Default Alive LLC, a California limited liability company (“we,” “us”), operates Tasks. This Policy covers the Tasks website, embedded apps, MCP tools, APIs, and support. It explains our practices, not the separate practices of ChatGPT, Codex, other agents, or services you connect.
1. Information we handle
- Account information: the account identifier, name, and email provided through ChatGPT authentication, plus your onboarding status. Tasks does not receive your ChatGPT password.
- Board content: board and list names, cards, Markdown descriptions, labels, ordering, comments, timestamps, and archived or deleted status.
- Activity records: previous and current card values, change history, versions, account attribution, browser or MCP source, and available actor labels. We also retain mutation identifiers and responses to safely process retried requests.
- Collaboration: invitation email addresses, membership, roles, invitation responses, and related timestamps. Another user may provide your email when inviting you.
- Support and technical information: information you send us and operational information processed by us or our hosting providers, such as IP addresses, device and browser details, requests, errors, and security logs.
Tasks receives the arguments supplied to its tools and returns requested task information. It does not automatically receive your full ChatGPT or Codex conversation history, but you or your agent may include conversation content in a card, comment, or tool request.
2. Why we use it
We use information to authenticate you; store and synchronize boards; process changes, comments, and invitations; attribute activity; provide support; diagnose and improve reliability and functionality; prevent abuse; communicate about the Service; meet legal obligations; and protect rights. We may access content when reasonably needed for these purposes.
Where applicable law requires a legal basis, we rely on performance of our agreement, legitimate interests in operating and protecting the Service, compliance with law, or consent when required. We use consent for optional processing only where it is actually requested.
3. Who can receive information
- People with board access. Owners and accepted members can see board content, comments, history, and attribution according to their role. Owners manage membership. People with access may copy content or make it available to agents they use.
- Connected clients and agents. When an authorized client calls a Tasks tool, relevant information is returned through that client to its host or model provider. Agent comments are associated with the authenticated account. Actor labels do not give an agent a separate private identity or separate board permissions.
- Service providers. OpenAI supplies Sites hosting, ChatGPT authentication, and the embedded app/tool connection. Cloudflare infrastructure, including D1 database storage, supports the hosted Service. Providers may process information to deliver and secure their services.
- Legal and business recipients. We may disclose information to advisers, authorities, or affected parties when reasonably necessary to comply with law, prevent abuse, or protect rights and safety, and to counterparties in a financing, merger, acquisition, reorganization, or sale, subject to applicable protections.
A public Tasks website or a link to a card does not, by itself, make that board public. Board permissions govern access. Removing someone’s access cannot retrieve copies already made or content already sent to an agent or other provider.
We do not sell personal information or share it for cross-context behavioral advertising. We do not use task content to train our own general-purpose AI models. When you use an AI provider, its handling of information, including any model-training choices, depends on that provider’s terms and your settings; this Policy does not override them.
4. Storage, retention, and deletion
The canonical task database is hosted through OpenAI Sites using Cloudflare D1. We retain account, board, collaboration, activity, and support information for as long as reasonably needed to provide the Service, preserve shared work and history, address security issues or disputes, and meet legal obligations. Retention depends on the information and purpose; we do not currently apply a fixed automatic expiry to every record.
Moving a card or comment to trash, archiving a board, or editing a description is not permanent erasure. Recoverable records, prior card values in history, and retry records may remain stored. Removing a collaborator or disconnecting a plugin does not delete those records. Shared contributions may remain available to other authorized board members.
For an account or permanent-deletion request, contact us below. We may verify identity and authority and retain information where permitted or required, including shared records needed to respect others’ rights. Backup and infrastructure logs may remain until the provider’s applicable retention cycle ends. We may retain information that has been de-identified so it cannot reasonably identify you.
5. Cookies, local storage, and tracking
Authentication and hosting providers use cookies and similar technologies to keep sign-in working and protect the Service. Tasks stores preferences, such as keyboard-shortcut settings, in browser local storage. Blocking these technologies may affect functionality.
Tasks currently has no third-party advertising trackers or application analytics SDK. We do not track activity across unrelated websites for targeted advertising. Tasks does not change its necessary operational processing in response to a browser “Do Not Track” signal. Because we do not sell personal information or share it for advertising, there is no such sale or sharing to opt out of. This does not describe the separate tracking practices of external sites or connected providers.
6. Your choices and privacy rights
You can edit content within your permissions, manage board access if you are an owner, and disconnect Tasks through your client’s controls. To request access, correction, a copy, deletion, restriction, or another right available under applicable law, email legal@boxhaven.dev. Include “Tasks” and the email used for your account; do not send your password.
Depending on your location and applicable law, you may also object to processing, withdraw consent, use an authorized representative, appeal our response, or complain to a privacy regulator. We may request reasonable verification and apply lawful exceptions. We will respond within applicable legal deadlines and will not unlawfully discriminate against you for exercising your rights. Requests involving another person’s board may require us to involve its owner without granting you access you do not have.
7. Security and international processing
We use access controls and other reasonable measures intended to protect information. No service is completely secure. Protect your ChatGPT account and devices, grant board and agent permissions carefully, and avoid storing credentials or sensitive information that requires protections Tasks has not agreed to provide. Report suspected security problems to our contact below.
We and our providers may process information in the United States and other countries, which may have different privacy laws. Where required, international transfers are subject to applicable legal safeguards. We do not promise storage in a particular country.
8. Children
Tasks is intended for adults 18 and older and is not directed to children. We do not knowingly collect children’s personal information. Contact us if you believe a child has provided it so we can investigate and take appropriate action.
9. Policy changes
We may update this Policy as the Service or our practices change. We will publish the new version, change its effective date, and provide additional notice or request consent when required by law. A policy update does not remove privacy rights you already have.
10. Contact
For privacy requests and questions about Tasks, contact Default Alive LLC at legal@boxhaven.dev. This is our shared company legal inbox; include “Tasks” in the subject line.