PRIVACY
Privacy Policy
Last updated: August 5, 2026. For a plain-language system map, read How Aitaskora stores your data.
Owner workspace data
Project briefs, scope baselines, change requests, commercial profiles, work logs, hours, expenses, and private approval owner keys are stored in browser local storage on the owner’s device unless the owner exports a backup.
Pilot feedback
When feedback is submitted, Aitaskora stores the selected type, usefulness rating, work role, use intention, message, source, app version, optional reply email, and optional safe diagnostics. Safe diagnostics contain aggregate counts and device context, not project or client content. A temporary daily one-way request fingerprint is used for abuse prevention. The sender’s raw IP address is not stored in the feedback record, although Cloudflare may process standard network data to deliver and protect the service.
Optional account authentication
Optional accounts store the normalized email, short-lived code records, hashed session tokens, session expiry, and basic request-security information.
Encrypted workspace synchronization
Project content and private owner keys are encrypted in the browser before upload. Aitaskora stores ciphertext and technical metadata. The passphrase is not sent to or recoverable by Aitaskora.
Published client approval records
When the owner explicitly creates an approval link, Aitaskora sends only the selected scope or change record to a Cloudflare Pages Function and stores it in Cloudflare D1. The online record may include project name, scope or change details, commercial impact, expiry, view count, client name, optional client email, comment, decision, and decision time.
Public and private tokens
The client receives a public approval token. A separate private owner key is stored only in the owner workspace and backups. The owner key is used to synchronize or revoke the record and should not be shared.
Client email delivery
When the owner chooses direct delivery, Aitaskora sends the intended client email address, email subject, personal note, project name, approval summary, and secure approval link through the configured transactional email provider. The current optional integration is Resend. Delivery attempts, recipient, subject, provider status, provider message identifier, time, and errors may be logged in Cloudflare D1. If direct delivery is not configured, Aitaskora opens the owner’s local email application instead.
Purpose and responsibility
The owner is responsible for having a lawful reason to contact each client, entering the correct recipient address, and ensuring project content is appropriate to send by email. Aitaskora does not permit the email API to send to an address other than the client email attached to the authorized project approval record.
Backups and exports
Workspace backups, project exports, and work-log CSV files are created only when requested. Backups may contain approval owner keys and must be protected as confidential files.
Retention and control
Approval links expire after the selected period and may be revoked by the owner. A decided record may remain available for documentation unless it is revoked or removed administratively.
Infrastructure data
The website and API are delivered through Cloudflare. Standard request, device, browser, network, and security information may be processed to deliver and protect the service.
Sensitive information
Do not enter passwords, access keys, payment-card information, health information, confidential source code, or highly sensitive personal or business data.
Usage analytics
Aitaskora uses Google Analytics 4 on the public informational pages and owner workspace to understand aggregate traffic and product usage. Google Analytics may use cookies or similar identifiers. Secure client approval pages and the private feedback administration page are deliberately excluded. The Aitaskora implementation removes query strings from page locations and referrers and disables Google signals and advertising-personalization signals.