Privacy model

We can't read your content.

Metadata still matters.

Taskessa is built on zero-knowledge encryption. Your content is encrypted on your device before it ever leaves. The server stores only ciphertext and the metadata needed to make planning work.

Read the full privacy policy

Your device

You create and encrypt content locally.

Plaintext exists here, behind your key.

Taskessa API

We store ciphertext and metadata only.

We cannot read your content.

Local MCP

You connect your own LLM via MCP.

Plaintext stays on your machine.

Encrypted content

Sealed on your device before it reaches Taskessa:

  • Task titles, notes, and checklists
  • Habit names, descriptions, and notes
  • Project, section, label, and category names
  • Habit check-in notes
  • Calendar names and block titles
  • Attachment names and file contents
End-to-end encrypted with libsodium: XChaCha20-Poly1305, keys derived with Argon2id.

Visible metadata

Stored in plaintext so planning can work:

  • Dates, times, and durations
  • Status, priority, and completion
  • Habit check-in values
  • Recurrence rules and timestamps
  • Project, label, and section IDs (the structure, not the words)
  • Calendar structure: how many calendars, their color, order, and which holds a block (never their names)
  • Attachment sizes and counts
  • Sync change log: entry types and timestamps
Metadata is never encrypted. The honest scope below spells out what that means.

Your recovery key

You hold the only keys that can decrypt your content.

  • Your encryption key is derived from your password, on your device
  • You can export a 12-word recovery phrase (BIP39), shown once and kept only by you
  • No server escrow. Ever.
  • Losing both your password and your recovery phrase means permanent data loss
Keep your recovery phrase safe. We cannot help you recover it.

BYO-LLM via local MCP

If you want AI, you bring your own.

  • Connect the LLM you choose through the local Taskessa MCP server
  • Decryption happens on your machine, where your key lives
  • The model sees only what you allow it to see
We do not operate an AI service or LLM gateway.

Sharing and links

Built on the same key-distribution model:

  • Each shared item gets its own resource key, sealed to each member
  • The server authorizes who can fetch ciphertext. It never holds keys
  • Public read-only links carry the key in the URL fragment, which never reaches our server
Sharing has not yet been independently audited. Do not treat it as risk-free.

Organizations

Shared work, with an honest trust boundary:

  • An org project's content is decryptable by the project's members and by the org itself
  • The org key is held client-side by admins, never by the server. No escrow
  • Billing and quota are pooled across the org; members pay nothing
  • Your personal vault stays separate: yours alone, never readable by the org
For org content the honest boundary is "you + your org admins", not "you alone". The server stays blind either way.

The honest scope

Zero-knowledge protects what your content says, not that it exists, when it changes, or how often you act.

We cannot read your content. We can still see the metadata above.

What we can't read
  • Task titles, notes, and checklists
  • Habit names, descriptions, and notes
  • Project, label, and category names
  • Calendar names and block titles
  • Attachment names and file contents
What we can see
  • Dates, times, durations, and recurrence
  • Status, priority, and completion
  • IDs and structural relationships
  • Calendar structure (count, color, order, block membership)
  • Attachment sizes and counts
  • Change-log entry types and timestamps

Security is a process

We design for privacy by default, minimize what we store, and keep reviewing risks. If our model changes, we will say so plainly. The policy below is the formal version of these commitments.

The zero-knowledge guarantee is true at rest: we store ciphertext we cannot read. Our assurance for it is internal and code-review-based (including review assisted by an AI model), not yet a third-party cryptographic audit, so please weigh it accordingly.

Legal

Privacy Policy

Last updated: July 4, 2026

Taskessa is zero-knowledge. Your content is encrypted on your device before it reaches our servers. We cannot read it. Only you, and the AI model you connect yourself, can.

What we can never read

The following are end-to-end encrypted on your device (XChaCha20-Poly1305, with a key derived from your password via Argon2id). We store only ciphertext and can never decrypt it:

  • Task titles, notes, and checklists
  • Project, section, and label names
  • Habit names, notes, categories, and check-in notes
  • Calendar names and block titles
  • Attachment names and file contents

What we store

  • Account: your email address and authentication credentials. We never receive your raw password, only a value derived from it on your device.
  • Encrypted content: ciphertext blobs we cannot read.
  • Plaintext metadata: dates, priorities, status, identifiers, and timestamps needed to organize your items. This includes the structure of your calendars (how many you have, their color, order, and which calendar a planning block belongs to) but never their names, which are encrypted like everything else you write.
  • Technical data: limited request information (such as IP address, used transiently for rate-limiting and abuse prevention). We do not log your content.

The Chrome extension

The Taskessa side-panel extension runs the same app locally in your browser. It:

  • connects only to your Taskessa account API (api.taskessa.com);
  • stores your authentication tokens locally in your browser's extension storage;
  • performs all encryption and decryption on your device: your password and encryption key never leave it and are never sent to us;
  • contains no analytics, no advertising, no third-party trackers, and no remotely-hosted code.

Your encryption key and recovery

Your encryption key is derived from your password on your device and is never escrowed with us. A one-time recovery key lets you regain access if you forget your password. If you lose both your password and your recovery key, we cannot recover your encrypted content, by design.

Sharing

When you share a project, task, or link, the item's encryption key is sealed directly to the people you choose; the server decides who may fetch ciphertext but never holds the keys. Public read-only links carry their key in the URL fragment, which your browser does not send to our servers. Sharing has not yet been independently audited.

Organizations

An organization gives a team a shared space that is separate from your personal vault. In an org, the content of an org project is decryptable by that project's members and by the organization itself: the organization holds its own key, generated and kept client-side by its admins, and that key is never held by our server. There is no server escrow of it, exactly as with a personal vault. The operator stays blind in both cases: "the org can read" means an org admin holds the org's key on their own device, not that we can.

Because the organization keeps its own key, it retains access to its projects even after a member leaves, which is what lets a team keep its shared work. Billing and storage quota for org projects are pooled at the organization level, so members do not pay individually. Your personal vault is not part of this: it stays decryptable by you alone and is never readable by the organization.

The honest trust boundary for org content is therefore "you and your organization's admins", not "you alone" as it is for a personal vault. Choose what you put in an org project accordingly.

Bring-your-own AI

Any AI assistance runs through a connector you set up locally, against a model you choose. We do not operate a server-side AI that reads your content.

Service providers

We rely on third-party infrastructure providers to operate Taskessa. They process only ciphertext and plaintext metadata on our behalf and cannot read your content: hosting, content delivery and storage, database, transactional email, and payment processing through a merchant of record. We do not sell or rent your data, and we do not share it for advertising.

Changes

We may update this policy. Material changes will be reflected here with a new "last updated" date.

Your rights

You can access and export your data, and delete your account and its data, at any time. To make a privacy request, contact us at privacy@taskessa.com.

Contact

Questions about privacy? Email privacy@taskessa.com.