Your work log stays scoped to your account

This policy explains what Tasktrail stores, when work-log content leaves Tasktrail, and who can access it.

Data we collect

Tasktrail stores the Google account identifier, name, email, and profile image used for sign-in. Tasktrail does not retain the Google access, refresh, or ID tokens returned during sign-in. We store the workspaces, projects, tasks, trails, links, technical details, summaries, schedule settings, and current selections that you or an authorized MCP client create.

We also retain the MCP client, consent, credential, request, tool-use, delivery, and error records needed to operate and secure the service. Hosting and application logs can include timestamps, request paths, account or client identifiers, status codes, and diagnostic details. Tasktrail does not load third-party behavioral analytics on its web pages.

How we use data

We use this data to authenticate you, provide and troubleshoot the dashboard, execute MCP tools within approved OAuth scopes, generate summaries you request, deliver scheduled summaries, prevent abuse, and maintain the reliability and security of Tasktrail.

AI summaries and delivery

When you request an AI narrative or enable a schedule, the relevant task and trail content is sent through OpenRouter to the configured model provider. The resulting narrative is stored in Tasktrail. If email delivery is enabled, Resend receives the destination email address and the summary email. If you provide a Slack incoming webhook, that webhook recipient receives the generated summary. Do not configure a destination that is not authorized to receive your work-log content.

Service providers and sharing

Tasktrail does not sell personal data. We use service providers to run the product, including Google for sign-in, Vercel for hosting and operational logs, Neon for Postgres storage and recovery, OpenRouter and the configured model provider for AI narratives, Resend for scheduled email, and GitHub Actions for backup artifacts. An operator-configured alert webhook may receive error messages and related diagnostic identifiers. Your own webhook provider and approved MCP clients process data according to the access you give them and their own policies.

Administrative access

Authorized Tasktrail administrators can access account identifiers, workspace and project details, task and trail content, technical details, and MCP activity or errors when needed for support, security, abuse prevention, and service operations. Access is restricted to designated administrators; your work log is not shared with other ordinary users.

Storage and security

Application data is stored in Postgres and application reads and writes are scoped to an authenticated account. Tasktrail-issued MCP authorization codes, access tokens, refresh tokens, and confidential client secrets are stored as SHA-256 hashes; raw values are shown only when issued. Google provider access, refresh, and ID tokens are discarded rather than stored. Provider API keys for OpenRouter and Resend remain in the server environment and are sent only to their respective providers.

Retention and deletion

Work-log records and generated summaries remain until they are deleted through the product or as part of an account-deletion request. OAuth, MCP activity, summary-delivery, and operational records are retained as needed to provide and secure the service. Revoked Tasktrail MCP tokens stop authorizing new requests immediately.

Deleted data can remain temporarily in disaster-recovery copies until those copies expire. Tasktrail uses provider point-in-time recovery and a weekly logical database backup configured with 90-day artifact retention. To request account or data deletion, contact support@tasktrail.ai.

Contact

Questions about privacy or security can be sent to support@tasktrail.ai.