Privacy Policy
Last updated: July 6, 2026
1. Introduction
This Privacy Policy explains how AgileTasker ("we", "us", or "the Service") collects, uses, stores, and protects your personal information. We are committed to protecting your privacy and ensuring transparency about our data practices.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Display name
- Profile photo (optional)
- Authentication credentials (securely hashed)
2.2 User Content
When you use the Service, we store:
- Tasks, notes, and project information you create
- Organization data (sections, boards, lists)
- Tags and labels you define
- Settings and preferences
- Scheduling information and due dates
2.3 Usage Information
We automatically collect:
- Device information (browser type, operating system)
- IP address
- Access times and usage patterns
- Error logs and diagnostic information
2.4 Third-Party Integration Data
If you connect third-party services like Google Calendar or Google Tasks, we access only the specific data you authorize, as described in section 3 below.
3. Google User Data (Calendar & Tasks Integration)
AgileTasker's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3.1 What we access
If you choose to connect your Google account, we request the following permissions:
- Google Calendar — to create, update, and delete calendar events that correspond to tasks you schedule in AgileTasker, and to read event times so changes you make in Google Calendar can be reflected back on your AgileTasker tasks.
- Google Tasks — to create, update, complete, and delete Google Tasks entries that correspond to date-only tasks you create in AgileTasker.
- Email address — to show you which Google account is connected.
3.2 How we use and store it
- Google data is used solely to provide the two-way task/event synchronization feature you enable. It is never used for advertising, profiling, or any other purpose.
- Your OAuth refresh token is stored server-side in our database (Google Cloud Firestore, encrypted at rest) and is never exposed to your browser or to other users.
- We store only the minimal sync metadata (event/task identifiers and timestamps) needed to keep items linked. We do not copy or retain the contents of your other calendar events or task lists.
- We do not sell, rent, or transfer Google user data to third parties. No humans read this data except with your explicit consent for support, or where required for security or by law.
3.3 Revoking access
You can disconnect Google at any time in AgileTasker under Settings → Integrations, which deletes the stored tokens. You can also revoke AgileTasker's access from your Google Account permissions page. Upon disconnection we delete the stored credentials and sync metadata.
4. How We Use Your Information
- Provide, maintain, and improve the Service
- Authenticate your identity and secure your account
- Store and sync your tasks and data across devices
- Enable third-party integrations you authorize
- Respond to your support requests and communications
- Monitor and analyze usage to improve functionality
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
5. Data Storage and Security
We store your data using Firebase, Google's cloud infrastructure. Security measures include:
- Encryption of data in transit using HTTPS/TLS
- Encryption of data at rest on Firebase servers
- Secure authentication using industry-standard protocols
- Regular security audits and updates
- Access controls limiting data access to authorized systems only
While we implement robust security measures, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:
- Service Providers: With Firebase and Google Cloud for hosting and infrastructure
- Third-Party Integrations: With services you explicitly authorize (e.g., Google Calendar)
- Legal Requirements: If required by law or in response to valid legal requests
- Protection of Rights: To protect our rights, safety, or property, or that of our users
7. Your Data Rights
- Access: You can access your data at any time through the Service
- Modification: You can edit or update your information through account settings
- Export: You can export your tasks and data
- Deletion: You can delete your account and associated data through account settings
- Withdrawal of Consent: You can disconnect third-party integrations at any time
8. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. When you delete your account, we will delete your personal data within 30 days, except where we are required to retain certain information for legal compliance, dispute resolution, or fraud prevention.
9. Cookies and Tracking
- Authentication Cookies: To keep you logged in and secure your session
- Preference Cookies: To remember your settings and preferences
- Analytics: To understand how the Service is used (anonymized when possible)
You can control cookies through your browser settings, but this may affect Service functionality.
10. Children's Privacy
The Service is not intended for users under the age of 13. We do not knowingly collect information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.
11. International Data Transfers
Your data may be processed and stored on servers located in different countries where Firebase operates. By using the Service, you consent to the transfer of your information to these locations, which may have different data protection laws than your country.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date and, where appropriate, by email or in-app notification. Your continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at lovro.rakar@gmail.com.