Privacy Policy
Effective Date: September 28, 2026
Neotask, Inc. ("Neotask," "we," "us," or "our"), a Delaware corporation, operates the Neotask application, platform, and related services (the "Service"). This Privacy Policy describes how we collect, use, store, and protect your information when you use Neotask across desktop (macOS, Windows, Linux), iOS, and the web dashboard, and when you visit our websites.
By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
a. Account Information
When you create an account using Apple Sign-In or Google Sign-In, we receive your name and email address as provided by the authentication provider. We do not receive or store your Apple ID password, Google password, or any other authentication credentials from these providers. When you activate a desktop license, we collect your license key and a device fingerprint used solely for device binding.
b. Agent and Deployment Configuration
When you configure and deploy AI agents through Neotask, we collect the selections you make, including your chosen AI models, messaging channels, agent configurations, skill settings, automation schedules, and deployment preferences. If you connect messaging channels such as Telegram, Discord, Slack, or WhatsApp, you provide credentials (bot tokens, OAuth grants, or QR code sessions) used solely to connect your agents to those platforms.
c. Usage and Billing Data
We collect usage data to operate the Service and calculate usage fees, including token consumption (input, output, cache read, and cache write tokens), model and provider usage, session activity, agent activity, tool call counts, and scheduling execution records. We also collect usage data for service improvement, including session identifiers, feature interactions, deployment events, timestamps, and general device information (platform, OS version). We do not collect precise GPS geolocation; where we derive location for analytics or fraud prevention, it is an approximate location (such as country, region, or city) computed from an anonymized IP address.
d. Chat and Message Data
Except as described below for local models, messages sent to and from your deployed AI agents are processed through the third-party AI model provider configured for that agent (for example Anthropic, OpenAI, Google, or providers reached via OpenRouter). We store message data — including message content and any attachments you provide — to maintain conversation context, enable session history, and provide the chat interface. We do not use your message content for advertising and we do not sell it to third parties. We do not use your content to train our own models.
When an agent uses a local model that you set up in the Neotask desktop app, that model runs on your own computer, or on another computer on your local network that you choose to connect, and the agent's messages are not sent to an AI model provider for that model's processing. We still store those messages as described above. A turn on a local model can still use hosted features that send content to their providers, such as image or media understanding, audio transcription, image generation, and web search. The agent can also hand work to other agents or subagents that use hosted models. If the agent's fallback models include a hosted model, or your default model is a hosted model, a turn that the local model cannot complete may continue on that hosted model, and that model's provider receives the turn; later turns in the same conversation may also continue on that model. The optional setting "Use a local model when your default model fails" does not change where your default model runs: it adds your local model as a fallback that is used only when your default model cannot answer. If a model server you connect forwards requests to an online service, such as an Ollama cloud model, that service receives them.
e. Website, Marketing, Sales, and Support Data
When you interact with our websites we may collect the information you submit (such as your email address on a waitlist form, or your name, email, phone number, and message on a contact or demo-booking form) together with technical context such as your IP address, browser user agent, referrer, and the approximate location derived from an anonymized IP address. If advertising measurement is enabled and you separately provide exact marketing-and-advertising consent, Meta Pixel and Meta's Conversions API may process the Meta browser identifiers _fbp and _fbc, and Reddit Pixel and Reddit's Conversions API v3 may process the Reddit browser identifier _rdt_uuid. These providers may also process a pseudonymous event reference, event type and time, and bounded purchase, trial, or subscription value and currency. Google Ads measurement may receive consent-gated measurement signals through Google tag. These advertising services are off by default, disabled in HIPAA mode, overridden by GPC or DNT, and do not receive chat content, agent content, license keys, or payment-card details from these integrations.
If you speak with our sales or support team by phone or through in-product voice features, those calls may be recorded and transcribed for quality, training, and record-keeping purposes. Where the law requires, you will be notified and/or asked for consent before recording begins. Call recordings are scrubbed on a fixed schedule (see Data Retention below); transcripts and summaries are retained as business records.
2. How We Use Your Information
We use the information we collect to:
- Authenticate your identity, manage your account, and validate your license
- Provision, deploy, and manage your AI agents across all connected channels
- Route agent requests to the appropriate AI model provider
- Track token usage and calculate usage fees for billing purposes
- Connect your agents to your selected messaging and integration platforms
- Execute scheduled automations and orchestrate multi-agent teams
- Monitor service health, performance, and reliability
- Diagnose technical issues and provide customer support
- Improve and develop new features for the Service
- Communicate important service updates, billing notices, or security alerts
- Comply with legal obligations
Legal Bases for Processing (EEA / UK / comparable law)
Where the GDPR or a comparable regime applies to you, we rely on the following legal bases to process your personal data:
- Performance of a contract — to provide the Service you signed up for (account management, agent deployment, billing).
- Legitimate interests — to operate, secure, and improve the Service, prevent fraud and abuse, maintain security and audit logs, and respond to enquiries you send us, balanced against your rights and freedoms.
- Consent — for analytics cookies where prior consent is required (including the EEA, UK, Switzerland, and unknown regions), for advertising measurement everywhere, and for marketing communications such as our waitlist; you can withdraw consent at any time.
- Legal obligation — to meet tax, accounting, and other legal requirements (for example, retention of financial records).
3. Third-Party Services and Subprocessors
Neotask integrates with the following categories of third-party services. Your use of these services is subject to their respective privacy policies. The complete, current list of our subprocessors — what each one does, where it processes data, and whether it is a core provider or only used if you connect it — is published at neotask.ai/subprocessors, and we update that page whenever the list changes:
- Authentication Providers - Apple Sign-In and Google Sign-In for account creation and login. We receive only the information you authorize these providers to share.
- AI Model Providers - Your agent messages are processed by the AI model provider configured for that agent (for example Anthropic, OpenAI, Google AI, or other providers via OpenRouter). Each provider processes your content under its own API terms and privacy practices, and we do not permit providers to sell your content. When using BYOK (Bring Your Own Key) mode, your API keys are sent directly to these providers. Some optional, user-selectable providers (for example MiniMax, Moonshot, or Qwen) process data in China — they are used only if you explicitly configure them. Turns processed by a local model that you set up in the Neotask desktop app are not sent to an AI model provider for that processing (see Section 1(d), Chat and Message Data).
- Messaging Platforms - Agents connect to platforms including Telegram, Discord, Slack, WhatsApp, Microsoft Teams, Google Chat, Signal, Matrix, Line, and others. Messages are transmitted through each platform's infrastructure.
- Payment Processors - Stripe processes credit/debit card payments and manages subscription billing. RevenueCat processes iOS in-app purchases. We do not store your full payment card details — card data is handled by the payment processor.
- Voice Services - Deepgram provides speech-to-text transcription. ElevenLabs provides text-to-speech synthesis. Audio data is transmitted to these providers for processing.
- Google Workspace - If you connect Google Workspace services (Gmail, Calendar, Drive, Docs, Sheets, and others), we access only the data you authorize through Google OAuth.
- Analytics, Advertising Measurement, Monitoring, and Support - Google Analytics and DataFast provide privacy-minimized visitor analytics for our public websites under regional requirements. In the EEA, UK, Switzerland, and unknown regions, analytics requires consent. GPC/DNT always disables analytics. Google Ads, Meta, and Reddit advertising measurement always require a separate marketing-and-advertising grant. Sentry provides minimized error monitoring and Intercom powers support messaging under the same regional analytics gate.
4. Cookies and Similar Technologies
We use cookies and similar technologies for essential operation and privacy-minimized site measurement. For a positively identified United States visitor, Google Analytics 4, DataFast, browser Sentry, Intercom, and first-party site analytics may operate by default on public pages until you deny cookies. In the EEA, UK, Switzerland, and any unknown region, those analytics runtimes stay absent until our server validates the exact latest analytics-consent receipt for the current session. Meta Pixel, Meta's Conversions API, Reddit Pixel, Reddit's Conversions API v3, and Google Ads measurement always require a separate exact marketing-and-advertising consent receipt. Global Privacy Control (GPC) and Do Not Track (DNT) disable analytics and advertising measurement in every region.
For the full list of cookies we set, what they do, how long they last, and how to manage them, see our Cookie Policy.
Advertising Measurement Notice (Authoritative English)
Effective July 14, 2026
Only when Neotask enables advertising measurement and you separately provide exact marketing-and-advertising consent may Google Ads measurement, Meta Pixel and Meta's server-side Conversions API, or Reddit Pixel and Reddit's Conversions API v3 operate. Meta Platforms, Inc. may receive consented _fbp/_fbc browser identifiers, and Reddit, Inc. may receive the consented _rdt_uuid browser identifier. Each enabled provider may receive the origin and bounded path of an approved public page, ordinary browser IP address and User-Agent network metadata, a pseudonymous event reference, event type and time, and bounded purchase, trial, or subscription value and currency. Browser pixels may also receive the referring page information ordinarily exposed by the browser. Encrypted advertising attribution expires after 90 days and each provider's conversion outbox after 180 days; withdrawal cancels pending delivery and removes the encrypted identifier envelope. The Reddit server API token is held only in AWS SSM and is never sent to the browser. Google enhanced conversions, ad personalization, and Google signals are disabled. These integrations are off by default, disabled in HIPAA mode, honor GPC and DNT, and do not receive chat content, agent content, license keys, or payment-card details from these integrations.
5. Data Storage and Security
Your account data, agent configurations, session history, and deployment settings are stored on secured servers. We use industry-standard security measures including encrypted connections (TLS 1.3), token-based authentication (JWT), HMAC-SHA256 request signing, and access controls to protect your data.
All API keys, bot tokens, and secrets are encrypted at rest using AES-256-GCM with versioned encryption keys. Keys are decrypted only at runtime when needed and are never exposed in logs or error messages. Billing and audit records are kept in append-only, tamper-evident ledgers. You may revoke any connected credentials at any time through the respective platform or through the Neotask dashboard.
The Neotask desktop application runs a local gateway on loopback (127.0.0.1) only, with no external network exposure, and encrypts locally cached credentials using your operating system's secure keystore (macOS Keychain, Windows Credential Manager, or Linux libsecret). While we implement commercially reasonable safeguards, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Sharing
We do not sell, rent, or trade your personal information to third parties. We may share information only in the following circumstances:
- Service Providers (Subprocessors) - With trusted providers who assist in operating the Service (hosting, analytics, payment processing, support), bound by data-processing agreements and confidentiality obligations. The current list is published on our Subprocessors page.
- AI Model Providers - Agent messages and prompts are sent to third-party AI providers for processing as part of normal Service operation. This does not apply to processing by a local model that you set up in the Neotask desktop app (see Section 1(d), Chat and Message Data).
- Legal Requirements - When required by law, regulation, legal process, or governmental request.
- Safety - To protect the rights, safety, or property of Neotask, our users, or the public.
- Business Transfers - In connection with a merger, acquisition, or sale of assets, with notice to affected users.
7. Data Retention and Deletion
We retain personal data only as long as needed for the purposes described in this policy. Our standard retention periods are:
- Account, agent configuration, and chat data — retained for the life of your account and deleted when your account is deleted.
- Session transcripts, activity logs, and diagnostic logs — automatically deleted on a 180-day rolling basis.
- Sales and support call recordings — audio is scrubbed within 90 days; transcripts and summaries are retained as business records.
- Financial, billing, and audit records — retained for up to 7 years as required by tax and accounting law.
- Marketing data (waitlist, contact forms, bookings) — retained on a fixed schedule and deleted earlier on request.
- Meta and Reddit advertising attribution and conversion records (only when enabled and consented): encrypted attribution identifiers expire after 90 days and each provider's server conversion outbox expires after 180 days; consent withdrawal cancels pending delivery and removes the encrypted identifier envelope.
- Anonymous, aggregated usage data — may be retained indefinitely for analytics; it does not identify you.
You may request deletion of your account and associated personal data at any time by using the account deletion feature in Settings (Account → Danger Zone → Delete Account) or by contacting us at [email protected]. Upon receiving a verified deletion request, we delete your personal data across our systems — and revoke connected-service tokens and cancel payment-processor records — without undue delay and within one month, except where limited retention is required by law (for example, financial records noted above).
8. Children's Privacy
The Service is not directed to children and is intended for adults and users who meet the minimum age below. We do not knowingly collect personal information from children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be up to 16 in some EEA countries). If we become aware that a child has provided us with personal information, we will promptly delete it. If you believe a child has provided us with personal information, please contact us at [email protected].
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access and receive a copy of your personal data
- Correct inaccurate or incomplete personal data
- Request deletion of your personal data
- Object to or restrict processing of your personal data (objection is absolute for direct marketing)
- Data portability (receive your data in a structured, commonly used, machine-readable format)
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with your local data protection supervisory authority (for EEA/UK residents)
You can exercise the most common rights yourself, instantly: use Download my data in account settings to export a complete, machine-readable copy of your data (access and portability), and Delete Account in Settings → Account → Danger Zone to erase it.
To exercise any of these rights, contact our Privacy Lead at [email protected] (or [email protected]). Exercising your rights is free of charge. We respond without undue delay and within one month, extendable by up to two further months for complex requests as permitted by law — we will tell you if we need an extension. Business customers may request a Data Processing Agreement (DPA) at [email protected].
10. Automated Decision-Making
The Service lets you deploy AI agents that act on your instructions. We do not subject you to decisions based solely on automated processing that produce legal or similarly significant effects. Consequential agent actions are gated behind a human-in-the-loop approval step: the agent proposes the action and a human approves or denies it before it runs. The logic involved is instruction-following: agents act on the goals, configurations, and approvals you provide, using the AI models you select. You are responsible for the decisions your deployed agents make toward your own end users.
11. Our Role: Controller and Processor
For the personal data described in this policy — your account, billing, usage, and the data you submit on our own websites — Neotask, Inc. is the data controller.
Some features let your business collect personal data from your own customers and contacts: for example, waitlist signups on websites the product generates for you, employee directories, and messages relayed from your connected channels. For that data, you (or your business) are the controller and Neotask is a processor acting on your instructions under our Data Processing Agreement. If your personal data was collected by a business using Neotask, please direct privacy requests to that business — we support them in fulfilling your request.
12. International Data Transfers
We are based in the United States, and your information will be transferred to and processed in the United States and other countries where our subprocessors operate. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards as required by law: the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the recipient is certified, and the European Commission's Standard Contractual Clauses (with the UK Addendum / International Data Transfer Agreement where applicable) in all other cases, alongside transfers to jurisdictions covered by an adequacy decision.
A small number of optional, user-selectable AI model providers (for example MiniMax, Moonshot, and Qwen) process data in China. They receive data only if you explicitly configure them for your agents; if you are subject to the GDPR we recommend reviewing your obligations before doing so.
You can obtain a copy of the safeguards we rely on (including the Standard Contractual Clauses we have in place) by contacting [email protected]. The current list of subprocessors and processing locations is published on our Subprocessors page, and a Data Processing Agreement is available to customers at [email protected].
13. Health Information (HIPAA)
For customers in healthcare, Neotask can act as a HIPAA Business Associate: we offer a Business Associate Agreement (BAA) to healthcare customers, available at [email protected]. Protected Health Information (PHI) is handled only under a signed BAA and only within a dedicated, U.S.-region, HIPAA-eligible environment — never on the general platform. Within that environment, AI processing is routed only to BAA-covered model providers with zero data retention, and PHI is never sold, used for marketing, or used to train shared or foundation models.
Unless and until you have a signed BAA with us, the Service must not be used to create, receive, maintain, or transmit PHI. Neotask is HIPAA-aligned as a Business Associate; HIPAA has no certification, and we make no "HIPAA certified" claim.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the app and on the website, and by updating the "Effective Date" above. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, or wish to exercise your rights, please contact us:
Neotask, Inc.
Privacy Lead: [email protected] · General: [email protected] · DPA / compliance: [email protected]
We are in the process of appointing an EU (Art. 27 GDPR) representative; until that appointment is published here, EEA data subjects may contact our Privacy Lead at [email protected] for all GDPR matters.