Task Manager Privacy Policy
Last updated: September 7, 2026
Task Manager is a personal task and calendar application. Its optional Gmail capture integration uses read-only Gmail access to detect messages delivered to a dedicated capture alias and selected by a dedicated Gmail label. It creates private intake records for those selected messages. It does not modify, move, delete, send, mark as read, or add or remove labels from Gmail messages.
Google data accessed
The integration accesses the authorized Gmail account address; Gmail label identifiers and names; mailbox history and watch state; and, for messages carrying the configured capture label, Gmail message and thread identifiers, history identifier, internal date, size, selected email headers, snippet, and bounded inline plain-text or HTML message content. The selected headers may include From, To, Cc, Reply-To, Subject, Date, Message-ID, and Delivered-To. Attachments and attachment-backed MIME content are not downloaded during this phase.
How the data is used
Google data is used only to identify newly received capture messages, recover messages missed by push delivery, prevent duplicate intake records, and retain a private server-side intake record for later processing in Task Manager. Gmail notifications are treated as mailbox-change signals rather than email content. Gmail remains the source and audit copy.
Server-side processing and storage
Gmail watch notifications pass through Google Cloud Pub/Sub to a private Supabase backend. Gmail API calls and intake processing occur on that backend, not in the browser or static PWA. OAuth client secrets, refresh tokens, and access tokens are not placed in browser storage or client-visible JavaScript.
The Google OAuth refresh token is encrypted with AES-256-GCM before database storage. The encryption key is held separately as a server-side secret. Short-lived access tokens are used in server memory. Access to Gmail integration tables is restricted from anonymous and normal authenticated clients, and authenticated Pub/Sub requests are validated before processing.
Retention
Validated intake records and encrypted Gmail connection state are retained until the integration owner requests their deletion or the associated Task Manager account data is deleted. Short-lived OAuth authorization-session records are marked consumed and expired records are removed during a later authorization bootstrap. Revoking Google access stops future authorized Gmail API access but does not automatically delete intake records already stored by Task Manager.
Sharing and sale
Google user data is not sold, rented, used for advertising, or shared with other Task Manager users. It is processed only through the infrastructure providers needed to operate the integration: Google APIs and Google Cloud Pub/Sub for Gmail notifications, and Supabase for private backend processing and storage. The public Cloudflare Pages application does not receive Gmail OAuth tokens.
Your choices and deletion
You can stop future access by revoking Task Manager under your Google Account's third-party connections and by disabling the dedicated Gmail filter or label workflow. To request deletion of the stored Gmail connection and intake records, email tyler.ktm373@gmail.com from the authorized account and identify the Task Manager Gmail integration. Deleting stored records does not delete the original messages in Gmail.
Security and changes
Task Manager uses scoped OAuth authorization, encrypted refresh-token storage, authenticated push delivery, server-only secrets, database access restrictions, bounded processing, and idempotent records to reduce risk. No internet service can promise absolute security. This policy will be updated if the integration's data practices materially change.
Google API Services User Data Policy
Task Manager's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions or requests concerning this policy can be sent to tyler.ktm373@gmail.com.