Privacy Policy
Effective date: · Last updated:
1. Introduction
This Privacy Policy describes how iTasks (the "Service"), a task management app that operates as a Telegram bot, Telegram Mini App, web interface, and Android app operated by Glazkov Pavel ("we", "us", "our"), collects, uses, shares, and protects your personal data when you use our Telegram bot @iTasksBot, the Mini App, the website, or the Android app.
iTasks is not a Telegram product, is not affiliated with Telegram, and is not endorsed by Telegram. The Service uses the Telegram Bot API, Telegram Mini Apps, Telegram Login, Telegram Stars, and external payment providers as third-party integrations.
By using the Service, you agree to the collection and use of information as described in this policy. If you do not agree with this policy, please do not use the Service. Please also review our Terms of Service.
2. Data We Collect
When you use the Service, we may process the following categories of data:
Account and authentication data. Depending on how you sign in, we may process:
- Telegram User ID, Telegram Login/OIDC subject, display name or nickname, username, language, and avatar URL if provided by Telegram.
- Session data: internal user ID, linked sign-in providers, interface language, and timezone.
- Android push data: FCM push token, platform, app version, notification status, and device last-seen time.
Technical and analytics data. When you use the website, Telegram bot, Mini App, or Android app, information about screen views and feature usage, client technical parameters, IP addresses in server logs, browser or Android WebView information, and standard analytics infrastructure identifiers may be processed automatically. We use Google Analytics and Ahrefs Analytics on the website, as well as internal monitoring tools. Direct Telegram account identifiers, nicknames, task content, comments, HelpDesk messages, and files are not sent to third-party analytics services. Analytics and metrics data is transmitted over encrypted HTTPS/TLS connections and processed in anonymized, pseudonymized, or aggregated form where applicable.
Microphone in the Android app. Microphone access is requested only when you use voice rooms. The audio stream is transmitted in real time through RTC infrastructure to operate the room and is not recorded by us.
We do not request or store passwords, contacts, address book data, email addresses, precise location, or phone numbers.
3. Data You Create
In the course of using the Service, you may create the following content, which is stored on our servers:
- Workspaces and projects
- Tasks (titles, descriptions, statuses, priorities, deadlines, assignees, watchers, and links to customers, sprints, and workflows)
- Task comments, file attachments, and time tracking entries
- Task and project activity: creation, updates, status changes, assignee changes, workflow transitions, and related service events
- Customer records if you manage them inside a workspace
- HelpDesk data: support channels, connected Telegram bot settings, customer Telegram IDs and chat IDs, names, usernames, customer language, conversations, messages, message captions, internal notes, statuses, task links, files, images, documents, and voice messages
- Voice room metadata: room names, participants, invitations, and connection state. Real-time voice streams are transmitted to operate the room and are not recorded by us
- Integration settings, including HelpDesk and AI Access
4. How We Use Your Data
We use your data solely to provide and improve the Service:
- To identify you within your workspaces and display your name to team members
- To deliver task notifications and updates via Telegram
- To deliver Android push notifications through Firebase Cloud Messaging if you use the Android app and notifications are enabled
- To process bank-card payments through the selected payment provider or Telegram Stars payments in supported flows (if you subscribe to a paid plan)
- To set the appropriate interface language
- To receive, store, and process HelpDesk conversations, customer messages, internal notes, and attachments
- To provide AI Access only when the workspace owner explicitly enables this feature and connects an external AI tool
- To operate voice rooms and issue short-lived room access tokens
- To generate aggregated usage statistics and analyze feature demand
- To monitor service availability, diagnose incidents, prevent abuse, and provide technical support for the Service
Internal operational metrics are processed exclusively on iTasks servers in anonymized and aggregated form, are not shared with third parties, and are used solely for internal operational purposes related to the operation, security, and development of the Service.
Data processed through Google Analytics and Ahrefs Analytics is used for standard web and product analytics in anonymized or pseudonymized form. We do not send direct Telegram account identifiers, nicknames, task content, comments, HelpDesk messages, or files to analytics services, and we do not use analytics data for individual profiling outside the operation of the Service.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data on the following legal bases:
- Contract performance — processing is necessary to provide the Service you requested (Art. 6(1)(b) GDPR)
- Legitimate interests — to maintain and improve the Service, prevent abuse, and ensure security (Art. 6(1)(f) GDPR)
6. Data Storage and Security
Your data is stored on secure servers located in the European Union. File attachments are stored using DigitalOcean Spaces (S3-compatible cloud storage) with servers also located in the EU.
We take reasonable technical and organizational measures to protect your data against unauthorized access, loss, or alteration. However, no method of transmission over the Internet is 100% secure.
Data is transmitted over encrypted HTTPS/TLS connections. Access to production data is limited to what is necessary to operate, support, and secure the Service. File attachments are stored in private storage and are available only through authenticated service access.
7. Third-Party Services
The Service interacts with the following third-party services:
- Telegram — for the Telegram Bot API, Mini Apps, Telegram Login/OIDC, notifications, HelpDesk messages and attachments, and Telegram Stars payment processing in supported flows. Telegram's own privacy policy applies to data they process.
- Bank-card payment providers — for preparing the payment page, accepting payments, processing service payment notifications, refunds, and financial records for PRO subscriptions. The selected payment provider may process payment details, transaction identifiers, amounts, currencies, payment technical data, and information required to complete payment under its own privacy policy.
- DigitalOcean — for file storage (cloud infrastructure provider, EU servers).
- Google — for Firebase Cloud Messaging push notifications and website usage analytics via Google Analytics. Google may process standard technical identifiers, device, browser, or WebView information, push tokens, notification payloads, and interaction data in accordance with its own privacy policy. iTasks does not use Google as an authentication provider in the current public version and does not store user email addresses.
- Ahrefs — for website visit analytics via Ahrefs Analytics. Ahrefs may process standard technical identifiers, browser information, and page visit data in accordance with its own privacy policy.
- LiveKit or compatible RTC infrastructure — for voice rooms if this feature is used. Connection data and real-time audio streams pass through this infrastructure; iTasks does not record voice rooms.
- External AI tools connected by the workspace owner — for example ChatGPT/OpenAI, Claude, Gemini, MCP clients, or OpenAPI clients. iTasks does not send data to these tools automatically. Transfer occurs only when the workspace owner enables AI Access and gives an external tool access. That tool may read or modify workspace data within the enabled capabilities; the tool provider's own terms and privacy policy apply to its processing.
Task content, HelpDesk messages, files, and attachments may be available to members of the relevant workspace, members of the HelpDesk channel, the workspace owner, and an external AI tool if AI Access has been explicitly enabled by the owner. We do not sell personal data or share it with third parties for marketing purposes.
In addition to the third-party services listed above, we maintain internal operational metrics for monitoring, diagnostics, and service stability. Such metrics are generated and processed within the iTasks infrastructure in anonymized and aggregated form. iTasks does not train its own AI models on user tasks, messages, files, or HelpDesk data.
8. Data Retention
- Workspace data — retained while the workspace is active. The owner can delete a workspace from the Mini App; when a workspace is deleted, associated data, including tasks, comments, files, HelpDesk channels, conversations, messages, attachments, AI Access settings, and time logs, is permanently and irreversibly deleted.
- HelpDesk channel data — deleted together with the workspace or when the relevant HelpDesk channel is deleted by an owner or admin, including that channel's conversations, messages, history, and attachments.
- User account data — retained while the account is active or needed to access workspaces. You can request account and personal data deletion at any time by emailing support@itasksbot.com or through the account deletion page. Support requests are usually processed within 7 business days after account ownership is verified.
- Android push tokens — retained while the device is registered for notifications and deleted when the device is unregistered, re-registered, or the account is deleted.
- Server logs and security logs — technical logs, including IP addresses and request metadata, are generally retained for 90 to 180 days for diagnostics, security, abuse prevention, and incident investigation, unless a longer period is required by law or needed to investigate a specific incident.
- Payment data — payment records (transaction IDs, amounts) are retained for the legally required period for financial record-keeping.
9. Your Rights (GDPR)
If you are in the EEA, you have the following rights under the GDPR:
- Access — request a copy of your personal data
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your personal data
- Restriction — request restriction of processing
- Data portability — request your data in a machine-readable format
- Objection — object to processing based on legitimate interests
To exercise any of these rights, contact us at support@itasksbot.com.
You also have the right to lodge a complaint with a supervisory authority in your country of residence.
10. Children's Privacy
The Service is intended for users aged 13 and older, in accordance with Telegram's minimum age requirements. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete such data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or your personal data, contact us:
- Email: support@itasksbot.com
- Telegram: @itaskssupportbot (Contact Support)