Privacy Policy
Last Updated: August 2026
1. Introduction & Data Controller
Future Task ("we", "our", or "us") is committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws. The data controller responsible for your personal data is Future Task, reachable at [email protected]. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service at future-task.com.
2. Information We Collect
We collect: (a) Account data — name, email address, hashed password, profile preferences (theme, language, timezone), subscription tier and plan; (b) Usage data — pages visited, features used, task/note counts, Pomodoro sessions, AI credit consumption; (c) Device data — IP address, browser type, operating system, referral source; (d) Payment data — processed by Stripe (subscriptions and AI credit pack purchases); we never store card numbers ourselves.
3. Legal Basis for Processing (GDPR)
We process your data on the following legal bases: (a) Contract performance — to provide the Service you signed up for (Art. 6(1)(b) GDPR); (b) Legitimate interests — to improve the Service, prevent fraud, and maintain security (Art. 6(1)(f) GDPR); (c) Consent — for optional analytics and marketing emails, which you may withdraw at any time; (d) Legal obligation — when required by applicable law.
4. How We Use Your Information
We use collected data to: provide, maintain, and improve the Service; authenticate your account and manage sessions; process subscription payments and AI credit pack purchases via Stripe; send transactional emails (password reset, account verification, purchase invoices) via Brevo; generate AI responses via OpenAI; track aggregate usage analytics via Google Analytics (only if you consent via the cookie banner); respond to support inquiries; and comply with legal obligations.
5. Third-Party Data Processors
We share data only with processors necessary to operate the Service, all bound by data processing agreements: Supabase (database & authentication, EU infrastructure); Brevo (transactional email); OpenAI (AI text generation — prompts and context only, no PII stored by OpenAI beyond the request); Stripe (payment processing); Google Analytics (anonymised usage analytics, only loaded with your consent). We do not sell or rent your personal information to any third party.
6. Data Retention
We retain your account data for as long as your account is active, or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g. billing records retained for 7 years for tax purposes).
7. International Data Transfers
Some of our processors may transfer data outside the European Economic Area (EEA). Where this occurs, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions.
8. Data Security
We implement industry-standard security measures: HTTPS/TLS encryption in transit, hashed passwords (never stored in plaintext), HTTP-only secure cookies for session tokens, Content Security Policy headers, and role-based access controls via Supabase RLS. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
9. Cookies & Tracking
We use: (a) Strictly necessary cookies — session tokens (sb-access-token, sb-refresh-token) required for authentication, and your cookie consent choice itself; these cannot be disabled without breaking login. (b) Analytics cookies — Google Analytics, loaded only if you accept them in the cookie banner; you may withdraw consent at any time from the banner or your browser settings. (c) Marketing cookies — AdSense and Adsterra ad scripts, loaded only if you accept them in the cookie banner; they never load otherwise. You can review or change your choice at any time; rejecting non-essential cookies has no effect on your ability to use the Service.
10. Your Rights (GDPR)
Under GDPR, you have the right to: Access — request a copy of your personal data; Rectification — correct inaccurate data; Erasure ('right to be forgotten') — request deletion of your data; Restriction — limit how we process your data; Data portability — receive your data in a structured, machine-readable format; Objection — object to processing based on legitimate interests; Withdraw consent — at any time for consent-based processing. To exercise any right, email [email protected]. You also have the right to lodge a complaint with your national supervisory authority.
11. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact [email protected] and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or by posting a notice on our website at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
For any privacy-related questions, data subject requests, or complaints, contact us at: [email protected]. We aim to respond within 30 days.