Cookie Policy

This Cookie Policy explains the necessary and optional cookies used across taskmachine.io, its application subdomain, taskmachine.run, and our legacy public domain iterationlayer.com. It should be read with the Privacy Policy.

Last updated: 10 September 2026

Who is responsible

Task Machine is operated by Fabian Schucht, C. General Vives 1 6E, 35006 Las Palmas de Gran Canaria, Spain, NIE: Z1096165J. For cookie or privacy questions, email [email protected] .

Cookies and similar technologies

Cookies are small data files a website stores in your browser. First-party cookies are set for a Task Machine domain. Third-party cookies are set or read by another provider when its service is used on the page. Session cookies expire with a browsing session, while persistent cookies remain until their stated expiry or earlier deletion.

Task Machine also uses browser storage for limited session, preference, and analytics state. Browser storage is not a cookie, but it can remember information in a similar way and is covered by this policy where Task Machine or DataFast uses it.

How cookies are used

Necessary cookies keep sessions, forms, account-specific browser features, saved generated-playbook references, and your analytics choice working. These cookies do not require analytics consent because they provide a service you request, protect the service, or remember the privacy choice itself. Blocking them can prevent sign-in, forms, or saved preferences from working.

Optional DataFast analytics cookies recognize returning public visitors, continue a consented journey across our current and legacy public domains, and connect that journey with a later checkout. DataFast runs in cookieless mode before acceptance and after rejection, without creating these persistent identifiers. We do not use advertising cookies.

Cookies and retention

Cookie Category and purpose Retention
cf_clearance Necessary security, when a Cloudflare edge challenge is passed. Remembers the successful challenge so legitimate requests can reach the service without repeating it. Our separate Turnstile form widget is not configured to issue this pre-clearance cookie. 30-minute configured challenge passage, with Cloudflare's clock-skew allowance and additional validation time for XMLHttpRequests.
_task_machine_key Necessary. Signed session data keeps you authenticated, carries requested navigation state, and supports cross-site request forgery protection. 1 year, or until sign-out
tm_browser_device Necessary app preference. Assigns a random identifier to a signed-in browser profile for browser-specific notification setup and status. It is not created on ordinary public website pages. 1 year
tm_generated_playbook Necessary saved reference. Lets a visitor return from the playbook gallery to a generated playbook proposal they previously opened. 1 year
tm_analytics_consent Necessary consent record. Remembers whether you accepted or rejected optional persistent DataFast analytics cookies so the website honors your choice. 1 year
datafast_visitor_id Optional analytics. Recognizes a consented returning browser for acquisition and conversion attribution. 1 year
datafast_visitor_first_seen_at Optional analytics. Records when the consented browser was first observed. 1 year
datafast_visitor_session_count Optional analytics. Counts sessions for journey and attribution analysis. 1 year
datafast_session_id Optional analytics. Groups consented public website activity into a session. 30 minutes
datafast_session_start Optional analytics. Records the start time used to expire the current session. 30 minutes

Cloudflare security processing is separate from optional analytics. Its proxy and challenge services can process IP addresses, browser and TLS signals, and request metadata even when no Cloudflare cookie is set. Cloudflare's global processing can include the United States. Rejecting analytics does not disable these security services.

After acceptance, the DataFast SDK may mirror persistent identifiers in local or session browser storage to preserve analytics state. Rejecting or withdrawing acceptance removes the known persistent DataFast cookie and browser-storage keys and prevents Task Machine from forwarding those identifiers to checkout. Cookieless mode may still use session-only storage for continuity within the current browser tab.

Analytics

Cookieless DataFast analytics runs on the public website by default. Before you accept analytics, and after rejection, DataFast can process page paths, referrers, campaign parameters, IP address, and user agent. It derives a server-side pseudonymous visitor identifier from IP address, user agent, site domain, and a salt that rotates about every 24 hours, and does not link visitors across our domains. After you select Accept, DataFast can additionally use persistent visitor and session identifiers, carry journey parameters between taskmachine.io and iterationlayer.com, and connect that journey with checkout attribution.

Product activity in the signed-in app is measured server-side through PostHog Cloud (EU) without analytics cookies, a browser SDK, or session replay. PostHog events use identifiers and bounded operational metadata rather than prompts or content.

Your analytics choice

The first public website visit presents equally available Reject and Accept choices for persistent analytics cookies. Rejecting does not limit public website access and keeps DataFast in cookieless mode. To review or change your choice later, remove the site's consent cookie in your browser's site-data controls and reload the page. Your choice and browser data are specific to each browser and domain, so you may need to repeat it on another browser, device, or Task Machine domain. Withdrawing acceptance returns DataFast to cookieless mode, removes known persistent DataFast identifiers from the browser, and stops forwarding those identifiers to checkout.

You can also delete or block cookies in your browser. Browser controls can remove necessary cookies too, which may sign you out, reset saved proposal references, or prevent parts of the service from working.

Changes and contact

We may update this Cookie Policy when browser storage or providers change. Material changes update the date above and may require a new choice. Personal data is handled under the Privacy Policy.