Privacy Policy
Last updated: January 8, 2025 • Effective: January 8, 2025
1. Introduction
Welcome to TaskToCompletion. We respect your privacy and are committed to protecting your personal data.
This privacy policy explains:
- What information we collect
- How we use your information
- Your rights regarding your data
- How we protect your information
Important: By using TaskToCompletion, you agree to this privacy policy.
2. YouTube Data Usage
How We Use YouTube Data
When you provide a YouTube video URL, we extract the video transcript to create task boards.
What we do:
- Extract video transcripts from YouTube URLs you provide
- Process transcripts with AI to generate task summaries
- Store the YouTube URL to link back to the original video
- Store AI-generated task descriptions (NOT raw transcripts)
What we DON'T do:
- Store raw video transcripts in our database
- Download or redistribute YouTube videos
- Access your YouTube account or viewing history
- Share YouTube data with third parties (except our AI processor)
Google Privacy Policy: YouTube data is also subject to the Google Privacy Policy.
3. Data We Collect
Account Information
When you create an account, we collect:
- Email address (via Clerk authentication)
- Name (if provided via GitHub OAuth)
- Profile picture (if provided via GitHub OAuth)
- Account creation date
Project Data
When you create projects, we collect:
- YouTube video URLs you provide
- AI-generated task boards and descriptions
- Task status updates (todo, in progress, done)
- AI chat conversations about your projects
- Project names and metadata
Usage Data
We automatically collect:
- Device type and browser information
- IP address (for security and fraud prevention)
- Pages visited and features used
- Error logs and performance metrics
Optional Data
You may choose to provide:
- Feedback and support requests
- User preferences (theme, font size, etc.)
- Beta feature opt-ins
4. How We Use Your Data
We use your data to:
We will NEVER:
- Sell your personal data to third parties
- Use your data for advertising purposes
- Share your project data publicly without permission
- Train AI models on your private conversations
5. Data Storage & Retention
Where We Store Data
- Database: Supabase (PostgreSQL) with encryption at rest
- Hosting: Vercel (deployed in US region)
- Authentication: Clerk (secure user management)
How Long We Keep Data
- Active projects: Stored until you delete them
- Deleted projects: Retained for 15 days for recovery, then permanently deleted
- Account data: Stored while your account is active
- Deleted accounts: All data permanently deleted within 7 days of deletion request
- Raw transcripts: Not stored (processed and discarded immediately)
- Error logs: Retained for 90 days for debugging
Good News
We don't store raw YouTube transcripts. Only AI-generated task summaries are saved, which contain much less data.
6. Your Rights (GDPR/CCPA)
Depending on your location, you have the following rights regarding your personal data:
California Residents (CCPA/CPRA)
We do not sell your personal information. See our Do Not Sell My Personal Information page for details. We honor Global Privacy Control (GPC) signals.
🔍 Right to Access
You can request a copy of all data we have about you. We'll provide it in a readable format within 30 days.
🗑️ Right to Delete
You can request deletion of your account and all associated data. We'll process this within 7 days.
📦 Right to Export (Data Portability)
You can download all your data in JSON format from your account settings.
✏️ Right to Correct
You can update your account information at any time from your settings page.
🚫 Right to Opt-Out
You can opt-out of non-essential data processing (analytics, optional features) in settings.
⏸️ Right to Restrict Processing
You can request we temporarily stop processing your data while we verify its accuracy.
❌ Right to Withdraw Consent
You can withdraw consent for data processing at any time. This won't affect previously processed data.
To exercise any of these rights, contact us at privacy@tasktocompletion.com
7. Data Security
We take security seriously. Here's how we protect your data:
🔒 Encryption
- • HTTPS encryption for all data in transit
- • Encrypted database storage at rest
- • Encrypted backups
🔐 Authentication
- • Secure OAuth via Clerk
- • Multi-factor authentication available
- • Session management and timeouts
🛡️ Access Controls
- • Row-level security (RLS) in database
- • User data isolated by account
- • Limited employee access
🚨 Monitoring
- • 24/7 security monitoring
- • Automated threat detection
- • Regular security audits
Data Breach Notification
In the unlikely event of a data breach, we will notify affected users within 72 hours via email and provide details on what data was affected and what steps we're taking.
8. Third-Party Services
We use the following third-party services to provide TaskToCompletion:
Clerk
Purpose: User authentication and account management
Data shared: Email, name, profile picture
Supabase
Purpose: Database hosting and storage
Data shared: All project data, tasks, conversations
OpenAI
Purpose: AI-powered task generation and chat
Data shared: YouTube transcripts, chat messages
Supadata
Purpose: YouTube transcript extraction
Data shared: YouTube video URLs only
Vercel
Purpose: Application hosting and deployment
Data shared: Usage logs, performance metrics
Note: We only share the minimum data necessary for each service to function. We have data processing agreements with all third-party providers.
9. Children's Privacy
TaskToCompletion is not intended for children under 13 years of age.
COPPA Compliance
- • We do not knowingly collect data from children under 13
- • We do not knowingly allow children under 13 to create accounts
- • If we discover a child under 13 has created an account, we will delete it immediately
Parents/Guardians: If you believe your child has created an account on TaskToCompletion, please contact us at privacy@tasktocompletion.com and we will delete the account and all associated data.
10. International Data Transfers
TaskToCompletion is operated from the United States. Your data may be transferred to and processed in the United States.
For EU/EEA Users
If you are located in the European Union or European Economic Area, your data is protected by:
- Standard Contractual Clauses (SCCs) with our US-based service providers
- GDPR-compliant data processing agreements
- Your rights under GDPR (see Section 6)
Data Storage Locations
- Primary database: US East region (Supabase)
- Application hosting: US region (Vercel)
- Backups: Encrypted and stored in US region
11. Contact Information
For questions, concerns, or requests regarding your privacy or this policy, contact us:
Privacy Inquiries
Email: privacy@tasktocompletion.com
Response time: We respond to all privacy requests within 7 business days
GDPR/CCPA requests: Processed within 30 days as required by law
Note: For general support questions, please use support@tasktocompletion.com
12. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements.
How We Notify You
- Minor changes: We'll update the "Last Updated" date at the top of this page
- Significant changes: We'll email you at least 30 days before the changes take effect
- Material changes affecting your rights: We'll require you to accept the new policy before continuing to use the service
Policy version history: Previous versions of this policy are available upon request at privacy@tasktocompletion.com
This privacy policy is effective as of January 8, 2025 and was last updated on January 8, 2025.
© 2025 TaskToCompletion. All rights reserved.