Legal
Privacy Policy
Last updated: TBD
Placeholder. Final policy will be reviewed by counsel before public beta (plan task 25.6). The summary below is informational.
What we collect
Account data from Clerk (email, name), TaskNode project metadata, GitHub installation identifiers and read-only file contents fetched per issue analysis, redacted log batches and events you send to POST /v1/logs/batch, billing metadata from Razorpay or Dodo Payments.
What we do NOT collect
We do not collect passwords, tokens, API keys, cookies, session IDs, full request bodies, payment card data, database URLs, or private personal data. Server-side redaction strips these on every batch. If a redactor misses something, treat it as a bug and report it.
Encryption
Raw log payloads are encrypted at rest with AES-256-GCM using an environment-provided master key.
Tenant isolation
Every row in our database is scoped to an organization. Requests for resources outside your organization return HTTP 404 (not 403, not data).
Data retention & deletion
Soft-delete is 30 days for projects. Account deletion is processed within 30 days of request per GDPR and India DPDPA.
Contact
For privacy questions, use the contact form.