Last Updated: 8 August 2026 Effective Date: 26 August 2026
TaskBolt is operated by Reuben Schultz, a sole trader trading as TaskBolt (ABN 99 557 604 248), based in South Australia, Australia. This policy explains what personal information we collect through the TaskBolt platform at https://taskbolt.ai and https://app.taskbolt.ai (the "Service"), how we use it, who we share it with, and the choices you have.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). This policy is a notice about our practices; it is not a contract.
If you have any question or request about your personal information, email legal@taskbolt.ai.
Account information: your name, email address, and optional profile photo. Authentication is handled by Clerk (our sign-in provider); if you sign in with Google, Microsoft, GitHub or Slack, we receive your name, email and profile photo from that provider. We do not see or store your password.
Content you create: projects, tasks, comments, notes, goals, habit and reflection data, file attachments and documents you upload, and your conversations with TaskBot and other AI features.
Billing information: your subscription status and transaction history. Card details go directly from your browser to Stripe; we never see or store full card numbers.
Integration data: if you connect an integration (Google Calendar, Gmail, Microsoft, GitHub, Slack), we store encrypted access tokens and the data you authorise the integration to use. Google integration scopes can include reading, sending and composing Gmail messages, if you grant them.
Messaging data: if you use the iMessage/SMS feature, your phone number and the content of messages sent and received. Messages you send are stored in full; assistant replies are stored in shortened form.
Technical information: IP address, browser and device information, and logs generated by running the Service. If you consent to analytics, page performance measurements via Vercel Speed Insights.
Identifiers and context: your user ID and chat session IDs (stored in our systems and in your browser so the app works across pages), any location and timezone context you set for the assistant, and, if you use location search, the location text you type.
We do not sell personal information, and we do not use third-party advertising or cross-site tracking. We do not use your data for automated decisions that have legal or similarly significant effects on you.
When you use AI features, relevant content is sent to third-party AI providers to generate the response. This can include your chat messages, project and task details (including project lists, task titles, goals and statistics used to give the assistant context), memory facts you have saved, your location and timezone context if set, and documents you submit for AI processing.
Current AI providers:
| Provider | What it receives | Used for |
|---|---|---|
| xAI (Grok) | Chat messages, project/task context, document text for embeddings, search queries | TaskBot chat, suggestions, semantic search |
| Google (Gemini) | Chat messages and conversation history | TaskBot chat, conversation summarisation |
| Anthropic (Claude) | Agent instructions, session messages and files | Managed AI agent sessions |
| Tavily | Search queries derived from your requests | Web search for AI agents |
| PDF.co | The full content of PDFs you submit for parsing | Document text extraction (only when this feature is enabled) |
You can avoid AI processing of particular content by not using AI features on it. AI provider retention is governed by each provider's own terms.
If you use agent automation features, your message content, context and related inputs are sent to our workflow automation system (n8n) to run the automation.
We use the following processors to run the Service. All are bound by their own published data processing terms.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Clerk | Authentication and user management | Name, email, profile photo, sign-in credentials (direct to Clerk) | United States |
| Neon | Database hosting | Your account data and content | United States |
| Vercel | Application hosting, file storage (Blob), performance measurement (consent-based) | All application data; uploaded files; page performance | United States, global edge |
| Stripe | Payments | Email, user reference, subscription and payment data; card details direct to Stripe | United States |
| Upstash | Caching and rate limiting | User identifiers, phone number (for messaging rate limits), cached agent memory | United States |
| Resend | Transactional email | Email address, name, plan and subscription details in email content | United States |
| Sendblue | iMessage/SMS delivery | Phone number, message content | United States |
| Slack | Slack integration (if connected) | Task titles and details, briefing text, DM conversation content | United States |
| Sign-in, Calendar/Gmail integrations (if connected), location search (Places) | Profile data; authorised integration data; typed location text | United States | |
| Microsoft | Sign-in and integrations (if connected) | Profile data; authorised integration data | United States |
| GitHub | Sign-in and integration (if connected) | Profile data; repository events you connect | United States |
| xAI, Google (Gemini), Anthropic, Tavily, PDF.co | AI features | See section 3 | United States |
| n8n (workflow automation) | AI agent automations | Message content and context for automations you trigger | Operator-configured infrastructure |
Locations shown are each provider's primary published operating region; global providers may also process data in other regions where they operate. The n8n automation endpoint receives data only when agent automations are enabled, on infrastructure we configure.
Error monitoring: the Service includes wiring for Sentry error monitoring, but it is not currently active in production; no data is sent to Sentry today. If we switch it on, browser-side monitoring (including session replay with text masked and media blocked) will only run with your analytics consent, and we will update this policy first.
We may also disclose personal information where required by law, such as in response to a court order, or to protect the safety of users or the public.
We set one first-party cookie, tb-cookie-consent, which stores your cookie choices for one year. Clerk sets its own cookies to keep you signed in (essential). Stripe and the sign-in providers set cookies during checkout and sign-in flows. Non-essential measurement (Vercel Speed Insights) runs only with your consent, given through the cookie banner.
The app also uses your browser's local storage for preferences and app state, including some identifiers such as your user ID and chat session ID, used only to make the app work on your device. See the Cookie Policy for the full list.
TaskBolt is operated from Australia, and our service providers listed in section 4 store and process data primarily in the United States. By using the Service, your personal information will be transferred to and processed in the United States and other locations where our providers operate. We take reasonable steps to use reputable providers with published security and privacy commitments, but overseas providers are subject to the laws of their own jurisdictions.
While your account is active, we keep your data so the Service works. Some data is cleaned up automatically: project drafts are purged after 24 hours, inactive AI agent sessions are deleted after 24 hours (including the remote provider session), expired and orphaned agent memories are cleaned monthly, and assistant replies in iMessage conversations are stored in shortened form.
When you delete your account:
What account deletion does not remove, honestly stated:
If you want us to pursue deletion of specific data held by a provider on our behalf, email legal@taskbolt.ai and we will take reasonable steps.
Data in transit is encrypted (HTTPS/TLS), database connections use SSL, and integration OAuth tokens are encrypted at rest. Access to production systems is limited to the operator. Payments and sign-in credentials are handled by Stripe and Clerk respectively and never touch our servers in raw form. No system is completely secure; if we suspect that an eligible data breach may have occurred, we will assess that suspicion promptly (the 30-day statutory outer limit applies only to assessing a suspected eligible data breach), and once we believe a breach is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner as soon as practicable, not at the end of any assessment window.
We respond to privacy requests within 30 days. We may need to verify your identity first.
If you are located outside Australia, you may have additional rights under your local law; contact us and we will engage with your request in good faith.
If you believe we have mishandled your personal information, email legal@taskbolt.ai with the details, and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC), phone 1300 363 992.
The Service is not directed at children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact legal@taskbolt.ai and we will delete it.
We may update this policy as the Service or the law changes. For material changes we will email registered users and post a notice before the change takes effect; for minor changes we will update the date above. Earlier versions are available on request.
Email: legal@taskbolt.ai Website: https://taskbolt.ai
Mailing Address: Reuben Schultz trading as TaskBolt PO Box 1222 Blackwood SA 5051 Australia