Taskforce beta · Edition 2026-09-14
Privacy policy
This policy describes the Taskforce Mac beta, the Taskforce website and the optional connection service. You can use manual Actions and Focus without a Taskforce account, source connection or AI service.
Who operates Taskforce
Taskforce is operated by 태스크포스, a sole proprietorship registered in South Korea, business registration number 687-30-01972. The operator handles privacy and support requests at songch9511@gmail.com.
Representative and privacy contact: Cheonghyeok Song. Business address: 262-20, Galma-dong, Seo-gu, Daejeon, Republic of Korea.
Your local workspace
The app stores Actions, Goals, next steps, Last Stop, focus state, source references, structured analysis results, user decisions and preferences on your Mac. This supports capturing, organizing and resuming your work. Display names and enabled account sessions are also stored locally.
Execution memory is not an archive of full emails, transcripts, prompts or model responses. Source text and AI input may be processed transiently when you enable an optional feature. Structured task text and references can still contain personal information.
Optional Taskforce account
When account sign-in is available, Supabase Auth processes your user ID, email address, verification status, enabled login identities and authentication sessions. This identifies your product account on the website and in the app. Email codes are delivered using Resend. Supabase, Resend and hosting providers may process authentication and security data outside your country under their own service policies.
The website uses necessary HttpOnly session cookies and an encrypted, ten-minute sign-in request cookie. Session cookies are cleared by browser sign-out; refresh sessions can last up to 30 days in the browser subject to provider expiry or revocation. The Mac app stores its own session in OS-protected storage. No authentication tokens are placed in navigation URLs or stored with Action history.
Signing in grants access to the Mac beta. It does not subscribe you to emails or grant source or AI access. Your Actions, Last Stop and Focus remain on this Mac; signing out or switching product accounts does not erase, hide or transfer the local workspace.
Product account information is kept while your account exists. Contact songch9511@gmail.com from your account email to request account access, correction or deletion. We verify ownership before removing the account and associated beta contact; provider security records or records required for legal obligations may have separate retention. Local workspace deletion remains a separate control in the app.
Optional connections
You choose which accounts, pages, repositories, channels or folders Taskforce may read. Provider authorization may grant broader permissions than the sources selected in the app; Taskforce applies the selected scope during reads. Providers also process authorization and API requests under their own policies.
Notion, GitHub, Slack and local-folder features are experimental in this beta. Only connect content you are authorized to use. Source analysis requires its own choice about external AI processing. Taskforce does not send messages or change your original records as part of the beta workflow.
Gmail connections, reads and analysis are paused. Google Calendar is limited to authorized test accounts and local calendar context; it does not automatically create Actions. Google-derived Actions and Calendar context are excluded from external AI and agent Handoff in this build. Availability in a settings screen is not a claim of general-public Google approval.
External AI and agent Handoff
If you enable source-text analysis, the app supplies the permitted input and instructions to the connected Codex runtime, which can process them through OpenAI. If you choose Handoff or connect an external agent, the information shown in that workflow may be copied or made available to that agent. Manual local use does not require these features.
The external provider and the account or plan you use determine their processing location, training settings, retention and deletion. Taskforce does not control or guarantee those settings. Review the provider terms and your account controls before enabling these features. Do not enable them for information you are not permitted to send. Google-derived data remains blocked regardless of user consent.
Taskforce does not use your local workspace for advertising or general-purpose model training and does not sell it. AI output can be wrong; user choices and deterministic app rules control Action state.
Website and connection hosting
Vercel hosts the website and HTTPS connection service. The service handles OAuth code exchange and token refresh transiently. Source document bodies are read by the desktop, not routed through the connection broker. The broker does not keep a token database. Desktop credentials are retained in protected local storage.
Hosting processes request metadata such as IP address, requested route, time, user agent, response status and operational errors. OAuth callback URLs can contain short-lived authorization parameters; the application avoids deliberately logging tokens or source content, but this is not a promise that infrastructure never processes request URLs. The configured function region is US East (iad1); CDN and security processing may take place in other regions.
The hosting account uses Vercel Pro with no external log drains configured as of this edition. Vercel documents a standard Pro runtime-log window of one day; infrastructure, security and service records follow Vercel's own retention rules. Project access is restricted to authorized operators. The website code does not add analytics SDKs, advertising cookies or payment processing. Interactive examples use fictional data. Optional externally hosted videos contact their media host only when used.
Beta access requests
When the beta request form is enabled, it asks for your email address and explicit consent to receive a download link and beta onboarding messages. We record the request source, consent edition, request time and delivery status to operate the beta. It is not consent to unrelated marketing. Submitting the form is optional.
Resend, operated by Plus Five Five Inc. in the United States, processes the email, beta contact record and email delivery. Cloudflare Turnstile processes browser and network signals to prevent automated submissions; its challenge does not collect the email field from the form. Vercel hosts the request endpoint. These providers may process information outside South Korea under their own privacy policies.
To stop beta emails or request deletion, email songch9511@gmail.com. We remove the active beta contact and identifiable request information within 90 days after the beta ends, or earlier following a verified deletion request. Where necessary to honor an opt-out, a minimal suppression record may remain until the mailing system is retired; it is not used to send further messages. Provider security, delivery and backup records follow their own retention rules. Requests are handled by the operator; the app cannot erase these hosted records through Delete local data.
Website beta registration
With your agreement on the beta form, we send your email address, signup time, consent version, campaign source and welcome-email status to Resend to maintain the Taskforce beta list and send the download link and beta onboarding messages. This does not enroll you in a general marketing newsletter. Registration is unavailable while the sending and download configuration is incomplete.
Cloudflare Turnstile processes browser and verification information to prevent automated abuse. Resend and Cloudflare may process this information outside South Korea under their service policies. This form does not request Action contents, connected source documents or AI prompts. Provider logs and backup copies follow the providers' retention policies.
We keep the beta list during participation, review it when the beta ends, and remove identifiable list entries within 90 days of beta closure unless you separately join a continuing service or a specific legal obligation requires retention. To stop beta emails or request deletion sooner, reply to the email or contact songch9511@gmail.com. The operator handles these requests manually; deleting the local Mac workspace does not delete a website signup.
Support and beta feedback
If you email support, we receive your email address, message and any attachments you choose to send through Gmail, operated by Google. Use a short description, app version, macOS version and reproduction steps. Do not send private task contents, passwords, tokens, full databases or backup passwords. We do not automatically upload app diagnostics or screenshots.
We use support messages to answer requests, resolve problems and improve the beta. We review closed conversations monthly and remove their identifiable contents within 90 days of closure, unless an unresolved request or a specific legal obligation requires longer retention. You may ask for earlier deletion. We retain only non-identifying issue summaries after that. Google's infrastructure and backup retention follow Google's policies and may involve processing outside South Korea.
Participation in interviews or sharing a testimonial is optional. Public use of a named quote requires separate permission. Support cannot remotely read or erase a local workspace.
Storage protection and backups
The beta encrypts the execution-memory database and journals with SQLCipher. Its random key and connection credentials are protected using macOS-backed Electron safeStorage. The app does not fall back to a plain-text database when key protection fails. New portable backups use password-derived scrypt keys and authenticated AES-256-GCM encryption.
Keep your backup password separately. Taskforce cannot recover it. Older unencrypted exports and copies in device backups are not automatically rewritten. Encryption does not guarantee the security of an unlocked or compromised device, and it does not erase historical disk or Time Machine copies.
Retention, access and deletion
Local workspace records remain until you remove the relevant data. Removing an Action from the current view can leave historical decisions or recovery copies. Disconnecting a source stops access and removes the connection credentials when its last source is removed, but does not erase previously created Actions or revoke a provider's authorization grant.
For whole-profile removal, open Settings → Privacy → Delete local data…, review the scope, type DELETE and select Delete data and restart. This removes the selected local profile, including Actions, history, preferences, recovery copies and protected credential/key files. An interrupted request resumes on next launch. No recovery copy is created by this deletion.
Uninstalling the app alone leaves local data. Exported backups, Time Machine copies, provider records, external AI history and MCP settings in other apps require separate removal. You can revoke provider access in the provider's account settings. Taskforce cannot delete copies held by another service on your behalf through this local-delete control.
You may request information about, correction of, deletion of, or restrictions on the personal information held by the operator by emailing the privacy contact. We may ask only for information needed to verify the request. Local information can be reviewed, corrected or exported in the app; contact us for help without sending the workspace itself. Rights and any exceptions depend on applicable law.
Google data and policy changes
Taskforce's use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including Limited Use requirements. Google information is not sold, used for advertising or permitted by Taskforce to train general-purpose AI models. Gmail remains paused pending the necessary processing safeguards and review.
This edition is included with the beta. Material changes will be documented with a new edition date. Where a change needs a new data-sharing choice, the app will request that choice before enabling the processing.