Privacy
Version 1.0 — effective 10/03/2026. This page describes what Taskit reads, what it stores, how it is used, and how to take access away.
1. What Taskit connects to
| Source | Permission requested | Used for |
|---|---|---|
| Microsoft 365 mailboxes (two) | Delegated: read mail and create drafts, read mailbox settings, read calendar, read contacts and people, read files | Turning emails in the @Tasks folder into tasks; reading only the specific messages, events, contacts, and files a task needs; placing reply drafts in the Drafts folder |
| Google Drive (personal) | drive.readonly (read-only) | Finding and reading a file only when a task names or references it |
Taskit has no permission to send email, create meeting invitations, write to calendars, or create, change, or delete files. Those paths do not exist in its code, and every call it makes to Microsoft or Google is checked against a fixed list of permitted operations.
2. How Google user data is used
- Taskit requests only the
https://www.googleapis.com/auth/drive.readonlyscope. - It reads a Google Drive file only when a task the owner created names or references that file. It never scans, indexes, or copies the Drive.
- From a file it keeps the file's identifier, name, link, and the short excerpts needed to work the task. The file itself stays in Drive.
- Excerpts may be sent to Anthropic's API, under commercial terms, to produce the task's intake fields, a brief, or a draft for the owner. They are not used to train AI models.
- Google user data is never sold, never used for advertising, never shared with any other party except the processors needed to run the service (listed below), and never used for any purpose other than the task features the owner asked for.
Limited Use disclosure. Taskit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How Microsoft 365 data is used
- Standing access is limited to the
@Tasksfolder in each connected mailbox and to free/busy information for the morning brief. - Other messages, events, contacts, and files are read only on demand for a specific task — for example, the rest of the thread an email came from.
- Reply drafts are created only on threads the owner placed in
@Tasks, only to the people already on that thread, with no attachments, tagged with the Outlook category "Taskit". Sending is always the owner's action in Outlook. - Existing mail, events, and files are never moved, modified, or deleted.
4. What Taskit stores
- Task records (title, tier, dates, status, history) and the context extracted for them: names, numbers, dates, reference numbers, and short excerpts.
- Links to source emails and files by identifier — not copies of mailboxes or Drives.
- Metadata for drafts it created; the draft body lives in Outlook.
- Preferences and learned shorthand.
- Sign-in tokens for each connected account, encrypted at rest with a key held only by the running service.
- An audit log of every automated action and every change made in a connected account.
Data is stored in Cloudflare's D1 database in the United States, with 30-day point-in-time recovery and a weekly backup kept for 90 days.
5. Processors
| Processor | Role | Receives |
|---|---|---|
| Cloudflare | Hosting, database, queues, inbound email routing | All stored Taskit data |
| Anthropic | AI reasoning (intake, briefs, drafts) | Task text and the excerpts pulled for that task; commercial API terms — not used for model training |
| Apple | Push notification relay | End-to-end-encrypted notification payloads (a short title and one line) |
6. Retention
- Tasks and their history: until the owner deletes them.
- Audit log: 24 months.
- Sign-in tokens: until the account is disconnected, then deleted immediately.
- Raw captures that failed processing: 30 days after resolution.
- Deleted data: recoverable for 30 days via point-in-time recovery, then gone; backups age out after 90 days.
7. Revoking access
- Google: remove Taskit at myaccount.google.com/permissions, or disconnect it in Taskit's Settings. The stored token is deleted at once.
- Microsoft: disconnect the mailbox in Taskit's Settings, or remove the Taskit enterprise application in the tenant.
- Everything: the retirement procedure in Taskit's Internal Risk Assessment removes all access and all data in about 30 minutes.
8. Changes
This page is versioned. Material changes to what Taskit reads or stores are made first in Taskit's Internal Risk Assessment and then reflected here with a new version and date.