Legal

Privacy Policy

Last updated: TBD

Placeholder. Final policy will be reviewed by counsel before public beta (plan task 25.6). The summary below is informational.

What we collect

Account data from Clerk (email, name), TaskNode project metadata, GitHub installation identifiers and read-only file contents fetched per issue analysis, redacted log batches and events you send to POST /v1/logs/batch, billing metadata from Razorpay or Dodo Payments.

What we do NOT collect

We do not collect passwords, tokens, API keys, cookies, session IDs, full request bodies, payment card data, database URLs, or private personal data. Server-side redaction strips these on every batch. If a redactor misses something, treat it as a bug and report it.

Encryption

Raw log payloads are encrypted at rest with AES-256-GCM using an environment-provided master key.

Tenant isolation

Every row in our database is scoped to an organization. Requests for resources outside your organization return HTTP 404 (not 403, not data).

Data retention & deletion

Soft-delete is 30 days for projects. Account deletion is processed within 30 days of request per GDPR and India DPDPA.

Contact

For privacy questions, use the contact form.