TaskHolder Privacy Policy
TaskHolder Desktop is a planning app for Mac and Windows that works on your own computer. Your plans and files are never uploaded to us. To hold your trial and licence, we keep a small account: your email address, your licence status and your purchases. We use no analytics, no advertising and no tracking.
1. Your plans and files stay on your computer
- Everything you create in TaskHolder (projects, cards, statuses, clips, prompts, layouts and
agent run history) is stored on your computer: in the app's own storage and in the
.taskflowand export files you save. - Attached files stay where they are; TaskHolder stores a reference to them.
- None of this is sent to magentaLAB or any other service. No telemetry reads it.
- If the app crashes, a short error log (
main.log, up to about 1 MB) is kept on your computer. It is not sent anywhere; you can attach it to a support email if you want to.
2. Your account
TaskHolder needs an account to give you a trial and a licence. When you sign in we store:
| Data | Why |
|---|---|
| Email address, and the account identifier and profile (name, picture) that Google shares when you sign in with Google | To create your account and let you sign in |
| Trial and licence status and dates (trial start and end, licence status) | To give you the 14-day trial and your licence on every computer you sign in on |
| Purchases: date, amount, currency, status and the payment provider's order number | To unlock your licence, show your purchase history and handle refunds |
| On the website only: which installer you downloaded and when, and whether you agreed to product-update emails | Support, abuse prevention, and emails you asked for |
- There are no passwords. The app signs you in with Google; the website also offers one-time email links.
- We do not collect a device or machine identifier, and your licence is not tied to a device.
- Your sign-in session and licence are stored on your computer, encrypted with your system's keychain (macOS Keychain, Windows DPAPI).
3. When the app connects to the internet
| When | What is sent, and to whom |
|---|---|
| Signing in | Your browser opens Google's sign-in page and our sign-in service (Supabase).
The result comes back to the app on your own computer (127.0.0.1). |
| Licence check (at sign-in, every few minutes while the app is open, and when you return to it) | Your sign-in token goes to our licence service (Supabase), which replies with your licence status. Nothing about your projects is sent. |
| Update check (when the app starts) | A request to GitHub, where TaskHolder's releases are published, to see whether a new version exists. GitHub receives your IP address and the app's name. Updates download from GitHub only when you choose. |
| Buy, Support and Help links | They open taskholder.app in your browser; the support link includes the app's version number. |
The app loads no fonts, scripts or ads from the internet, and contains no analytics, crash reporting or advertising SDK.
4. Agent Control Tower (optional)
- The Agent Control Tower is off until you turn it on in Settings. It works only with Claude Code on your own computer and sends nothing over the internet. TaskHolder never calls an AI service, and needs no API key.
- When you connect it, TaskHolder adds entries to your Claude Code settings file
(
~/.claude/settings.json, or the project's.claude/settings.local.json) after showing you the change and saving a backup in TaskHolder's folder. Disconnect restores the file. - While it is on, Claude Code reports its activity to a file in TaskHolder's folder on your computer: session IDs and names, the working folder, tool names with a short target (such as a file path or command, up to 200 characters), and a short excerpt of Claude's last message (up to 600 characters). Your prompt text is not stored; only TaskHolder's card markers are read from it. With Detailed capture (off by default), tool inputs and outputs are kept, shortened.
- These activity files are deleted after 7 days without use. The run history you see on a card (time, outcome, a short last report) is saved in your project file.
- Run in Claude Code (Mac) writes the task text to a temporary file so Terminal can start the session; these files are deleted after 24 hours.
- Claude Code itself is Anthropic's product; what it sends to Anthropic is covered by Anthropic's terms and privacy policy, not by TaskHolder.
5. Purchases
Purchases are made on taskholder.app and processed by Polar as merchant of record. Polar handles checkout, payment, receipts, taxes and refunds, under its own privacy policy. Your card details go to Polar and its payment processors, never to us. We receive the order details listed in section 2, linked to your account so your licence can be unlocked.
6. Service providers
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase | Accounts, sign-in, licence and purchase records | supabase.com/privacy |
| Sign in with Google | policies.google.com/privacy | |
| Polar | Payments (merchant of record) | polar.sh/legal/privacy |
| GitHub | Publishing releases, update checks and downloads | GitHub Privacy Statement |
| Cloudflare | Hosting taskholder.app and this site | cloudflare.com/privacypolicy |
| Resend | Website sign-in emails and, if you agreed, product-update emails | resend.com/legal/privacy-policy |
These services process data only for the purposes above and under their own policies. We do not sell or share your data with anyone else, and we do not use it for advertising. Some of these services may process data outside your country under their standard safeguards.
7. Keeping and deleting your data
- On your computer: your data stays until you delete it. Uninstalling does not remove the
app's stored data; delete the folder
~/Library/Application Support/TaskHolder Desktop(Mac) or%APPDATA%\TaskHolder Desktop(Windows) and any.taskflowfiles you saved. - Your account: kept while your account exists. Delete it yourself at taskholder.app/account: this removes your sign-in, trial and licence, purchase display copy, download history and email preferences in one step. A purchased licence cannot be recovered after deletion. You can also ask us by email.
- Payment records are kept by Polar for the periods the law requires.
- Signing out removes the sign-in session and licence from your computer.
8. Children
TaskHolder is a productivity app for a general audience and is not directed to children under 14 (or the minimum age in your country). We do not knowingly collect their data.
9. Your rights
Depending on where you live (for example under the GDPR in the EEA and the UK, or Korea's Personal Information Protection Act), you have rights to access, correct, export and delete your personal data and to object to or restrict its processing. You can see and delete your account at taskholder.app/account; for anything else, email magenta23.lab@gmail.com. You may also lodge a complaint with your data protection authority.
10. Changes
If this policy changes, the new version will be posted here with a new effective date. If a change matters (for example, if the app starts sending crash reports), we will say so in the app's update notes before it takes effect.
11. Contact
magentaLAB
magenta23.lab@gmail.com · We reply within 72 hours. This address is
also our contact point for privacy questions.