Privacy Policy
Effective date: August 2, 2026
1. Overview
withtask (the “Service”) is a team task, schedule, and reminder service operated by an individual. The operator values your personal information and, in accordance with this policy, collects, uses, and stores personal data while protecting your rights. Because the Service is run by an individual (not a business entity), business registration details are not shown; please direct privacy-related inquiries to the contact below.
2. Personal information we collect
- Sign-up and authentication (required) — email address, name, password (stored encrypted), and email verification code (OTP)
- Profile (optional) — profile photo, username, and time zone
- Collected automatically during use — IP address, browser and device information (User-Agent), session and cookie data, push notification tokens (web push subscription data, Android/iOS device tokens), and service usage records and error logs
- Content you enter or upload — task titles and descriptions, reminder text (including sentences entered in natural language), and attached images
The Service does not offer social login and uses only email-based authentication at sign-up.
3. How we collect it
Personal data is either entered directly by you during sign-up and use of the Service, or generated and collected automatically as you use the Service. For usage analysis and error diagnosis, some information may be collected automatically through analytics tools.
4. How we use personal information
- Member identification, authentication, and account management
- Providing core services such as teams, tasks, schedules, and reminders
- Sending notifications via web and mobile push and email
- Interpreting the schedule from reminder sentences you entered in natural language
- Service improvement, usage analysis, and error diagnosis
- Maintaining security and preventing abuse
- Meeting obligations under applicable law
5. Delegated processing and overseas transfer
To operate reliably and provide its features, the Service delegates personal data processing as shown below, and some data is transferred to infrastructure located overseas. The recipient’s country, the items transferred, and the purpose are as follows.
| Recipient | Country | Items transferred | Purpose | Retention and use period |
|---|---|---|---|---|
| Cloudflare, Inc. | United States (global edge) | Account information, service content, profile photo, email address | Running, storing, and transmitting the service (hosting/CDN/email delivery) | Until membership withdrawal or termination of the processing contract |
| PostHog (EU region) | European Union (EU) | Service usage records, device information, access IP, error logs, and screen usage records | Service usage analysis and error diagnosis | Until the analytics purpose is fulfilled, or per the processor’s policy |
| OpenAI, L.L.C. | United States | The reminder sentences you entered, the time of entry, and time zone | Interpreting reminder schedules entered in natural language | Not retained separately after interpretation |
| Google LLC (FCM) | United States | Device push notification token | Sending push notifications to Android devices | Until subscription cancellation or membership withdrawal |
| Apple Inc. (APNs) | United States | Device push notification token | Sending push notifications to iOS devices | Until subscription cancellation or membership withdrawal |
| Operator’s own database (Postgres) | Western Europe (EU) | Member information and service data in general | Storing service data | Until membership withdrawal |
| crona (operator’s own notification scheduler) | Western Europe (EU) | Task title, reminder trigger time and recurrence rule, time zone, and user identifier | Sending scheduled and recurring reminders | Until the reminder is deleted or membership is withdrawn |
The information above is transferred over the network at the point each service is provided (sign-up, reminder registration, service use, etc.). You may refuse the overseas transfer, but doing so may limit sign-up or use of the related features. Profile photos and team icons are served through a separate public address (CDN), so anyone who knows the URL can access them.
6. Retention period and destruction
As a rule, personal data is destroyed without delay when you withdraw your membership. When you request account deletion, your account and related data are deleted after a 7-day grace period; logging back in within the grace period cancels the deletion. Login session data expires after up to 30 days. Information that must be retained under applicable law is kept for the period that law requires. Retention and deletion of data accumulated by third parties (PostHog, crona, etc.) follow each provider’s policy.
7. Your rights and how to exercise them
You may request access to, correction of, deletion of, or suspension of processing of your personal data at any time. Account deletion can be requested directly through the in-app account deletion feature; for details, please see the account deletion guide. To exercise other rights, contact us below and we will act without delay.
8. Cookies and similar technologies
The Service uses cookies and similar technologies to keep you logged in and to analyze usage. You can refuse cookie storage through your browser settings, but some features such as login may then be limited.
9. Privacy officer and contact
Please direct inquiries, complaints, and remedy requests regarding personal data handling to the contact below.
10. Changes to this policy
This privacy policy may be revised in line with changes in law or the Service, and any changes will be announced on this page.
This policy takes effect on August 2, 2026.