Cookie Policy
This Cookie Policy explains the necessary and optional cookies used across taskmachine.io, its application subdomain, taskmachine.run, and our legacy public domain iterationlayer.com. It should be read with the Privacy Policy.
Last updated: 10 September 2026
Who is responsible
Task Machine is operated by Fabian Schucht, C. General Vives 1 6E, 35006 Las Palmas de Gran Canaria, Spain, NIE: Z1096165J. For cookie or privacy questions, email [email protected] .
Cookies and similar technologies
Cookies are small data files a website stores in your browser. First-party cookies are set for a Task Machine domain. Third-party cookies are set or read by another provider when its service is used on the page. Session cookies expire with a browsing session, while persistent cookies remain until their stated expiry or earlier deletion.
Task Machine also uses browser storage for limited session, preference, and analytics state. Browser storage is not a cookie, but it can remember information in a similar way and is covered by this policy where Task Machine or DataFast uses it.
How cookies are used
Necessary cookies keep sessions, forms, account-specific browser features, saved generated-playbook references, and your analytics choice working. These cookies do not require analytics consent because they provide a service you request, protect the service, or remember the privacy choice itself. Blocking them can prevent sign-in, forms, or saved preferences from working.
Optional DataFast analytics cookies recognize returning public visitors, continue a consented journey across our current and legacy public domains, and connect that journey with a later checkout. DataFast runs in cookieless mode before acceptance and after rejection, without creating these persistent identifiers. We do not use advertising cookies.
Cookies and retention
| Cookie | Category and purpose | Retention |
|---|---|---|
| cf_clearance | Necessary security, when a Cloudflare edge challenge is passed. Remembers the successful challenge so legitimate requests can reach the service without repeating it. Our separate Turnstile form widget is not configured to issue this pre-clearance cookie. | 30-minute configured challenge passage, with Cloudflare's clock-skew allowance and additional validation time for XMLHttpRequests. |
| _task_machine_key | Necessary. Signed session data keeps you authenticated, carries requested navigation state, and supports cross-site request forgery protection. | 1 year, or until sign-out |
| tm_browser_device | Necessary app preference. Assigns a random identifier to a signed-in browser profile for browser-specific notification setup and status. It is not created on ordinary public website pages. | 1 year |
| tm_generated_playbook | Necessary saved reference. Lets a visitor return from the playbook gallery to a generated playbook proposal they previously opened. | 1 year |
| tm_analytics_consent | Necessary consent record. Remembers whether you accepted or rejected optional persistent DataFast analytics cookies so the website honors your choice. | 1 year |
| datafast_visitor_id | Optional analytics. Recognizes a consented returning browser for acquisition and conversion attribution. | 1 year |
| datafast_visitor_first_seen_at | Optional analytics. Records when the consented browser was first observed. | 1 year |
| datafast_visitor_session_count | Optional analytics. Counts sessions for journey and attribution analysis. | 1 year |
| datafast_session_id | Optional analytics. Groups consented public website activity into a session. | 30 minutes |
| datafast_session_start | Optional analytics. Records the start time used to expire the current session. | 30 minutes |
Cloudflare security processing is separate from optional analytics. Its proxy and challenge services can process IP addresses, browser and TLS signals, and request metadata even when no Cloudflare cookie is set. Cloudflare's global processing can include the United States. Rejecting analytics does not disable these security services.
After acceptance, the DataFast SDK may mirror persistent identifiers in local or session browser storage to preserve analytics state. Rejecting or withdrawing acceptance removes the known persistent DataFast cookie and browser-storage keys and prevents Task Machine from forwarding those identifiers to checkout. Cookieless mode may still use session-only storage for continuity within the current browser tab.
Analytics
Cookieless DataFast analytics runs on the public website by default. Before you accept analytics, and after rejection, DataFast can process page paths, referrers, campaign parameters, IP address, and user agent. It derives a server-side pseudonymous visitor identifier from IP address, user agent, site domain, and a salt that rotates about every 24 hours, and does not link visitors across our domains. After you select Accept, DataFast can additionally use persistent visitor and session identifiers, carry journey parameters between taskmachine.io and iterationlayer.com, and connect that journey with checkout attribution.
Product activity in the signed-in app is measured server-side through PostHog Cloud (EU) without analytics cookies, a browser SDK, or session replay. PostHog events use identifiers and bounded operational metadata rather than prompts or content.
Your analytics choice
The first public website visit presents equally available Reject and Accept choices for persistent analytics cookies. Rejecting does not limit public website access and keeps DataFast in cookieless mode. To review or change your choice later, remove the site's consent cookie in your browser's site-data controls and reload the page. Your choice and browser data are specific to each browser and domain, so you may need to repeat it on another browser, device, or Task Machine domain. Withdrawing acceptance returns DataFast to cookieless mode, removes known persistent DataFast identifiers from the browser, and stops forwarding those identifiers to checkout.
You can also delete or block cookies in your browser. Browser controls can remove necessary cookies too, which may sign you out, reset saved proposal references, or prevent parts of the service from working.
Changes and contact
We may update this Cookie Policy when browser storage or providers change. Material changes update the date above and may require a new choice. Personal data is handled under the Privacy Policy.