Privacy policy
Effective 3 September 2026 · Task Columns · https://taskcolumns.com
This policy states exactly what Google user data Task Columns accesses, how that data is used, what is shared and with whom, how it is secured, and how long it is kept. Reviewer walkthrough: https://taskcolumns.com/google-api-disclosure.
Data Access · Data Use · Data Transfer · Data Protection · Data Retention & Deletion · Limited Use Compliance Statement
Who we are
Task Columns is a project layer on top of Google Tasks. Contact: josef2011@gmail.com.
Data Access
We access Google user data only after you sign in and, for Tasks, after you separately authorize the Tasks scope. We do not scrape unrelated Google account content.
Raw Google user data accessed:
- Google sign-in (non-sensitive): name, email address, and profile photo. Scopes:
openid,email,profile. - Google Tasks (sensitive): task title, notes, due date, completion status, parent, order, and the Task List they belong to, plus OAuth access and refresh tokens needed to call the API. Scope:
https://www.googleapis.com/auth/tasks. - Task Columns data (not Google): projects, workflow column, priority, labels, estimate, and blocked state. These stay in our database and are not written into Google task notes.
- Technical: session cookies used to keep you signed in.
Aggregated or anonymized Google user data accessed: none. Task Columns does not create, receive, or store aggregated, anonymized, or de-identified Google user data. We do not run cross-user analytics on Tasks content.
Data Use
How raw Google user data is used: only to provide or improve user-facing Task Columns features. Sign-in data identifies your workspace. Google Tasks data is shown on Inbox, Today, Focus, List, and Kanban, and is written back to Google when you create, edit, complete, or reopen a task so your Google lists stay in sync.
How aggregated or anonymized Google user data is used: not applicable. We do not produce or use aggregated or anonymized Google user data.
Ranking and project suggestions in the product are deterministic heuristics that run in our app for that signed-in user only. They are not used to train a generalized model.
Data Transfer
What raw Google user data is shared, and with what types of parties:
- Google: we send create, update, complete, and reopen requests to the Google Tasks API so your lists stay in sync. Google remains the source of title, notes, due date, completion, parent, order, and list.
- Infrastructure processors: Vercel (hosting and application runtime) and Neon (Postgres) process data solely to run Task Columns. They are not permitted to use Google user data for their own products, advertising, or model training.
- Legal and safety: we will disclose data if required by law, or to investigate abuse or a security incident.
- Business transfer: if Task Columns is sold or merged, Google user data would transfer only with prior notice and, where required, your consent, and only to continue providing this service.
Aggregated or anonymized Google user data shared: none. We do not sell, rent, or share Google user data with advertising platforms, data brokers, lenders, or other unrelated companies.
Data Protection
Google user data is secured in transit and at rest, isolated per account, and never sent to the browser as OAuth tokens. Details are in the following section.
Data protection mechanisms for sensitive data
Task Columns specifies the following data protection mechanisms for sensitive data, including Google Tasks content and Google OAuth credentials:
- Encryption in transit: All traffic between your browser, Task Columns, and Google APIs is sent only over HTTPS using TLS 1.2 or newer. We do not accept plaintext HTTP for the production origin.
- Encryption at rest: Google OAuth access and refresh tokens are encrypted at rest with AES-256-GCM before they are written to the database. The encryption key is held in server environment variables (
TOKEN_ENCRYPTION_KEY/AUTH_SECRET), not in the application repository. Tokens are decrypted only in server-side code when calling the Google Tasks API. - Token handling: OAuth tokens are stored only on the server. They are never exposed to client-side JavaScript, logs we control, or third-party analytics. Disconnecting Google Tasks or deleting your workspace permanently removes the stored tokens.
- Access control: Each signed-in session can read and write only that user's workspace. Server routes check the session before loading tasks, tokens, or settings. Infrastructure consoles (Vercel, Neon, Google Cloud) are limited to the operator of Task Columns and are protected by those providers' account authentication, including multi-factor authentication where the provider requires or offers it.
- Least privilege: Sign-in requests only
openid,email, andprofile. Google Tasks uses onlyhttps://www.googleapis.com/auth/tasks. We do not request Gmail, Drive, Calendar, Chat, Photos, YouTube, or Data Portability scopes. - Data minimization: We store the Google Tasks fields needed to display and sync your board. Task Columns fields (project, priority, labels) stay in our database and are not written into Google task notes.
- Human access: Operators do not read your Google Tasks content in the ordinary course of providing the service. A person may access stored data only to investigate a security incident, a bug you report, abuse, or a legal obligation, and only for that purpose.
- No remote code in the token path: Token encrypt, decrypt, and Google API calls run in our deployed server functions. We do not inject third-party remote scripts into that path.
Data Retention & Deletion
Sensitive Google user data is kept only while your account stays connected and the data is needed to provide sync.
- Disconnect Google Tasks in Settings → Integrations. That stops new sync and permanently deletes stored OAuth tokens.
- Revoke access in your Google Account under Third-party access. The next API call then fails and we treat the connection as expired.
- Email josef2011@gmail.com to request deletion of your Task Columns workspace. We then delete the stored Google user data and local project fields we hold.
Tasks that remain in your Google account are not deleted by a Task Columns deletion request unless you delete them in Google. Completing or deleting a task inside Task Columns does update or remove that item in Google Tasks when the Tasks scope is connected, because two-way sync is the product.
Prohibited Data Use
Raw and aggregated or anonymized Google user data is not used for any purpose other than to provide or improve user-facing Task Columns features. Use for targeted advertising, credit or lending decisions, unrelated analytics products, or generalized AI training is prohibited and is not practiced by this app.
Prohibited Data Transfer
Raw and aggregated or anonymized Google user data is not transferred or sold to third parties for any purpose other than to provide or improve user-facing features. Transfer or sale to data brokers, advertisers, and lenders is prohibited and is not practiced by this app. Processors listed under Data Transfer act only as infrastructure for this service.
AI/ML Model Training Restrictions
Raw and aggregated or anonymized Workspace API user data is not used to develop, improve, or train AI or machine-learning models, except a specific user's own in-product ranking which is a deterministic heuristic and is not a trained model.
We do not transfer Workspace API user data to third-party AI or ML services (including OpenAI, Anthropic, Google Gemini consumer APIs, or similar) that would use that data to train their models. Task Columns does not call those APIs with Google Tasks content.
Limited Use Compliance Statement
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
Task Columns's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
See the Google API Services User Data Policy, including the Limited Use requirements. This statement is also hosted on the Google API disclosure page and in the terms of service.
Allowed vs. Prohibited Use Cases
Task Columns uses the Google Tasks API so people can organize their own tasks in projects and columns. That is an allowed, user-facing productivity use. We do not use Drive, Gmail, Chat, Data Portability, Meet, Health, Photos, or YouTube APIs. We do not send commercial email, warm inboxes, use Google as a CDN, or reward engagement on other Google products.
Your choices
- Disconnect Google Tasks in Settings → Integrations.
- Revoke access in your Google Account under Third-party access.
- Email josef2011@gmail.com to request deletion of your Task Columns workspace.
Children
Task Columns is not directed at children under 16.
Changes
If this policy changes in a material way, we will update this page and the effective date. Data protection disclosures remain at https://taskcolumns.com/privacy#data-protection-mechanisms-for-sensitive-data.