Privacy Policy

Effective date: August 2, 2026

1. Overview

withtask (the “Service”) is a team task, schedule, and reminder service operated by an individual. The operator values your personal information and, in accordance with this policy, collects, uses, and stores personal data while protecting your rights. Because the Service is run by an individual (not a business entity), business registration details are not shown; please direct privacy-related inquiries to the contact below.

2. Personal information we collect

  • Sign-up and authentication (required) — email address, name, password (stored encrypted), and email verification code (OTP)
  • Profile (optional) — profile photo, username, and time zone
  • Collected automatically during use — IP address, browser and device information (User-Agent), session and cookie data, push notification tokens (web push subscription data, Android/iOS device tokens), and service usage records and error logs
  • Content you enter or upload — task titles and descriptions, reminder text (including sentences entered in natural language), and attached images

The Service does not offer social login and uses only email-based authentication at sign-up.

3. How we collect it

Personal data is either entered directly by you during sign-up and use of the Service, or generated and collected automatically as you use the Service. For usage analysis and error diagnosis, some information may be collected automatically through analytics tools.

4. How we use personal information

  • Member identification, authentication, and account management
  • Providing core services such as teams, tasks, schedules, and reminders
  • Sending notifications via web and mobile push and email
  • Interpreting the schedule from reminder sentences you entered in natural language
  • Service improvement, usage analysis, and error diagnosis
  • Maintaining security and preventing abuse
  • Meeting obligations under applicable law

5. Delegated processing and overseas transfer

To operate reliably and provide its features, the Service delegates personal data processing as shown below, and some data is transferred to infrastructure located overseas. The recipient’s country, the items transferred, and the purpose are as follows.

Recipient Country Items transferred Purpose Retention and use period
Cloudflare, Inc. United States (global edge) Account information, service content, profile photo, email address Running, storing, and transmitting the service (hosting/CDN/email delivery) Until membership withdrawal or termination of the processing contract
PostHog (EU region) European Union (EU) Service usage records, device information, access IP, error logs, and screen usage records Service usage analysis and error diagnosis Until the analytics purpose is fulfilled, or per the processor’s policy
OpenAI, L.L.C. United States The reminder sentences you entered, the time of entry, and time zone Interpreting reminder schedules entered in natural language Not retained separately after interpretation
Google LLC (FCM) United States Device push notification token Sending push notifications to Android devices Until subscription cancellation or membership withdrawal
Apple Inc. (APNs) United States Device push notification token Sending push notifications to iOS devices Until subscription cancellation or membership withdrawal
Operator’s own database (Postgres) Western Europe (EU) Member information and service data in general Storing service data Until membership withdrawal
crona (operator’s own notification scheduler) Western Europe (EU) Task title, reminder trigger time and recurrence rule, time zone, and user identifier Sending scheduled and recurring reminders Until the reminder is deleted or membership is withdrawn

The information above is transferred over the network at the point each service is provided (sign-up, reminder registration, service use, etc.). You may refuse the overseas transfer, but doing so may limit sign-up or use of the related features. Profile photos and team icons are served through a separate public address (CDN), so anyone who knows the URL can access them.

6. Retention period and destruction

As a rule, personal data is destroyed without delay when you withdraw your membership. When you request account deletion, your account and related data are deleted after a 7-day grace period; logging back in within the grace period cancels the deletion. Login session data expires after up to 30 days. Information that must be retained under applicable law is kept for the period that law requires. Retention and deletion of data accumulated by third parties (PostHog, crona, etc.) follow each provider’s policy.

7. Your rights and how to exercise them

You may request access to, correction of, deletion of, or suspension of processing of your personal data at any time. Account deletion can be requested directly through the in-app account deletion feature; for details, please see the account deletion guide. To exercise other rights, contact us below and we will act without delay.

8. Cookies and similar technologies

The Service uses cookies and similar technologies to keep you logged in and to analyze usage. You can refuse cookie storage through your browser settings, but some features such as login may then be limited.

9. Privacy officer and contact

Please direct inquiries, complaints, and remedy requests regarding personal data handling to the contact below.

bonoself@gmail.com

10. Changes to this policy

This privacy policy may be revised in line with changes in law or the Service, and any changes will be announced on this page.

This policy takes effect on August 2, 2026.