GDPR-compliant task management, hosted in the EU

Taskinger is operated by Vivan Health Projects Ltd., a company registered in Sofia, Bulgaria, and every account's data lives in Google Cloud's European region. This page collects the facts a privacy-conscious person or a company's data protection officer needs, in one place, with links to the full legal documents.

Last updated: 3 September 2026

Where the data lives

Tasks, notes, files and account data are stored in Firestore and Cloud Storage in Google Cloud's eur3 multi-region, which is located inside the European Union, and the application's server functions run in the europe-west1 region (Belgium). Google encrypts data at rest and in transit by default. The core service keeps its data in the EU; the few sub-processors outside it are named below and in the privacy policy, with the safeguards that apply.

What is collected, and why

To run an account Taskinger needs an email address and a display name; everything else is what you put in: tasks, notes, files, the members you invite. There are no advertising trackers, no third-party analytics scripts and no cookie banner, because the only client-side storage is what the app needs to work, described in the privacy policy's cookie and local storage section. The legal grounds for each purpose are listed in the policy, purpose by purpose.

Who else touches the data

Three categories of sub-processors, all listed with their roles in the privacy policy: Google (Firebase and Google Cloud) for hosting, database, storage, authentication and push notifications; RevenueCat and Stripe Payments Europe for subscriptions and card processing on paid plans, so that Taskinger never sees a card number; and, only when you switch it on yourself, the AI provider whose API key you bring: Anthropic, OpenAI or Google. Nothing is sent to an AI provider unless you press Analyze on a specific note.

Your rights, and how to use them

Business workbooks: Taskinger as processor

When a company uses a workbook for its own staff and clients, the company is the controller and Taskinger acts as processor under Article 28 GDPR. The privacy policy's section on business workspaces sets out those terms: processing only on the controller's instructions, confidentiality, the sub-processor list above, assistance with data subject requests and deletion at the end of the relationship. Workbook owners decide who is a member and what each member may see; the permission flags are enforced on the server, so the processor's technical measures match the controller's decisions.

Technical and organizational measures

AI under the EU AI Act

The optional assistant that turns a meeting note into suggested tasks is off by default, runs only with your own API key, sends only the note you analyze plus the titles of open tasks in scope, and never writes into the workbook without your approval. Taskinger stores neither requests nor responses and trains nothing on your data. The AI statement documents this under Regulation (EU) 2024/1689.

Documents

Privacy policy · Terms of service · EULA · AI statement · security.txt. Bulgarian versions of every document are linked from each page. Questions from a data protection officer are welcome at valentin.k.kirilov@gmail.com.

EU-hosted from the first task.

Start free