Privacy policy.
This notice explains the information TaskCenter handles, why it is used, how OAuth-connected services participate, and which controls are currently automated versus manually reviewed.
Updated August 17, 2026
Operational privacy notice for the current product. Counsel review and jurisdiction-specific disclosures are still required before broad commercial release.
Purpose-limited
Workspace and connected-service data is used to provide the request, preserve its record, secure the service, and account for usage.
Organization-scoped
Protected records and connector sessions are associated with an authenticated account and workspace boundary.
Honest controls
Export, retention, and deletion surfaces distinguish recorded requests from completed automated fulfillment.
01
Information we handle
The categories depend on the features and connections you choose to use.
- Account and identity data, such as name, email, authentication method, organization membership, role, session metadata, and security events.
- Workspace content, such as prompts, messages, project and issue records, plans, approvals, files, artifacts, comments, run output, and memory you ask TaskCenter to retain.
- Connected-service data, such as provider identity, requested scopes, connection status, and content retrieved or acted on for an authorized task.
- Operational data, such as feature usage, model and tool events, billing package and consumption records, diagnostics, audit events, abuse-prevention signals, and optional browser analytics when you allow it.
02
How we use information
Information is processed to provide the workspace and the services you request.
- Provide authentication, workspace collaboration, agent planning, approved execution, search, memory, artifacts, support, billing, and requested integrations.
- Maintain provenance, approvals, auditability, fraud and abuse controls, service reliability, debugging, and security investigation.
- Improve product behavior using operational signals, feedback, and optional browser analytics when allowed. Customer content is not represented as public marketing data, and provider use remains subject to configured contracts and controls.
03
OAuth and connected applications
A connection is an authorization boundary, not blanket access to an account.
- Google sign-in requests OpenID Connect identity scopes (openid, email, and profile) to authenticate the account; the authorization code is exchanged and validated server-side.
- Tool connectors request provider-specific scopes shown during authorization. TaskCenter or an approved connection provider such as Composio may process provider tokens and requested content to perform the authorized action.
- Disconnecting prevents new TaskCenter requests through that connection. Provider-side authorization, logs, or retained records may also need to be managed with the provider.
- Where token exchange is not implemented, TaskCenter records the connection as needing reauthorization rather than claiming that the provider is connected.
04
Sharing and service providers
Information is shared only as needed to operate the selected service or comply with law.
- Cloudflare may process application traffic and store runtime data; Stripe may process payments; Google may provide authentication; Composio and connected providers may process authorized integration requests.
- Configured AI model providers receive the prompt and contextual material needed to answer or execute a request. Exact providers can vary by deployment and selected model.
- We may disclose information to protect users, the service, or legal rights; respond to valid legal process; complete a corporate transaction; or act with your direction.
05
Retention, export, and deletion
Retention follows product need, security obligations, configured policy, and the state of account controls.
- Workspace records are retained while needed to operate the account and preserve the requested operating history. Audit, billing, security, provider, and backup records may follow separate obligations.
- Account settings can record data-access, retention-preference, export, or deletion requests where exposed. A recorded request is not the same as completed fulfillment.
- Account deletion currently enters a manual owner-review queue and does not automatically delete every record. Runtime-event retention automation may remain active while a user preference is recorded for review.
- Contact privacy@taskcenter.co for access, correction, portability, objection, or deletion questions. Identity and authority may need to be verified before a request is completed.
06
Security, transfers, and choices
Use the workspace and provider controls that match the sensitivity of your work.
- TaskCenter uses access checks, secure sessions, scoped OAuth state, guarded data access, audit records, and approval gates, but no service can guarantee absolute security.
- Service providers may process data in countries different from yours. Applicable contractual and provider safeguards depend on the deployed service and customer arrangement.
- Do not upload information you are not authorized to use. Limit connector scopes, review agent proposals, disconnect unused providers, and use account settings to manage available notification, memory, and browser analytics choices.
Questions about this document?
Contact privacy@taskcenter.co for questions about privacy or terms. To report a security issue, contact security@taskcenter.co.