PRIVACY

Privacy Policy

Last updated: August 5, 2026. For a plain-language system map, read How Aitaskora stores your data.

Owner workspace data

Project briefs, scope baselines, change requests, commercial profiles, work logs, hours, expenses, and private approval owner keys are stored in browser local storage on the owner’s device unless the owner exports a backup.

Pilot feedback

When feedback is submitted, Aitaskora stores the selected type, usefulness rating, work role, use intention, message, source, app version, optional reply email, and optional safe diagnostics. Safe diagnostics contain aggregate counts and device context, not project or client content. A temporary daily one-way request fingerprint is used for abuse prevention. The sender’s raw IP address is not stored in the feedback record, although Cloudflare may process standard network data to deliver and protect the service.

Optional account authentication

Optional accounts store the normalized email, short-lived code records, hashed session tokens, session expiry, and basic request-security information.

Encrypted workspace synchronization

Project content and private owner keys are encrypted in the browser before upload. Aitaskora stores ciphertext and technical metadata. The passphrase is not sent to or recoverable by Aitaskora.

Published client approval records

When the owner explicitly creates an approval link, Aitaskora sends only the selected scope or change record to a Cloudflare Pages Function and stores it in Cloudflare D1. The online record may include project name, scope or change details, commercial impact, expiry, view count, client name, optional client email, comment, decision, and decision time.

Public and private tokens

The client receives a public approval token. A separate private owner key is stored only in the owner workspace and backups. The owner key is used to synchronize or revoke the record and should not be shared.

Client email delivery

When the owner chooses direct delivery, Aitaskora sends the intended client email address, email subject, personal note, project name, approval summary, and secure approval link through the configured transactional email provider. The current optional integration is Resend. Delivery attempts, recipient, subject, provider status, provider message identifier, time, and errors may be logged in Cloudflare D1. If direct delivery is not configured, Aitaskora opens the owner’s local email application instead.

Purpose and responsibility

The owner is responsible for having a lawful reason to contact each client, entering the correct recipient address, and ensuring project content is appropriate to send by email. Aitaskora does not permit the email API to send to an address other than the client email attached to the authorized project approval record.

Backups and exports

Workspace backups, project exports, and work-log CSV files are created only when requested. Backups may contain approval owner keys and must be protected as confidential files.

Retention and control

Approval links expire after the selected period and may be revoked by the owner. A decided record may remain available for documentation unless it is revoked or removed administratively.

Infrastructure data

The website and API are delivered through Cloudflare. Standard request, device, browser, network, and security information may be processed to deliver and protect the service.

Sensitive information

Do not enter passwords, access keys, payment-card information, health information, confidential source code, or highly sensitive personal or business data.

Usage analytics

Aitaskora uses Google Analytics 4 on the public informational pages and owner workspace to understand aggregate traffic and product usage. Google Analytics may use cookies or similar identifiers. Secure client approval pages and the private feedback administration page are deliberately excluded. The Aitaskora implementation removes query strings from page locations and referrers and disables Google signals and advertising-personalization signals.