Privacy Policy
This Privacy Policy explains how Task Machine handles personal data across the public website, accounts, workspaces, subscriptions, local and managed agent runs, support, and product operations.
Version and last updated: 31 August 2026
Who is responsible
Fabian Schucht is the controller for account administration, the public website, direct customer relationships, security, product analytics, and support. When a business customer submits personal data for Task Machine to process on its behalf, that customer is normally the controller and Task Machine acts as its processor under the Data Processing Addendum.
Fabian Schucht
C. General Vives 1 6E
35006 Las Palmas de Gran Canaria
Spain
NIE: Z1096165J
What we collect
-
Account and commercial data
This includes your name, email address, authentication provider, locale and timezone preferences, workspace memberships, invitations, role information, subscription status, transaction identifiers, billing country and currency, support requests, and legal-policy acceptance records. Link, as merchant of record for Managed Payments, collects payment details directly. Task Machine does not receive complete card details.
Historical waitlist records contain the name and email address submitted before public signup opened. We retain them to send the launch announcement and handle related follow-up, and they do not grant account access or workspace membership.
-
Commercial inquiries and service requests
A public on-premises inquiry contains the work email, message, optional name and company you submit. We use these details to evaluate and respond to your commercial request as steps before a possible contract and for our legitimate interest in handling business inquiries. The submission becomes an inquiry Task in an operator-controlled Operations project and is available only to authorized operators, including the agent configured for that intake channel. The form accepts no uploads. We use the request IP address only for transient abuse controls and Cloudflare verification and do not put the request IP address into the resulting Task. Product analytics receives only the inquiry Task identifier, never the submitted contact details or message.
If a workspace manager requests higher service limits, we send the workspace name, requester's account email, current and requested values, and reason to the operator-controlled Operations project so authorized operators can evaluate and respond. Submitting the request does not change limits automatically. Product analytics receives only the resulting Operations Task identifier with workspace and actor identifiers, never the requested values or reason.
-
Workspace and run content
This can include tasks, goals, projects, chats, comments, documents, uploads, workflow definitions, connector configuration, credentials you place in the Vault, and complete agent-run records. Run records can contain prompts and instructions, supplied context, conversation messages, tool names, tool inputs and outputs, model responses, reasoning reported by the coding tool or model, logs, errors, usage and cost metadata, status events, and final output. This content can contain personal data or confidential information depending on what you submit and what connected tools return.
-
Browser-use visual history
When an authorized agent uses Task Machine's browser for a Task or Chat, we automatically keep an ordered action log. Automatic masked viewport images are enabled by default at workspace level; workspace owners and admins can disable future images while action logs continue. This history can include the page location without its query or fragment, accessible labels for elements the agent used, command outcomes, timestamps, and third-party page content visible in a frame. We do not store browser command values, Vault references, upload paths, raw browser errors, URL user information, queries, or fragments in this history. Password, payment, one-time-code, Vault-filled, and known exact-secret content is masked before capture, and a masking failure withholds the frame. Other visible page content can still contain personal data or confidential information. Existing images remain unless the owner or admin chooses irreversible screenshot deletion when disabling the setting.
-
Execution metadata
Local execution metadata includes machine and worker identifiers, supported coding tools, versions, capabilities, run status, timestamps, and transcript events sent by the local daemon. Managed execution can additionally process source files, repository history, working files, process state, and provider resource identifiers.
-
Website, analytics, and security data
This can include requested pages, timestamps, IP address, user agent, referrer, campaign parameters, cookie choices, and security or diagnostic events. Cookieless DataFast analytics derives a server-side pseudonymous visitor identifier from IP address, user agent, site domain, and a salt that rotates about every 24 hours. Persistent DataFast visitor and session identifiers are created only after analytics-cookie acceptance.
-
Abuse-prevention data
When you submit an on-premises inquiry or request a magic sign-in link, Cloudflare Turnstile may process your IP address, browser and request metadata, a single-use challenge token, and challenge interaction signals to help us distinguish people from automated abuse. We do not send your email address or other form content to Turnstile, and we do not store its challenge token or response.
-
Browser and device data
In the signed-in app, we store a random browser-profile identifier with normalized browser and operating-system families and recent sign-in and activity times. This pseudonymous record supports browser-specific notification setup. It does not identify physical hardware and does not include your raw user agent, IP address, or fingerprinting characteristics.
Sources of personal data
We collect information you provide directly when you create an account, join a workspace, submit content, configure a connector, contact support, make a commercial inquiry, or manage a subscription. A workspace customer or another member may also provide your information when they invite you or submit content about people connected with their work.
Connected services can return identity, repository, communication, file, public-web, and tool-result data according to the connection and instructions you or your workspace selected. Google can provide account information when you choose Google authentication. Link and Stripe provide transaction status and limited billing records without giving Task Machine complete card details.
We collect website, device, usage, and security information automatically when browsers, local daemons, managed workers, and connected services communicate with Task Machine. The categories and limits of that collection are described above and in the Cookie Policy.
Purposes and legal bases
We use personal data to create and secure accounts, operate workspaces, execute and resume agent work, keep browser-use visual audit history, deliver model and connector requests, keep run history, provide support, process subscriptions and refunds, prevent abuse, diagnose failures, improve the product, communicate service information, and meet legal obligations.
We rely on performance of a contract and steps requested before a contract to provide accounts, workspaces, support, and paid service. We rely on legitimate interests to secure and improve Task Machine, prevent abuse, support customers, keep appropriate business records, and measure public reach, after considering the effect on the people involved. We rely on legal obligations for tax, accounting, regulatory, and lawful-request records. We rely on consent for optional persistent public-website analytics cookies and optional communications where consent is required.
You can withdraw consent without affecting earlier lawful processing. You may object to processing based on legitimate interests, and we will assess the request against any compelling legitimate grounds or legal requirements that apply.
Analytics and cookies
Cookieless DataFast analytics runs on the public website by default. Before you accept analytics, and after rejection, DataFast can process page paths, referrers, campaign parameters, IP address, and user agent, use session-only browser storage, and derive a server-side pseudonymous visitor identifier with an approximately daily rotating salt. This mode does not link visitors across taskmachine.io and iterationlayer.com or forward identifiers to checkout. After you choose Accept, DataFast can additionally use persistent first-party visitor and session identifiers, briefly carry pseudonymous journey parameters between those domains, and connect that journey with Stripe revenue attribution. We do not use DataFast for advertising or unrelated cross-site tracking.
Signed-in product activity is measured server-side through PostHog Cloud (EU). Events contain identifiers, enumerations, counts, durations, routes, and cost figures rather than prompts, message bodies, file contents, names, email addresses, or raw errors. PostHog receives an IP address only for user-originated events where geolocation is used. No PostHog browser SDK, analytics cookie, session replay, or public website page-view tracking is enabled.
The Cookie Policy lists each browser cookie and explains how to change your choice. Read the Cookie Policy .
How we share personal data
We do not sell personal data. We do not use personal data for targeted advertising or unrelated cross-site tracking. If we create aggregated or de-identified information for service analysis, we use it only where people and customers are not reasonably identifiable and do not attempt to re-identify it.
We use Scaleway for hosting, managed PostgreSQL, object storage, transactional email, observability, and backups. Blaxel processes managed sandbox and worktree data. PostHog Cloud (EU) provides product analytics, DataFast provides cookieless public website analytics with optional consent-based persistent attribution, Cloudflare provides Turnstile abuse prevention, and OpenRouter and the selected downstream model provider process managed model requests. Customer-selected connectors, including Exa when you install or invoke it, and local coding tools receive data only when you or your workspace configure or invoke them.
Link is the merchant of record for Managed Payments and processes payment, tax, fraud, refund, and dispute data as an independent controller under its own terms. Authentication services and customer-selected coding tools, model providers, MCP servers, and connectors may also act under their own privacy terms when you or your workspace choose them.
We may disclose limited information to professional advisers, insurers, auditors, public authorities, courts, or other parties when reasonably necessary for advice, legal compliance, security, claims, or the protection of rights. Information may also be disclosed as part of a proposed or completed corporate transaction, financing, reorganization, or transfer of the business, subject to appropriate confidentiality and data-protection safeguards.
View the Subprocessor Schedule or read the Data Processing Addendum.
Retention and deletion
Account, workspace, task, chat, transcript, browser-use action history, and related product records are normally kept while the account or workspace remains active and afterward only for as long as needed for service operation, security, disputes, legal obligations, or an agreed customer instruction. Browser-use records and remaining private frames follow their owning Task or Chat and do not have a separate automatic expiry. Disabling future browser-use screenshots retains existing images unless the owner or admin chooses irreversible deletion; that deletion removes matching active-storage images while preserving action logs, and residual backup copies expire through applicable backup cycles. Historical waitlist contact details remain until the launch announcement and related follow-up are complete or the contact asks us to delete them, subject to applicable legal obligations. A public inquiry Task and its submitted contact details remain under that operator project lifecycle until they are no longer needed for inquiry follow-up, legal obligations, or a related contract. Archiving a workspace or record does not delete its history. Signed-in users can submit a privacy request from the Privacy and data page; otherwise, contact us by email. We assess each request's records, scope, and legal obligations.
Scaleway Cockpit application logs are configured for 30 days and metrics for 15 days. Deleted Vault credentials remain recoverable from trash for 30 days before permanent purge. Managed worktree files are retained for 60 days after each managed run and then deleted on the date shown in the product. Another managed run extends that date. The Task or Chat, transcript, comments, receipts, and separately saved results remain under the ordinary product-record lifecycle. Local worktree files remain on the customer's machine and are not deleted by Task Machine.
Provider records and backup copies follow the applicable provider settings and backup cycles. When primary data is deleted, residual backup copies are removed as those backup cycles expire unless preservation is required for security, legal claims, tax, accounting, fraud prevention, or another legal obligation. Analytics records follow the configured vendor retention settings.
International transfers
Task Machine is operated from Spain and uses EU infrastructure where stated in the Subprocessor Schedule. Some providers and selected model developers may process data outside the EEA. Where required, we rely on an adequacy decision, the European Commission Standard Contractual Clauses, or another lawful transfer mechanism and assess supplementary safeguards.
Your choices and rights
Depending on applicable law, you may request access, rectification, deletion, restriction, portability, or objection. You may withdraw consent where processing relies on consent. Signed-in users can submit a request through the Privacy and data page, while anyone may contact us by email. We may ask for information needed to verify your identity, authority, and request scope. An authorized representative may submit a request where applicable, but we may require proof of that authority and verify the request with you.
A workspace customer may need to handle requests concerning personal data it controls, and Task Machine will assist that customer as described in the Data Processing Addendum. You may complain to the Agencia Española de Protección de Datos or another competent supervisory authority in your place of residence, work, or the alleged infringement. Task Machine does not use personal data to make solely automated decisions that produce legal or similarly significant effects about you.
Children
Task Machine is not directed to children. You must be at least 18 years old to create an account or purchase a subscription.
Changes and contact
We may update this policy as Task Machine, its providers, or legal requirements change. Material changes receive a new version and an appropriate notice or renewed acknowledgement where required.
For privacy requests, email [email protected] .