iTasks LogoiTasks

Privacy Policy

Effective date: · Last updated:

1. Introduction

This Privacy Policy describes how iTasks (the "Service"), a task management app that operates as a Telegram bot, Telegram Mini App, web interface, and Android app, collects, uses, shares, and protects your personal data when you use our Telegram bot @iTasksBot, the Mini App, the website, or the Android app.

iTasks is not a Telegram product, is not affiliated with Telegram, and is not endorsed by Telegram. The Service uses the Telegram Bot API, Telegram Mini Apps, Telegram Login, Telegram Stars, and external payment providers as third-party integrations.

By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree with this policy, please do not use the Service. Please also review our Terms of Service.

2. Data We Collect

When you use the Service, we may process the following categories of data:

Account and authentication data. Depending on how you sign in, we may process:

  • Telegram User ID, Telegram Login/OIDC subject, display name or nickname, username, language, and avatar URL if provided by Telegram.
  • Session data: internal user ID, linked sign-in providers, interface language, and timezone.
  • Android push data: FCM push token, platform, app version, notification status, and device last-seen time.

Technical and analytics data. When you use the website, Telegram bot, Mini App, or Android app, information about screen views and feature usage, client technical parameters, IP addresses in server logs, browser or Android WebView information, and standard analytics infrastructure identifiers may be processed automatically. We use Google Analytics, Ahrefs Analytics, Microsoft Clarity, and internal monitoring tools for this purpose. Microsoft Clarity may process information about clicks, scrolling, errors, screen dimensions, and interface session replay; direct Telegram account identifiers, nicknames, and files are not sent to third-party analytics services. Analytics and metrics data is transmitted over encrypted HTTPS/TLS connections and processed in anonymized, pseudonymized, or aggregated form where applicable.

We do not request or store passwords, contacts, address book data, email addresses, precise location, or phone numbers.

3. Data You Create

In the course of using the Service, you may create the following content, which is stored on our servers:

  • Workspaces and projects
  • Tasks (titles, descriptions, statuses, priorities, deadlines, assignees, watchers, and links to customers, sprints, and workflows)
  • Task comments, file attachments, and time tracking entries
  • Task and project activity: creation, updates, status changes, assignee changes, workflow transitions, and related service events
  • Customer records if you manage them inside a workspace
  • HelpDesk data: support channels, connected Telegram bot settings, customer Telegram IDs and chat IDs, names, usernames, customer language, conversations, messages, message captions, internal notes, statuses, task links, files, images, documents, and voice messages
  • Voice task creation data: the real-time audio stream used for recognition, recognized text, detected language indicators, recording duration, AI-drafted title, description, and due date, and technical usage and AI token records
  • AI token pack purchase data: workspace, internal user ID, Telegram payer ID, SKU, amount of tokens, Stars price, invoice/charge ID, purchase and refund statuses, usage, and remaining balance
  • Consent evidence: versions and hashes of the Terms and Privacy Policy, locale, consent timestamp, and the version of the displayed checkbox text; unnecessary fingerprint data is not collected for this purpose
  • Integration settings, including HelpDesk and AI Access

4. How We Use Your Data

We use your data solely to provide and improve the Service:

  • To identify you within your workspaces and display your name to team members
  • To deliver task notifications and updates via Telegram
  • To deliver Android push notifications through Firebase Cloud Messaging if you use the Android app and notifications are enabled
  • To process card payments for PRO and Telegram Stars payments for PRO or separate AI token packs in supported flows
  • To set the appropriate interface language
  • To receive, store, and process HelpDesk conversations, customer messages, internal notes, and attachments
  • To recognize dictated speech, show the transcript to the user, and prepare the task title, description, and a clearly stated due date with built-in AI
  • To perform the contract and deliver the digital product, prevent duplicate grants and resolve disputes, process refunds, provide support, maintain security, and keep required financial/legal records
  • To work with an external AI tool that a user with personal AI access connects to the selected workspace
  • To generate aggregated usage statistics and analyze feature demand
  • To monitor service availability, diagnose incidents, prevent abuse, and provide technical support for the Service

Internal operational metrics are processed exclusively on iTasks servers in anonymized and aggregated form, are not shared with third parties, and are used solely for internal operational purposes related to the operation, security, and development of the Service.

Data processed through Google Analytics, Ahrefs Analytics, and Microsoft Clarity is used for standard web, product, and behavior analytics in anonymized or pseudonymized form. We do not send direct Telegram account identifiers, nicknames, task content, comments, HelpDesk messages, or files to analytics services, and we do not use analytics data for individual profiling outside the operation of the Service.

We do not sell, rent, or share your personal data with third parties for marketing purposes.

6. Data Storage and Security

Your data is stored on secure servers located in the European Union. File attachments are stored using DigitalOcean Spaces (S3-compatible cloud storage) with servers also located in the EU.

We take reasonable technical and organizational measures to protect your data against unauthorized access, loss, or alteration. However, no method of transmission over the Internet is 100% secure.

Data is transmitted over encrypted HTTPS/TLS connections. Access to production data is limited to what is necessary to operate, support, and secure the Service. File attachments are stored in private storage and are available only through authenticated service access.

7. Third-Party Services

The Service interacts with the following third-party services:

  • Telegram — for the Telegram Bot API, Mini Apps, Telegram Login/OIDC, notifications, HelpDesk messages and attachments, and Telegram Stars processing for digital goods. Telegram applies its own Terms and Privacy Policy; iTasks does not receive card details or Apple/Google Stars purchase data.
  • Bank-card payment providers — for preparing the payment page, accepting payments, processing service payment notifications, refunds, and financial records for PRO subscriptions. The selected payment provider may process payment details, transaction identifiers, amounts, currencies, payment technical data, and information required to complete payment under its own privacy policy.
  • DigitalOcean — for file storage (cloud infrastructure provider, EU servers).
  • Google — for Firebase Cloud Messaging push notifications and website/product usage analytics via Google Analytics. Google may process standard technical identifiers, device, browser, or WebView information, push tokens, notification payloads, and interaction data in accordance with its own privacy policy. iTasks does not use Google as an authentication provider in the current public version and does not store user email addresses.
  • Ahrefs — for website visit analytics via Ahrefs Analytics. Ahrefs may process standard technical identifiers, browser information, and page visit data in accordance with its own privacy policy.
  • Microsoft — for product behavior analytics through Microsoft Clarity: heatmaps, anonymized interface events, and session recordings. Microsoft may process standard technical identifiers, browser or WebView information, clicks, scrolling, diagnostic events, and session replay data in accordance with its own privacy policy.
  • Soniox — for real-time speech recognition when the user explicitly starts voice input. Soniox receives the audio stream and returns a transcript; Soniox's terms and privacy policy apply.
  • Google Cloud Vertex AI — to process the transcript automatically and prepare the task title, description, and a clearly stated due date with built-in AI. The dictation text, current title, description, and due date, plus the user's current date, time, and time zone are sent; Google Cloud data-processing terms apply.
  • External AI tools connected by a user — such as AI assistants, MCP or OpenAPI clients. iTasks does not send data to them automatically. A user connects a chosen tool using their personal link for a specific workspace. Owners have automatic permission; other members need a grant from the owner or an administrator. The tool reads and modifies data within that user's current permissions. Users can update their keys, and owners or administrators can revoke a member's grant. The external provider's terms and privacy policy apply to its processing.

Task content, HelpDesk messages, files, and attachments may be available to members of the relevant workspace, members of the HelpDesk channel, the workspace owner, and an external AI tool when a user connects it with a personal AI access grant, within that user's current permissions. We do not sell personal data or share it with third parties for marketing purposes.

In addition to the third-party services listed above, we maintain internal operational metrics for monitoring, diagnostics, and service stability. Such metrics are generated and processed within the iTasks infrastructure in anonymized and aggregated form. iTasks does not train its own AI models on user tasks, messages, files, or HelpDesk data.

8. Data Retention

  • Workspace data — retained while the workspace is active. The owner can delete a workspace from the Mini App; when a workspace is deleted, associated data, including tasks, comments, files, HelpDesk channels, conversations, messages, attachments, AI Access settings, and time logs, is permanently and irreversibly deleted. If an unpaid workspace has no activity from any member for 180 days, iTasks warns the owner 14 days in advance and then automatically deletes only that workspace, fully freeing associated resources, including files in storage. Any activity by any workspace member before the deletion date automatically cancels deletion.
  • HelpDesk channel data — deleted together with the workspace or when the relevant HelpDesk channel is deleted by an owner or admin, including that channel's conversations, messages, history, and attachments.
  • Voice input sessions — the transcript, AI drafting result, and related technical fields are retained for up to 90 days by default, after which expired sessions are deleted. The audio stream is sent for real-time recognition and is not stored by iTasks as a separate audio file.
  • User account data — retained while the account is active or needed to access workspaces. During automatic deletion of an inactive workspace, a user is deleted only if no other workspaces remain after that workspace is removed. You can delete your account and personal data yourself at any time through the account deletion page. If you cannot delete your account yourself, contact support at support@itasksbot.com.
  • Android push tokens — retained while the device is registered for notifications and deleted when the device is unregistered, re-registered, or the account is deleted.
  • Server logs and security logs — technical logs, including IP addresses and request metadata, are generally retained for 90 to 180 days for diagnostics, security, abuse prevention, and incident investigation, unless a longer period is required by law or needed to investigate a specific incident.
  • Payment data — payment records (transaction IDs, amounts) are retained for the legally required period for financial record-keeping.
  • Token pack payment and consent audit — minimum purchase, refund, and accepted-document-version records are retained for the legally required period even after the user or workspace is deleted. The usable balance ceases to exist when the workspace is deleted; identifiers are deleted or anonymized after the mandatory period under the approved retention policy.

9. Your Rights (GDPR)

If you are in the EEA, you have the following rights under the GDPR:

  • Access — request a copy of your personal data
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your personal data
  • Restriction — request restriction of processing
  • Data portability — request your data in a machine-readable format
  • Objection — object to processing based on legitimate interests

To exercise any of these rights, contact us at support@itasksbot.com.

You also have the right to lodge a complaint with a supervisory authority in your country of residence.

10. Children's Privacy

The Service is intended for users aged 13 and older, in accordance with Telegram's minimum age requirements. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete such data.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.

12. Data Controller

For GDPR purposes, the personal data controller is the Service developer: Glazkov Pavel.

13. Contact Us

If you have questions about this Privacy Policy or your personal data, contact us: