Legal & Trust

Subprocessors

Last updated: 31 July 2026

Working draft. TaskForce is pre-launch. This document is provided for transparency and is pending final legal review — it is not yet a binding agreement. Questions? hello@taskforce.dev

To run TaskForce we rely on a small number of subprocessors, each bound by data-protection obligations and given only what they need. This is the current list; it will change as the product grows, and we'll give notice before adding one that handles personal data.

The big picture first

Much of TaskForce can run on your own infrastructure. On a self-hosted deployment using local models through Ollama, your content need not touch any third party — the subprocessors below apply mainly to our hosted service and to hosted-model calls you choose to make.

Current subprocessors

  • Stripe — payments. Processes billing and customer contact details for paid plans. We don't store full card numbers.
  • Anthropic / OpenAI — hosted AI models, only for the calls you route to them. They receive the prompt and return the output for that step. Choose local models to avoid this entirely.
  • Hetzner Online GmbH — cloud infrastructure for our hosted service (application data at rest and in transit), located in the EU (Germany).
  • [Transactional email provider] — account and notification emails, if applicable. To be confirmed.

Components such as identity (Keycloak), object storage (MinIO) and the database (PostgreSQL) run within the deployment — on a self-hosted install, they're yours, not third-party subprocessors.

Changes

When we add or change a subprocessor that handles personal data, we'll update this page and notify customers with an active agreement so they can object. See the DPA and privacy policy for how this fits together.


Questions about this document? Write to hello@taskforce.dev.