Privacy Policy
Last Updated: June 2026
1. Introduction & Data Controller
Future Task ("we", "our", or "us") is committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws. The data controller responsible for your personal data is Future Task, reachable at [email protected]. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service at future-task.com.
2. Information We Collect
We collect: (a) Account data — name, email address, hashed password, profile preferences (theme, language, timezone), subscription tier and plan; (b) Usage data — pages visited, features used, task/note counts, Pomodoro sessions, AI credit consumption; (c) Device data — IP address, browser type, operating system, referral source; (d) Payment data — processed exclusively by PayPal; we never store card numbers.
3. Legal Basis for Processing (GDPR)
We process your data on the following legal bases: (a) Contract performance — to provide the Service you signed up for (Art. 6(1)(b) GDPR); (b) Legitimate interests — to improve the Service, prevent fraud, and maintain security (Art. 6(1)(f) GDPR); (c) Consent — for optional analytics and marketing emails, which you may withdraw at any time; (d) Legal obligation — when required by applicable law.
4. How We Use Your Information
We use collected data to: provide, maintain, and improve the Service; authenticate your account and manage sessions; process subscription payments via PayPal; send transactional emails (password reset, account verification) via Brevo; generate AI responses via Groq; track aggregate usage analytics via Google Analytics; respond to support inquiries; and comply with legal obligations.
5. Third-Party Data Processors
We share data only with processors necessary to operate the Service, all bound by data processing agreements: Supabase (database & authentication, EU infrastructure); Brevo (transactional email); Groq (AI text generation — prompts and context only, no PII stored by Groq beyond the request); PayPal (payment processing); Google Analytics (anonymised usage analytics). We do not sell or rent your personal information to any third party.
6. Data Retention
We retain your account data for as long as your account is active, or as needed to provide the Service. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law (e.g. billing records retained for 7 years for tax purposes).
7. International Data Transfers
Some of our processors may transfer data outside the European Economic Area (EEA). Where this occurs, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions.
8. Data Security
We implement industry-standard security measures: HTTPS/TLS encryption in transit, hashed passwords (never stored in plaintext), HTTP-only secure cookies for session tokens, Content Security Policy headers, and role-based access controls via Supabase RLS. However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
9. Cookies & Tracking
We use: (a) Strictly necessary cookies — session tokens (sb-access-token, sb-refresh-token) required for authentication; (b) Analytics cookies — Google Analytics (anonymised, you may opt out via browser settings or the Google Analytics Opt-out Add-on); (c) We do not use advertising tracking cookies. You can control or disable cookies via your browser settings; disabling necessary cookies will prevent login.
10. Your Rights (GDPR)
Under GDPR, you have the right to: Access — request a copy of your personal data; Rectification — correct inaccurate data; Erasure ('right to be forgotten') — request deletion of your data; Restriction — limit how we process your data; Data portability — receive your data in a structured, machine-readable format; Objection — object to processing based on legitimate interests; Withdraw consent — at any time for consent-based processing. To exercise any right, email [email protected]. You also have the right to lodge a complaint with your national supervisory authority.
11. Children's Privacy
The Service is not directed to individuals under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact [email protected] and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or by posting a notice on our website at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact
For any privacy-related questions, data subject requests, or complaints, contact us at: [email protected]. We aim to respond within 30 days.