Privacy Policy
Updated: Sep 4, 2026
1. What this covers
This policy explains what Cretask collects, why, where it is stored, who else can see it, how long it is kept, and how to get it back or have it deleted. It applies to the iOS app, the web dashboard and the hosted connector that lets an assistant such as Claude act on your workspace.
Cretask is built and run by a very small team. There is no advertising business behind it, no data brokerage, and no third party paying for access to what you store.
2. What we collect
Account data: your email address, your display name, and the authentication identifiers created when you sign in with email and password, Google or Apple. If you sign in with a provider, we receive the identifier and email that provider releases, not your password.
Workspace content: the tasks, subtasks, projects, plans, statuses, custom fields, comments and file attachments you create, along with who created or changed each one and when. This is the product, so it is the bulk of what we hold.
Operational data: request logs for the API and the connector endpoint, including the account and the API key or grant used, so that a change can be attributed and abuse can be stopped. We do not log the contents of your conversations with an assistant.
Billing data: whether your account is on a paid plan and when it renews. Card numbers never reach us; Apple or our web payment processor handles the payment and tells us only the entitlement result.
3. What we do not collect
There is no third-party advertising or analytics SDK in the apps or on this site. We do not track you across other websites, we do not build an advertising profile, and we do not sell or rent any of the above to anyone.
We do not use your workspace content to train machine-learning models, ours or anyone else's.
4. Where it is stored and who processes it
Cretask runs on Google Firebase: Firebase Authentication for accounts, Cloud Firestore for workspace content, and Cloud Storage for attachments. Google processes that data on our behalf as a subprocessor. The web dashboard and the connector endpoint are hosted on Vercel.
The in-app AI planning feature sends the goal text you type, and nothing else, to OpenAI in order to return a task breakdown. That call happens in a server function; the API key never reaches your device. If you plan through Claude instead, no OpenAI call is made at all: the assistant does the reasoning and Cretask only stores the result.
Payments are processed by Apple for purchases made inside the iOS app, and by our web payment processor acting as merchant of record for purchases made on the web. Each has its own privacy policy covering the payment itself.
5. The connector, in plain terms
Connecting Cretask to an assistant grants that assistant access to your workspace under the scopes you approve on the consent screen: reading tasks and projects, creating and updating them, and adding notes. Read-only is a valid choice and is offered first.
Every write made through the connector is recorded with the actor that made it, so a task an assistant created reads as a task an assistant created, and a batch of changes can be undone as a unit. You can revoke the grant at any time from Settings, Security, and access stops immediately.
Cretask does not read your chat history, your assistant's memory, or any file you have shared with it. The connector only ever sees the arguments of the specific tool call being made.
6. How long we keep it
Workspace content is kept for as long as your account exists, because it is the thing you came for. Activity history is trimmed on a schedule: ninety days of change history, and a thirty-day window in which a batched change can be undone.
When you delete your account, your workspace data is removed within thirty days. Backups age out on their own cycle shortly after that. Records we are legally required to keep, such as invoices, are kept for the period the law requires and nothing longer.
7. Your rights
You can export your entire workspace as JSON and CSV from Settings at any time, without asking us. You can correct your account details in the app, and you can delete your account and everything in it from Settings, Delete account.
If you are in a jurisdiction that grants rights of access, correction, portability, erasure, restriction or objection, those rights apply here, and you can exercise them by emailing support@cretask.com. We answer within one month. You also have the right to complain to your local data protection authority.
8. Security, children and changes
Data is encrypted in transit and at rest by the platforms above, access rules are scoped per user and per workspace, and API keys are scoped to a single workspace and revocable. No system is perfect; if a breach affects you, we will tell you.
Cretask is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will remove it.
We may update this policy. The date at the top of this page always reflects the current version, and a material change is announced in the product before it takes effect. Questions go to support@cretask.com.
Start getting things done
Bring every task, project and plan into one place, and let Claude do the busywork alongside you.