1. Scope of this policy
This policy applies to information processed by TaskFlow when an individual creates a workspace, is invited to an existing workspace, signs into the web application, or installs and uses the desktop companion. It does not apply to third-party services that a workspace administrator may choose to integrate with, which are governed by their own privacy practices.
Each TaskFlow workspace is operated under the direction of its administrators. Those administrators determine which members are added, which data is captured, and how long that data is retained within the limits established by this policy.
2. Information we collect
We collect the following categories of information:
- Account information. Name, email address, hashed password credentials, workspace code, organization name, and role.
- Operational data. Projects, tasks, comments, attachments, time-tracking sessions, attendance records, and time-off requests that you or your teammates create inside the workspace.
- Activity data (desktop application). Aggregate keystroke and mouse-event counters recorded during active timer sessions. We record event frequency only; we never capture the content of keystrokes or the screen contents of other applications.
- Periodic screenshots (desktop application). When a timer session is active, the desktop application captures a compressed screenshot of the desktop at regular intervals. These are uploaded to a storage prefix scoped to your organization.
- Diagnostic and log data. Server logs, error traces, API request metadata (timestamp, IP address, user agent) retained for the purposes of debugging, abuse prevention, and service reliability.
3. How we use information
We process the information described above to:
- Provide, maintain, and improve the TaskFlow platform.
- Authenticate members, enforce role-based access control, and prevent unauthorized access.
- Generate dashboards, reports, and automated daily summaries requested by workspace administrators.
- Detect, investigate, and respond to security incidents and abusive activity.
- Comply with applicable laws, regulations, and lawful requests from public authorities.
We do not sell personal information and we do not use the contents of your workspace to train machine-learning models.
5. Storage and retention
Workspace data is stored in the Asia-Pacific (Mumbai) region of Amazon Web Services. Each tenant’s records in the primary database are prefixed with a unique organization identifier so cross-tenant access is architecturally prevented.
We retain account and operational data for the lifetime of your workspace. Upon deletion of a workspace, we remove associated records from production systems within sixty (60) days, subject to limited retention for backup, legal, or audit purposes.
Workspace administrators may export their data in CSV format at any time from inside the application. A full-workspace export covering users, projects, tasks, attendance, and time-off records is planned.
6. Security measures
TaskFlow applies industry-standard safeguards to protect the confidentiality and integrity of information in our custody:
- Secure Remote Password (SRP) authentication — user passwords never leave the browser in plaintext and are never transmitted to our servers.
- TLS 1.3 encryption for all data in transit.
- Server-side encryption at rest for databases, object storage, and backups.
- Least-privilege access controls, audit logging, and per-tenant isolation at the presigned-URL layer.
No system can be guaranteed one hundred percent secure. If we become aware of a security incident affecting your information, we will notify you in accordance with applicable law.
7. Your rights and choices
Subject to applicable law, you may request access to, correction of, or deletion of your personal information. Most operational data can be edited or removed directly inside the application by a user with the appropriate role. For requests that cannot be fulfilled through the product, contact us using the details below.
If you are located in a jurisdiction that grants additional rights — such as the right to object to processing, to restrict processing, or to data portability — we will honor those rights to the extent required.
9. Children’s privacy
TaskFlow is not directed to children under thirteen (13), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us so we can remove it.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where required, provide additional notice through the product or by email to workspace administrators. Continued use of TaskFlow after an update constitutes acceptance of the revised policy.
11. Contacting us
Questions about this policy or the handling of your information can be directed to support@neurostack.in. Please include the workspace code affected by your request to help us respond accurately.
Privacy questions?
Our team reviews every inquiry and responds within one business day.
support@neurostack.in