Your device
You create and encrypt content locally.
Plaintext exists here, behind your key.
We can't read your content.
Metadata still matters.
Taskessa is built on zero-knowledge encryption. Your content is encrypted on your device before it ever leaves. The server stores only ciphertext and the metadata needed to make planning work.
Read the full privacy policyYou create and encrypt content locally.
Plaintext exists here, behind your key.
We store ciphertext and metadata only.
We cannot read your content.
You connect your own LLM via MCP.
Plaintext stays on your machine.
Sealed on your device before it reaches Taskessa:
Stored in plaintext so planning can work:
You hold the only keys that can decrypt your content.
If you want AI, you bring your own.
Built on the same key-distribution model:
Shared work, with an honest trust boundary:
Zero-knowledge protects what your content says, not that it exists, when it changes, or how often you act.
We cannot read your content. We can still see the metadata above.
We design for privacy by default, minimize what we store, and keep reviewing risks. If our model changes, we will say so plainly. The policy below is the formal version of these commitments.
The zero-knowledge guarantee is true at rest: we store ciphertext we cannot read. Our assurance for it is internal and code-review-based (including review assisted by an AI model), not yet a third-party cryptographic audit, so please weigh it accordingly.
Legal
Last updated: July 4, 2026
Taskessa is zero-knowledge. Your content is encrypted on your device before it reaches our servers. We cannot read it. Only you, and the AI model you connect yourself, can.
The following are end-to-end encrypted on your device (XChaCha20-Poly1305, with a key derived from your password via Argon2id). We store only ciphertext and can never decrypt it:
The Taskessa side-panel extension runs the same app locally in your browser. It:
Your encryption key is derived from your password on your device and is never escrowed with us. A one-time recovery key lets you regain access if you forget your password. If you lose both your password and your recovery key, we cannot recover your encrypted content, by design.
When you share a project, task, or link, the item's encryption key is sealed directly to the people you choose; the server decides who may fetch ciphertext but never holds the keys. Public read-only links carry their key in the URL fragment, which your browser does not send to our servers. Sharing has not yet been independently audited.
An organization gives a team a shared space that is separate from your personal vault. In an org, the content of an org project is decryptable by that project's members and by the organization itself: the organization holds its own key, generated and kept client-side by its admins, and that key is never held by our server. There is no server escrow of it, exactly as with a personal vault. The operator stays blind in both cases: "the org can read" means an org admin holds the org's key on their own device, not that we can.
Because the organization keeps its own key, it retains access to its projects even after a member leaves, which is what lets a team keep its shared work. Billing and storage quota for org projects are pooled at the organization level, so members do not pay individually. Your personal vault is not part of this: it stays decryptable by you alone and is never readable by the organization.
The honest trust boundary for org content is therefore "you and your organization's admins", not "you alone" as it is for a personal vault. Choose what you put in an org project accordingly.
Any AI assistance runs through a connector you set up locally, against a model you choose. We do not operate a server-side AI that reads your content.
We rely on third-party infrastructure providers to operate Taskessa. They process only ciphertext and plaintext metadata on our behalf and cannot read your content: hosting, content delivery and storage, database, transactional email, and payment processing through a merchant of record. We do not sell or rent your data, and we do not share it for advertising.
We may update this policy. Material changes will be reflected here with a new "last updated" date.
You can access and export your data, and delete your account and its data, at any time. To make a privacy request, contact us at privacy@taskessa.com.
Questions about privacy? Email privacy@taskessa.com.