Policy

Privacy Policy

Last updated: July 21, 2026

Current release status Taskliner is local-first. Optional Google Drive sync uses end-to-end encrypted files, and optional Discord completion sharing uses the Webhook URL you provide. Cloudflare Web Analytics measures page views and performance. Advertising and error-reporting SDKs are not enabled.

Who operates Taskliner

Taskliner is an independent software project operated from Japan. For privacy or security questions, contact [email protected].

What Taskliner stores in your browser

When you use the app, task titles, notes, due dates, completion state, outline structure, and app settings are stored in your browser. The current release uses IndexedDB as its local data store and may retain the legacy localStorage["taskliner-v1"] copy while migration and recovery safeguards are in place.

This data is not sent to a Taskliner database. Clearing browser storage can remove your local copy, so use the JSON export in the File menu when you need a portable backup.

Optional Discord completion sharing

If you explicitly enable Discord completion sharing and provide your own Discord Incoming Webhook URL, the browser sends a completion update directly to that Discord channel. Taskliner does not proxy or store these posts on an operator server.

The selected visibility level controls whether the post contains only a generic progress message, the top-level category, or the completed task title. Without Google sync, the Webhook setting stays on that device. With encrypted sync enabled, the Webhook URL and sharing settings are included only as encrypted shared settings. Pending and failed completion posts remain local and are never synced or included in task JSON exports. Discord processes received posts under its own terms and privacy policy.

Information processed by the website

These providers may process information outside Japan. The current release does not include an advertising script or a third-party error-reporting service. If you enable sync, the browser uses Taskliner’s Cloudflare Pages Functions and Google Drive API to access only the drive.appdata area.

Google authorization and Drive sync

When you explicitly connect Google, Google’s authorization endpoint handles account selection and consent. Taskliner requests only the openid, email, and drive.appdata scopes. Cloudflare Pages Functions exchange the authorization code and keep an encrypted refresh token so the browser does not need to start an OAuth redirect on every reload. Taskliner does not request access to ordinary Drive files.

Before upload, the browser encrypts each device state and shared setting with a random 256-bit workspace data key using AES-256-GCM. Cloudflare Pages Functions validates and relays only the encrypted artifact and its outer metadata, and Google Drive stores the encrypted files in appDataFolder. Taskliner does not store task content, the workspace key, or Discord Webhook URLs in D1 or KV. When you connect Google, D1 stores your Google account identifier and email address, the encrypted OAuth refresh token, and non-secret synchronization metadata such as workspace and encryption cutover status.

The workspace key is protected on a returning device by a non-extractable browser key. A Taskliner passkey using the WebAuthn PRF extension can protect a synchronized key wrapper. If PRF is unavailable on the first device, saving a randomly generated recovery file is required before sync starts. A new device can use the synchronized passkey, approval from an existing device, or the recovery file. If all approved devices, usable passkeys, and recovery files are lost, neither Taskliner nor Google can recover the encrypted data.

End-to-end encryption protects synchronized data in Google Drive, while passing through Cloudflare, and from Taskliner’s backend. Local task data remains readable in IndexedDB. It does not protect an unlocked browser profile, malicious code executing in the Taskliner page after unlock, compromised devices, or information contained in ordinary network metadata and access logs.

Disconnecting Taskliner removes the local session; it does not delete encrypted Drive files or the refresh token shared by other devices. “Disconnect Google everywhere” revokes Google access and removes that stored refresh token and account record from Taskliner. Drive deletion is a separate explicit action. An empty or externally deleted Drive snapshot is not treated as a command to erase the local document.

Choices and deletion

Children

Taskliner is not directed to children under 16 and is not designed or advertised as a service for children.

Changes to this policy

We will update this page when data practices change, especially before enabling advertising or additional account features. The effective date at the top of this page will change with the policy.