Privacy Policy
Last updated: 22 August 2026
Summary - the binding text is below
We never record your sessions: video and audio are relayed live and are gone the moment the session ends. We store what you give us (account, profile, tasks, chat, bookings) plus automatically logged session attendance, and we show other members only what you choose to show. Room chat is deleted 30 days after a session. We run no analytics and no profiling; the one measurement we do is which of our ads bring people here, through Meta's pixel, and in the UK and EEA only if you allow it. Six providers help us run the service (Supabase, LiveKit, Stripe, Resend, Netlify, Meta); nobody buys your data from us, ever. You can delete your account yourself in Settings; the main thing we keep afterwards is safety-report evidence and the billing records the law makes us keep.
1. Who is responsible
The controller responsible for processing your personal data on Task Party is:
[FULL LEGAL NAME], trading as Task Party[STREET ADDRESS]
[CITY], [BUNDESLAND], Germany
Email: hello@taskparty.co
This policy explains, as required by Articles 13 and 14 of the GDPR (and the UK GDPR), what personal data we process when you use the Service at taskparty.co, why, on what legal basis, who receives it, how long we keep it, and your rights.
2. What we process, why, and on what legal basis
The legal bases below refer to Article 6(1) GDPR: (a) consent, (b) performance of a contract, (c) legal obligation, (f) legitimate interests. Where we rely on (f), the legitimate interest pursued is named in the row.
| Purpose | Data | Legal basis |
|---|---|---|
| Account and sign-in | Email address, password (stored as a hash) or your Google sign-in identity, session token | (b) contract |
| Your profile, shown to other members as described in section 3 | Name, display name, handle, photo, pronouns, badges, timezone, bio, headline, company, location, links, work preferences, focus note, goal - all exactly as you entered them | (b) contract |
| Sessions, bookings and attendance | Sessions you book; attendance logged automatically by our server whenever you enter a live room; host counters derived from attendance | (b) contract |
| Live video and audio during sessions | Your camera and microphone streams, relayed in real time between the people in the room via LiveKit; never recorded, no storage destination exists | (b) contract |
| Room chat | Messages, sender, room; visible only to that room's members; deleted 30 days after the session ends | (b) contract |
| Tasks, notes, ratings and focus stats | Private to you; shared task titles appear on your room tile only if you choose; focus stats are shown to you alone and are the only analysis we do | (b) contract |
| Thanks notes for hosts | Your message, emoji, name and photo, stamped by the server with your account identity; published on the host's public page | (b) contract |
| Reports and safety evidence | Your report, plus server-captured evidence: the room roster and a snapshot of the room chat at the moment of the report (see section 4) | (f) keeping members safe and establishing, exercising or defending legal claims |
| Blocking | Your block list; enforced silently at booking and room entry; never disclosed to the blocked person | (b) contract and (f) member safety |
| Referral programme | Your referral code, the link between your account and the invited person's account, and credit records tied to billing events | (b) contract |
| Billing | Email, chosen name and an internal profile reference shared with Stripe; membership status mirrored back to us. Card details never touch our systems | (b) contract; (c) tax-law retention of billing records |
| Service email (receipts, reminders, recaps, safety notices) | Email address, name, session details, sent via Resend | (b) contract |
| Newsletter and announcements | Email address and first name, included in our mailing lists only while the matching switch in Settings is on; every email has one-click unsubscribe | (a) consent, withdrawable at any time |
| Waitlist (before launch) | Email address you gave when joining the waitlist, used to recognise you at sign-up and grant the extended trial | (b) steps prior to entering a contract |
| Host applications | Your application answers, name and photo, reviewed by administrators | (b) contract |
| Measuring advertising | Which Meta ad (if any) brought you here: the campaign tags on the link you clicked and Meta's click id, kept with your account from signup; on signup and on your first booking, a hashed form of your email, your IP address, browser type and the same click id are sent to Meta so the ad can be credited. No ad is ever shown to you based on this | (a) consent in the UK and EEA, withdrawable on the Cookie Policy page; (f) measuring our own advertising, elsewhere |
| Feedback and contact messages | Your message and name, routed to our team ("urgent" messages are the 24-hour safety channel) | (b) contract and (f) running and improving the Service |
Providing your email address (and, for a paid Membership, payment through Stripe) is required to enter the contract; without them we cannot provide the Service. Everything else - photo, bio, pronouns, shared task titles and so on - is optional.
3. Who can see what
- Inside a session, other members see your chosen display name and photo, and any task titles you choose to share on your tile.
- Hosts have a public profile page showing the profile fields they filled in (handle, badges, pronouns, headline, company, location, links, bio and hosting counters). Members who are not hosts have no public page.
- Thanks notes you leave appear publicly on the host's page with your name and photo.
- Profile photos are stored in a public storage bucket: anyone who has the photo's web address can fetch it, even without an account. Do not upload a photo you would not want visible at a public address. You can remove your photo at any time.
- Your email, private tasks, notes, ratings and focus stats are private to you.
- A very small number of administrators can additionally see the report queue (including reporter and reported identities and account emails, resolved only when handling a report), host applications, and feedback messages. Administrators cannot watch sessions; nothing is recorded to watch.
4. Reports and safety evidence
When a report is filed from inside a session, our server captures the evidence itself: who was in the room and a snapshot of the room chat at that moment, with timestamps. This means evidence cannot be edited or faked by anyone, and it can include chat lines written by people other than the reporter and the reported person. When a host removes someone from a room, a report is filed automatically and our team is alerted.
Report records and their evidence are kept after the 30-day chat deletion and after account deletion, for as long as necessary to keep members safe (for example to recognise repeated behaviour) and to establish, exercise or defend legal claims. The legal basis is Article 6(1)(f) GDPR; these are the legitimate interests pursued. Where the law requires it, reports may be shared with competent authorities.
5. What we do not do
- We never record session video or audio; no recording feature exists anywhere in the Service.
- No analytics tools, no fingerprinting, and no advertising shown to you. The only tracking we do is measuring our own ads through Meta's pixel, under the rule in the Cookie Policy.
- No selling or renting of personal data, to anyone, ever.
- No profiling and no automated decision-making within the meaning of Article 22 GDPR. Every decision that affects you (moderation, hosting approval) is made by a person. Stripe may run its own automated fraud screening on payments as an independent controller (section 6).
- We do not read your tasks or notes to personalise anything.
6. Who receives your data (processors and other recipients)
Six service providers process personal data to run Task Party. Each is bound by a data processing agreement (except where noted as an independent controller). Where data leaves the UK/EU, the named safeguard under Chapter V GDPR applies; you can request a copy of the safeguards at hello@taskparty.co. For UK members, the UK Extension to the EU-US Data Privacy Framework and the UK Addendum to the Standard Contractual Clauses apply correspondingly.
Supabase (database, sign-in and storage)
- Role: processor. Stores all account, profile, activity and report data at rest, with per-account access rules.
- Data: everything listed in section 2 except live video/audio, which never reaches Supabase.
- Place: project region [SUPABASE REGION - VERIFY]; Supabase Inc. is a US company.
- Transfer safeguard: safeguarded by Standard Contractual Clauses [VERIFY].
LiveKit Cloud (live video relay)
- Role: processor. Relays session video, audio and in-room chat between participants in real time. Transit only: nothing is recorded or stored, and our access tokens grant no recording permissions.
- Data: your profile reference, display name and photo address (so others see who you are in the room), and the live streams while the session runs.
- Place: United States [LIVEKIT REGION - VERIFY].
- Transfer safeguard: safeguarded by Standard Contractual Clauses [VERIFY whether LiveKit, Inc. holds an active Data Privacy Framework certification].
Stripe (payments)
- Role: processor for the billing data we share; independent controller for the payment data you enter on Stripe's own pages and for Stripe's fraud prevention and legal compliance.
- Data: from us: email, chosen name, internal profile reference. Entered by you on stripe.com: card and payment details, which never touch our systems.
- Place: United States and worldwide.
- Transfer safeguard: safeguarded by the EU-US Data Privacy Framework (with UK Extension); Stripe's agreements also incorporate Standard Contractual Clauses.
Resend (email delivery)
- Role: processor. Sends every email we send, and holds a contact list (email + first name) for members whose newsletter or announcement switches are on and for hosts receiving host announcements.
- Data: recipient address, subject and full email content (which can include names, session titles and times, and calendar attachments).
- Place: United States.
- Transfer safeguard: safeguarded by the EU-US Data Privacy Framework [VERIFY current certification].
Netlify (web hosting and delivery)
- Role: processor. Serves the Task Party application to your browser; keeps short-lived technical connection logs (such as IP addresses) as any web host does.
- Data: connection data of visitors (IP address, requested pages, browser type).
- Place: United States.
- Transfer safeguard: safeguarded by Standard Contractual Clauses and the UK Addendum/IDTA [VERIFY].
Meta Platforms Ireland (ad measurement: pixel and Conversions API)
- Role: processor for the measurement events we send; Meta also acts as an independent controller for its own use of the data under its terms.
- Purpose: telling which of our Meta ads bring people who sign up and book, so we can stop paying for the ones that do not. Nothing is used to show you ads.
- Data: a hashed form of your email address, your IP address, your browser type, the ad you clicked (Meta's click id and our campaign tags), the two pixel cookies, and the page you were on at signup or booking.
- When: in the UK and EEA only after you allow it in the cookie choice; elsewhere by default, switchable off on the Cookie Policy page.
- Place: Ireland, with onward transfer to Meta Platforms, Inc. in the United States.
- Transfer safeguard: the EU-US Data Privacy Framework (with UK Extension) and Meta's Standard Contractual Clauses [VERIFY current certification].
Other recipients: our tax advisor (billing records), and competent authorities where the law requires disclosure. There are no other recipients, and no data is sold or shared with data brokers.
7. How long we keep data
| Category | Kept for |
|---|---|
| Session video and audio | Not stored at all - relayed live, then gone |
| Room chat | Deleted 30 days after the session ends |
| Account, profile, tasks, notes, ratings, bookings, attendance, blocks | Until you delete your account (section 8) |
| Profile photo | Until you remove it or delete your account |
| Thanks notes | Displayed on the host's page until removed; if you delete your account, your name and photo are replaced with "Departed member" |
| Reports and safety evidence | Kept while the report is handled and afterwards for as long as necessary for member safety and legal claims; survives the 30-day chat deletion and account deletion (section 4) |
| Billing and membership records | For the statutory commercial and tax retention periods (up to 10 years under German law) |
| Referral and credit records | As part of billing records, for the same statutory periods |
| Mailing lists at Resend | List membership ends when you switch the preference off, unsubscribe, or delete your account; the underlying contact record (email + first name) at Resend is deleted on request |
| Waitlist email | Until used to grant your trial, or deleted on request |
| Host applications | [RETENTION PERIOD - VERIFY AND SET] |
| Ad attribution on your account | Until you delete your account; the pixel cookies expire after 90 days |
| Hosting connection logs (Netlify) | Short-lived technical logs per Netlify's standard schedule [VERIFY] |
8. Deleting your account
You can delete your account yourself in Settings at any time. Deletion removes your login, profile, photo, tasks, notes, ratings and bookings. Chat messages you wrote that are still within their 30-day window, and thanks notes you left, lose your identity: they are re-attributed to "Departed member". What remains afterwards is only what section 7 says remains: safety reports and their evidence, and billing records we are legally required to keep.
9. Cookies and local storage
Task Party sets no cookies of its own and uses a small set of first-party browser storage keys. If you allow ad measurement (asked in the UK and EEA, on by default elsewhere), Meta's pixel sets two cookies. The full list, with purposes and lifetimes, is in the Cookie Policy.
10. Your rights
Under the GDPR (and the UK GDPR) you have the right to:
- Access (Art. 15): a copy of the personal data we hold about you;
- Rectification (Art. 16): correction of inaccurate data - most profile data you can edit yourself in Settings;
- Erasure (Art. 17): deletion, which you can do yourself (section 8) or request by email;
- Restriction of processing (Art. 18);
- Data portability (Art. 20): the data you provided, in a machine-readable format;
- Withdrawal of consent (Art. 7(3)): where processing rests on consent (the newsletter and announcement emails, and ad measurement in the UK and EEA), you can withdraw at any time - via the switch in Settings, the unsubscribe link in every such email, or the button on the Cookie Policy page - without affecting past processing.
Right to object (Art. 21 GDPR)
Where we process your personal data on the basis of legitimate interests (Article 6(1)(f) - in particular safety-report evidence, and ad measurement outside the UK and EEA), you have the right to object at any time, on grounds relating to your particular situation. We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. We do no direct marketing on the basis of legitimate interests.
To exercise any right, email hello@taskparty.co. Exercising your rights is free of charge and we respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority - the authority competent for us is the data protection authority of [BUNDESLAND] ([SUPERVISORY AUTHORITY NAME AND ADDRESS]), or you can complain to the authority of your own country of residence (for the UK, the Information Commissioner's Office).
11. No children's data
The Service is for adults who are at least 18 years old and is not directed at children. We do not knowingly process children's data; if you believe a minor holds an account, contact safety@taskparty.co.
12. Changes to this policy
We will update this policy when the Service or the law changes. Meaningful changes are announced in the app and, where appropriate, by email before they take effect. The date at the top always shows the current version.
See also: Terms & Conditions · Cookie Policy · Community Guidelines · Host Guidelines · How we keep you safe