Economic Area is transferred internationally, we rely on appropriate safeguards, including standard contractual clauses where applicable.
13. Children's Privacy
13.1. The Services are intended for business use and are not directed at individuals under the age of eighteen (18).
13.2. We do not knowingly collect personal information from anyone under eighteen (18). If we become aware that we have, we will take steps to delete such data promptly.
14. California Privacy Rights (CCPA)
14.1. If you are a California resident, you have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share personal information.
14.2. You have the right to request deletion of your personal information, subject to certain exceptions.
14.3. We do not sell personal information, and we do not use or disclose sensitive personal information for purposes other than those permitted under the CCPA.
14.4. To exercise your rights under the CCPA, contact us at [email protected].
15. Changes to This Privacy Policy
15.1. We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Services at least thirty (30) days before the changes take effect.
15.2. The "Last Updated" date at the top of this policy indicates when the most recent changes were made.
15.3. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
TruetaskMiami, Florida, USA
Email: [email protected]
Security reports: [email protected]
Website: https://truetask.io