Privacy Policy

Effective Date: September 28, 2026

Neotask, Inc. ("Neotask," "we," "us," or "our"), a Delaware corporation, operates the Neotask application, platform, and related services (the "Service"). This Privacy Policy describes how we collect, use, store, and protect your information when you use Neotask across desktop (macOS, Windows, Linux), iOS, and the web dashboard, and when you visit our websites.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.

1. Information We Collect

a. Account Information

When you create an account using Apple Sign-In or Google Sign-In, we receive your name and email address as provided by the authentication provider. We do not receive or store your Apple ID password, Google password, or any other authentication credentials from these providers. When you activate a desktop license, we collect your license key and a device fingerprint used solely for device binding.

b. Agent and Deployment Configuration

When you configure and deploy AI agents through Neotask, we collect the selections you make, including your chosen AI models, messaging channels, agent configurations, skill settings, automation schedules, and deployment preferences. If you connect messaging channels such as Telegram, Discord, Slack, or WhatsApp, you provide credentials (bot tokens, OAuth grants, or QR code sessions) used solely to connect your agents to those platforms.

c. Usage and Billing Data

We collect usage data to operate the Service and calculate usage fees, including token consumption (input, output, cache read, and cache write tokens), model and provider usage, session activity, agent activity, tool call counts, and scheduling execution records. We also collect usage data for service improvement, including session identifiers, feature interactions, deployment events, timestamps, and general device information (platform, OS version). We do not collect precise GPS geolocation; where we derive location for analytics or fraud prevention, it is an approximate location (such as country, region, or city) computed from an anonymized IP address.

d. Chat and Message Data

Except as described below for local models, messages sent to and from your deployed AI agents are processed through the third-party AI model provider configured for that agent (for example Anthropic, OpenAI, Google, or providers reached via OpenRouter). We store message data — including message content and any attachments you provide — to maintain conversation context, enable session history, and provide the chat interface. We do not use your message content for advertising and we do not sell it to third parties. We do not use your content to train our own models.

When an agent uses a local model that you set up in the Neotask desktop app, that model runs on your own computer, or on another computer on your local network that you choose to connect, and the agent's messages are not sent to an AI model provider for that model's processing. We still store those messages as described above. A turn on a local model can still use hosted features that send content to their providers, such as image or media understanding, audio transcription, image generation, and web search. The agent can also hand work to other agents or subagents that use hosted models. If the agent's fallback models include a hosted model, or your default model is a hosted model, a turn that the local model cannot complete may continue on that hosted model, and that model's provider receives the turn; later turns in the same conversation may also continue on that model. The optional setting "Use a local model when your default model fails" does not change where your default model runs: it adds your local model as a fallback that is used only when your default model cannot answer. If a model server you connect forwards requests to an online service, such as an Ollama cloud model, that service receives them.

e. Website, Marketing, Sales, and Support Data

When you interact with our websites we may collect the information you submit (such as your email address on a waitlist form, or your name, email, phone number, and message on a contact or demo-booking form) together with technical context such as your IP address, browser user agent, referrer, and the approximate location derived from an anonymized IP address. If advertising measurement is enabled and you separately provide exact marketing-and-advertising consent, Meta Pixel and Meta's Conversions API may process the Meta browser identifiers _fbp and _fbc, and Reddit Pixel and Reddit's Conversions API v3 may process the Reddit browser identifier _rdt_uuid. These providers may also process a pseudonymous event reference, event type and time, and bounded purchase, trial, or subscription value and currency. Google Ads measurement may receive consent-gated measurement signals through Google tag. These advertising services are off by default, disabled in HIPAA mode, overridden by GPC or DNT, and do not receive chat content, agent content, license keys, or payment-card details from these integrations.

If you speak with our sales or support team by phone or through in-product voice features, those calls may be recorded and transcribed for quality, training, and record-keeping purposes. Where the law requires, you will be notified and/or asked for consent before recording begins. Call recordings are scrubbed on a fixed schedule (see Data Retention below); transcripts and summaries are retained as business records.

2. How We Use Your Information

We use the information we collect to:

Legal Bases for Processing (EEA / UK / comparable law)

Where the GDPR or a comparable regime applies to you, we rely on the following legal bases to process your personal data:

3. Third-Party Services and Subprocessors

Neotask integrates with the following categories of third-party services. Your use of these services is subject to their respective privacy policies. The complete, current list of our subprocessors — what each one does, where it processes data, and whether it is a core provider or only used if you connect it — is published at neotask.ai/subprocessors, and we update that page whenever the list changes:

4. Cookies and Similar Technologies

We use cookies and similar technologies for essential operation and privacy-minimized site measurement. For a positively identified United States visitor, Google Analytics 4, DataFast, browser Sentry, Intercom, and first-party site analytics may operate by default on public pages until you deny cookies. In the EEA, UK, Switzerland, and any unknown region, those analytics runtimes stay absent until our server validates the exact latest analytics-consent receipt for the current session. Meta Pixel, Meta's Conversions API, Reddit Pixel, Reddit's Conversions API v3, and Google Ads measurement always require a separate exact marketing-and-advertising consent receipt. Global Privacy Control (GPC) and Do Not Track (DNT) disable analytics and advertising measurement in every region.

For the full list of cookies we set, what they do, how long they last, and how to manage them, see our Cookie Policy.

Advertising Measurement Notice (Authoritative English)

Effective July 14, 2026

Only when Neotask enables advertising measurement and you separately provide exact marketing-and-advertising consent may Google Ads measurement, Meta Pixel and Meta's server-side Conversions API, or Reddit Pixel and Reddit's Conversions API v3 operate. Meta Platforms, Inc. may receive consented _fbp/_fbc browser identifiers, and Reddit, Inc. may receive the consented _rdt_uuid browser identifier. Each enabled provider may receive the origin and bounded path of an approved public page, ordinary browser IP address and User-Agent network metadata, a pseudonymous event reference, event type and time, and bounded purchase, trial, or subscription value and currency. Browser pixels may also receive the referring page information ordinarily exposed by the browser. Encrypted advertising attribution expires after 90 days and each provider's conversion outbox after 180 days; withdrawal cancels pending delivery and removes the encrypted identifier envelope. The Reddit server API token is held only in AWS SSM and is never sent to the browser. Google enhanced conversions, ad personalization, and Google signals are disabled. These integrations are off by default, disabled in HIPAA mode, honor GPC and DNT, and do not receive chat content, agent content, license keys, or payment-card details from these integrations.

5. Data Storage and Security

Your account data, agent configurations, session history, and deployment settings are stored on secured servers. We use industry-standard security measures including encrypted connections (TLS 1.3), token-based authentication (JWT), HMAC-SHA256 request signing, and access controls to protect your data.

All API keys, bot tokens, and secrets are encrypted at rest using AES-256-GCM with versioned encryption keys. Keys are decrypted only at runtime when needed and are never exposed in logs or error messages. Billing and audit records are kept in append-only, tamper-evident ledgers. You may revoke any connected credentials at any time through the respective platform or through the Neotask dashboard.

The Neotask desktop application runs a local gateway on loopback (127.0.0.1) only, with no external network exposure, and encrypts locally cached credentials using your operating system's secure keystore (macOS Keychain, Windows Credential Manager, or Linux libsecret). While we implement commercially reasonable safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Sharing

We do not sell, rent, or trade your personal information to third parties. We may share information only in the following circumstances:

7. Data Retention and Deletion

We retain personal data only as long as needed for the purposes described in this policy. Our standard retention periods are:

You may request deletion of your account and associated personal data at any time by using the account deletion feature in Settings (Account → Danger Zone → Delete Account) or by contacting us at [email protected]. Upon receiving a verified deletion request, we delete your personal data across our systems — and revoke connected-service tokens and cancel payment-processor records — without undue delay and within one month, except where limited retention is required by law (for example, financial records noted above).

8. Children's Privacy

The Service is not directed to children and is intended for adults and users who meet the minimum age below. We do not knowingly collect personal information from children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be up to 16 in some EEA countries). If we become aware that a child has provided us with personal information, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at [email protected].

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

You can exercise the most common rights yourself, instantly: use Download my data in account settings to export a complete, machine-readable copy of your data (access and portability), and Delete Account in Settings → Account → Danger Zone to erase it.

To exercise any of these rights, contact our Privacy Lead at [email protected] (or [email protected]). Exercising your rights is free of charge. We respond without undue delay and within one month, extendable by up to two further months for complex requests as permitted by law — we will tell you if we need an extension. Business customers may request a Data Processing Agreement (DPA) at [email protected].

10. Automated Decision-Making

The Service lets you deploy AI agents that act on your instructions. We do not subject you to decisions based solely on automated processing that produce legal or similarly significant effects. Consequential agent actions are gated behind a human-in-the-loop approval step: the agent proposes the action and a human approves or denies it before it runs. The logic involved is instruction-following: agents act on the goals, configurations, and approvals you provide, using the AI models you select. You are responsible for the decisions your deployed agents make toward your own end users.

11. Our Role: Controller and Processor

For the personal data described in this policy — your account, billing, usage, and the data you submit on our own websites — Neotask, Inc. is the data controller.

Some features let your business collect personal data from your own customers and contacts: for example, waitlist signups on websites the product generates for you, employee directories, and messages relayed from your connected channels. For that data, you (or your business) are the controller and Neotask is a processor acting on your instructions under our Data Processing Agreement. If your personal data was collected by a business using Neotask, please direct privacy requests to that business — we support them in fulfilling your request.

12. International Data Transfers

We are based in the United States, and your information will be transferred to and processed in the United States and other countries where our subprocessors operate. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards as required by law: the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the recipient is certified, and the European Commission's Standard Contractual Clauses (with the UK Addendum / International Data Transfer Agreement where applicable) in all other cases, alongside transfers to jurisdictions covered by an adequacy decision.

A small number of optional, user-selectable AI model providers (for example MiniMax, Moonshot, and Qwen) process data in China. They receive data only if you explicitly configure them for your agents; if you are subject to the GDPR we recommend reviewing your obligations before doing so.

You can obtain a copy of the safeguards we rely on (including the Standard Contractual Clauses we have in place) by contacting [email protected]. The current list of subprocessors and processing locations is published on our Subprocessors page, and a Data Processing Agreement is available to customers at [email protected].

13. Health Information (HIPAA)

For customers in healthcare, Neotask can act as a HIPAA Business Associate: we offer a Business Associate Agreement (BAA) to healthcare customers, available at [email protected]. Protected Health Information (PHI) is handled only under a signed BAA and only within a dedicated, U.S.-region, HIPAA-eligible environment — never on the general platform. Within that environment, AI processing is routed only to BAA-covered model providers with zero data retention, and PHI is never sold, used for marketing, or used to train shared or foundation models.

Unless and until you have a signed BAA with us, the Service must not be used to create, receive, maintain, or transmit PHI. Neotask is HIPAA-aligned as a Business Associate; HIPAA has no certification, and we make no "HIPAA certified" claim.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app and on the website, and by updating the "Effective Date" above. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, or wish to exercise your rights, please contact us:

Neotask, Inc.

Privacy Lead: [email protected] · General: [email protected] · DPA / compliance: [email protected]

We are in the process of appointing an EU (Art. 27 GDPR) representative; until that appointment is published here, EEA data subjects may contact our Privacy Lead at [email protected] for all GDPR matters.