Where the data lives
Tasks, notes, files and account data are stored in Firestore and Cloud Storage in Google Cloud's eur3 multi-region, which is located inside the European Union, and the application's server functions run in the europe-west1 region (Belgium). Google encrypts data at rest and in transit by default. The core service keeps its data in the EU; the few sub-processors outside it are named below and in the privacy policy, with the safeguards that apply.
What is collected, and why
To run an account Taskinger needs an email address and a display name; everything else is what you put in: tasks, notes, files, the members you invite. There are no advertising trackers, no third-party analytics scripts and no cookie banner, because the only client-side storage is what the app needs to work, described in the privacy policy's cookie and local storage section. The legal grounds for each purpose are listed in the policy, purpose by purpose.
Who else touches the data
Three categories of sub-processors, all listed with their roles in the privacy policy: Google (Firebase and Google Cloud) for hosting, database, storage, authentication and push notifications; RevenueCat and Stripe Payments Europe for subscriptions and card processing on paid plans, so that Taskinger never sees a card number; and, only when you switch it on yourself, the AI provider whose API key you bring: Anthropic, OpenAI or Google. Nothing is sent to an AI provider unless you press Analyze on a specific note.
Your rights, and how to use them
- Access and portability. Export your profile, personal tasks, notes and file list as JSON from the profile page at any time.
- Correction. Edit your profile and content directly in the app.
- Erasure. Delete the account from the app or by email; the account and its personal data are removed. Deleted tasks and notes spend thirty days in the bin first, so a mistake can be undone.
- Objection and complaint. Write to the contact in the privacy policy, or to the Bulgarian Commission for Personal Data Protection.
Business workbooks: Taskinger as processor
When a company uses a workbook for its own staff and clients, the company is the controller and Taskinger acts as processor under Article 28 GDPR. The privacy policy's section on business workspaces sets out those terms: processing only on the controller's instructions, confidentiality, the sub-processor list above, assistance with data subject requests and deletion at the end of the relationship. Workbook owners decide who is a member and what each member may see; the permission flags are enforced on the server, so the processor's technical measures match the controller's decisions.
Technical and organizational measures
- Deny-by-default security rules inside the database, so a member of one workbook has no technical way to read another, covered by an automated test suite on every change. How the isolation works.
- Two-factor authentication with an authenticator app; app lock with a PIN or biometrics on shared devices; App Check attestation on server calls.
- An activity trail that cannot be edited, and accountable deletion with a recorded reason.
- A published security contact at /.well-known/security.txt for responsible disclosure.
AI under the EU AI Act
The optional assistant that turns a meeting note into suggested tasks is off by default, runs only with your own API key, sends only the note you analyze plus the titles of open tasks in scope, and never writes into the workbook without your approval. Taskinger stores neither requests nor responses and trains nothing on your data. The AI statement documents this under Regulation (EU) 2024/1689.
Documents
Privacy policy · Terms of service · EULA · AI statement · security.txt. Bulgarian versions of every document are linked from each page. Questions from a data protection officer are welcome at valentin.k.kirilov@gmail.com.