Privacy Policy

Last updated: August 23, 2026

This policy explains how TaskGeniusAI collects, uses, shares, and protects information when you use our growth operations platform, our iOS app, our websites, and our support services. It applies to workspace operators, invited users, and people whose business records are processed through a customer workspace.

Information we process

  • Account and workspace data, such as names, email addresses, roles, and preferences.
  • Connected-source data, such as advertising, analytics, search, business profile, website, CRM, call, lead, job, revenue, and attribution records selected by a customer.
  • Content you submit, including prompts, feedback, playbooks, settings, approvals, and generated reports or recommendations.
  • Billing records from our payment processor. We do not store complete payment-card numbers.
  • Technical and security data, including device, browser, IP address, authentication, audit, integration, error, and performance events.

How we use information

We use information to provide and secure the service; sync connected data; generate dashboards, reports, and recommendations; execute customer-authorized actions; support users; process billing; detect abuse; improve reliability; and comply with law. We do not sell personal information or use customer business data to serve third-party ads.

AI processing and automated actions

Workspace data may be sent to configured AI providers to create analysis and recommendations. TaskGenius AI uses permission levels, feature flags, review controls, and audit logs around provider-changing actions. Customers remain responsible for reviewing recommendations and choosing their automation settings.

Connected services and Google user data

When you connect a provider, we use its credentials and selected data only to deliver the requested integration. You can disconnect an integration from the product. Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

The TaskGenius mobile app

Our iOS app is a second surface onto the same workspace, not a separate product. It signs in against the same account system and reads the same business data through our mobile API. Alongside the account and workspace data described above, the app collects two things a browser does not:

  • A push notification tokenissued by Expo for the specific device, so alerts you have turned on can reach that phone. The token is stored against your user, is revoked when you sign out or turn push off, and is deleted with your account. It is delivered through Expo's push service and Apple's Push Notification service.
  • Device and diagnostic signals — device model, OS version, app version, and error reports — used to keep the app working and to investigate crashes.

If you use Sign in with Apple, Apple may give us a private relay email address instead of your real one; we treat it exactly as we would any other account email. Your session token is held in the device keychain, and business data cached for offline reading stays inside the app's sandbox on your phone.

The app does not collectprecise location, browsing history, purchases made outside the app, health data, contacts, or photos. We do not sell personal information, we do not run third-party advertising, and we do not track you across other companies' apps or websites — so the app never asks for tracking permission.

You can delete your account from inside the appat any time — Business & settings → Account → Delete account. That permanently removes your login, profile, the workspaces you own and their data, your notification history, and your push tokens.

Service providers and disclosures

We disclose information only as needed to service providers that support hosting, database, authentication, AI, email, messaging, analytics, error monitoring, payments, and customer-selected integrations; to professional advisers; during a business transaction; or when required to protect rights, safety, and comply with law. Providers are permitted to process data only for the services they supply to us or the customer. The current vendor list and data-flow map is published at /subprocessors. Processing we do on a customer's instructions is described in the Data Processing Addendum.

Analytics and privacy choices

Optional product analytics and session-replay scripts load only after you accept them in the privacy choices banner. You can reopen Privacy choices at any time and withdraw consent. We also honor browser Global Privacy Control and Do Not Track signals by keeping optional analytics disabled. Details and a reopen control are on /cookies.

Retention and deletion

We keep information while an account is active and as needed for the purposes above. Normalized raw ingest payloads are purged after 180 days. Call transcripts and recording URLs are redacted after 180 days; the call and lead rows stay for attribution. Credentials are removed or disabled when an integration is disconnected. Operators can download a privacy export and delete their account from Profile. Deleting an account cancels Stripe billing for that operator when no shared workspace remains. We may retain limited records for legal, fraud-prevention, backup, and dispute-resolution needs.

Security and international processing

We use access controls, encryption in transit, secret storage, tenant authorization, database protections, audit logging, and operational monitoring. No system is perfectly secure. Information may be processed where we and our providers operate, subject to appropriate legal safeguards when required.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export personal information, and to withdraw consent. We may need to verify your identity and authority over the relevant workspace. You may also complain to your local data-protection authority.

California privacy rights

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as the California Consumer Privacy Act uses those words. We have not done so in the preceding twelve months, and we do not knowingly do either with the personal information of anyone under sixteen. There is consequently nothing to opt out of, but we honour Global Privacy Control signals regardless by keeping optional analytics off.

California residents may request access to the categories and specific pieces of personal information we hold, request correction or deletion, and ask how it was collected, why, and with whom it was disclosed. Exercising these rights will never cost you a different price or a worse service. Make a request from /support; we will verify your identity, and your authorised agent may act for you with written permission.

Where a business uses TaskGenius to process records about its own customers, that business is the party those people deal with, and we act on its instructions under the Data Processing Addendum. A request we receive about those records is passed to the business it belongs to.

Children and policy changes

The service is for business users and is not directed to children under 13. We may update this policy as the service or law changes. Material changes will be identified by a new update date and, when appropriate, an in-product notice.

Contact

Privacy questions and requests can be sent from /support or taskgeniusai@gmail.com. Vulnerability reports go to the security policy.