Legal & Trust

Privacy Policy

Last updated: 31 July 2026

Working draft. TaskForce is pre-launch. This document is provided for transparency and is pending final legal review — it is not yet a binding agreement. Questions? hello@taskforce.dev

This policy explains what personal data TaskForce processes, why, and the choices and rights you have. It is written to reflect how the product actually handles data. Placeholders in [brackets] mark details we will confirm before launch.

Who is responsible

The controller for personal data is [Company legal name], [registered address]. For any privacy question, contact hello@taskforce.dev (no data-protection officer is appointed; this address reaches the team responsible for data protection).

What we collect

  • Account — your name and email, managed through our identity provider (Keycloak over OIDC).
  • Workspace content — the projects, issues, cycles, comments and documents you and your team create.
  • Connector credentials — when you connect a tool, its keys or tokens, stored encrypted.
  • AI usage metadata — which model ran which step, and token counts, for metering and auditability.
  • Billing — plan and payment status, processed by our payment provider (see subprocessors). We do not store full card numbers.
  • Technical data — logs needed to run and secure the service.

Why we process it

  • To provide the service you asked for (performance of a contract).
  • To secure and maintain it, and prevent abuse (legitimate interest).
  • To bill paid plans (contract and legal obligation).
  • With your consent, for anything optional — which you can withdraw at any time.

AI and your data

Inside a run, agents process your workspace context to produce drafts and proposals. Model calls go to the provider you configure: a hosted provider, or a local model through Ollama that keeps prompts and outputs inside your own network. We do not use your data to train TaskForce models. Training policy for a hosted model depends on that provider; local models remove the question entirely. See AI transparency.

Who we share it with

We do not sell your data. We share it only with the subprocessors that help us run the service — and only what they need. The current list, with purpose and location, is on our subprocessors page. On a self-hosted deployment with local models, your content need not leave your infrastructure at all.

How long we keep it

We keep personal data for as long as your account is active, then for up to 90 days after your account is closed unless a longer period is required by law. You can request deletion at any time, and the product supports removing your data on request.

Your rights

Under the GDPR and similar laws you can access, correct, delete, export, restrict or object to the processing of your personal data. To exercise a right, email hello@taskforce.dev. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr).

International transfers

Where data is processed outside your region, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Our hosting is in the EU (Hetzner, Germany), so hosting itself involves no transfer outside the EU. Self-hosting and local models let you keep data in a region of your choosing.

Security & changes

We protect data with encryption in transit and at rest, access controls and tested infrastructure — see the Trust Center. If this policy changes materially, we'll update the date above and notify account holders.


Questions about this document? Write to hello@taskforce.dev.