← Back to Home

Taskora Privacy Policy

1. Introduction & Scope

Taskora, Inc., a Delaware corporation ("Taskora," "we," "us," or "our"), provides a web application, autonomous AI agents ("Agent Services"), and a Chrome Extension that automate operational workflows for service and trade businesses. This Privacy Policy explains how we collect, use, disclose, and share information across our website (gettaskora.com), our product, and our Agent Services.

This policy applies to individuals in the United States and is intended to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). Residents of other U.S. states may have rights under their state's law where it applies to us; contact us as described in Section 13 and we will honor any request applicable law requires. The choices described in Sections 4 and 10 are available to every U.S. visitor, whichever state's laws apply. We do not currently offer the Services in the European Union, and this policy does not address the EU General Data Protection Regulation.

Two different roles. We handle two kinds of data very differently.

  1. Website/marketing data — what we collect when you visit gettaskora.com or fill out a form. We make our own decisions about this (we act as a "business" under the CCPA), and as explained in Section 4, some of it counts as a "sale/share" for advertising, described in Section 6.
  2. Customer Data — the credentials, agent activity, recordings, and connected-system content your Agents touch. Here Taskora acts as a "service provider" and processes this data only to run the Service for you, on the customer's documented instructions. We never sell it, share it, or use it for advertising.

2. Notice at Collection — Categories of Personal Information

We handle two kinds of data very differently, and the tables below reflect that.

A. Website & marketing data

Personal information we collect from website visitors at gettaskora.com. Some of this is sold or shared for advertising and visitor identification on the basis described in Section 4. In California and the other states where we require opt-in, the advertising and visitor-identification technologies described in Section 4 run only if you opt in. In other U.S. states they may run unless you decline, opt out, or send a Global Privacy Control signal (Section 10).

B. Customer & product data

Personal information we process when you use the product and Agent Services. We never sell or share any of this — we process it only as your service provider, to run the Service for you.

We collect each category from the sources in Section 3, use it for the purposes in Section 5, and retain it as described in Section 8. We disclose some categories to our service providers to run the Service (Sections 6 and 7); those disclosures are not a sale or share.

3. Information We Collect

Website Visitors

When you visit gettaskora.com, we collect information you voluntarily provide through forms (such as contact or demo requests), and we automatically collect device and usage information through cookies and similar technologies. We also use website-visitor-identification technology that may identify the company or the individual associated with a website visit — including name, job title, and professional profile information — for marketing and sales purposes. See Section 4 (Cookies, Tracking & Online Advertising) for details and your choices.

Account Information

When you sign in to the Taskora dashboard or extension, we collect your email address and authentication credentials, profile information you provide (such as names), and limited audit logs (IP address, user agent) for security monitoring.

Customer Credentials (Agent Services)

To operate Agents on your behalf, we collect and store credentials you provide for your own and third-party systems — including logins, API keys, access tokens, and multi-factor authentication materials such as one-time-passcode seeds and authenticator codes ("Customer Credentials"). We do not collect biometric identifiers — such as fingerprint, voiceprint, or facial-recognition data — as part of Customer Credentials. We keep Customer Credentials in an encrypted vault. They're decrypted only to operate your Agents — for example, when an Agent signs in or sends on your behalf — for the duration of that work, or to help you when you ask. You can delete Customer Credentials anytime from the dashboard. We never sell, share, or use Customer Credentials for advertising or to train AI.

Agent Activity & Conversation Data (Agent Services)

When you use Agent Services, we process the task instructions you give Agents, Agent conversation history across supported channels, the Playbooks Agents author, and activity and execution logs. The contents of communications an Agent sends or receives on your behalf through connected channels are sensitive personal information under the CCPA; we process them only as described in Sections 2B and 10.

Agent Session Recordings (Agent Services)

Agent Sessions that involve browser automation are recorded to provide audit, support, debugging, and security. These are recordings of the Agent's own automated browser sessions on the systems you connect, not of your visits to our website — how we collect website data (including consent-gated session replay on some pages) is described in Sections 2A and 4. Recordings may capture navigation, clicks, form interactions, screenshots, and page content accessed by the Agent on the platforms you connect. Recordings that contain personal information are treated as Customer Data and, where they capture message or communication content, as sensitive personal information (see Section 2B), and are processed only as a service provider.

Extension Usage & Automation Data

The Taskora Chrome Extension operates only on a fixed list of supported platforms and on Taskora's own domains ("Supported Platforms"). On a Supported Platform, the extension observes — in your browser's local memory — the API responses the platform loads, so it can act on the record you're viewing. This observed data is not sent to Taskora automatically. Captured record data is transmitted to the Taskora backend only when you, or an automation you've configured, start an action — for example, running a task from the side panel or a compliance indicator, enabling auto-run for a task, or editing a previously-checked record while the side panel is open. To show compliance indicators on list pages, the extension sends only record identifiers (not their contents) and receives status back. It uses local browser storage to cache run history, temporary logs, and user-specific encryption keys, and it does not read, capture, or monitor your activity on other websites.

Device & Log Data

We collect standard application logs (timestamps, request URLs, HTTP status codes) to monitor stability and security. Remote logging in the extension is disabled by default; when enabled, sensitive headers are redacted.

Sources of Personal Information

We collect personal information from the following categories of sources: (a) directly from you (forms, account setup, support requests); (b) automatically from your device and browser (cookies, log data, the extension); (c) from our business customers and their personnel, where you interact with systems an Agent operates on a customer's behalf; and (d) from advertising and website-visitor-identification providers, who provide professional/contact information matched to a website visit.

4. Cookies, Tracking & Online Advertising

Our website uses cookies and similar technologies for three purposes:

When you first visit gettaskora.com we present a notice at collection and cookie/tracking choices, and a link to this policy. If your browser sends a Global Privacy Control (GPC) signal, we apply the opt-out automatically. You can change your choices at any time from the Consent Preferences link in the site footer.

Whether these technologies wait for your opt-in depends on your location, which we determine from your IP address.

Opt-in states. In California and the other states where we require opt-in, the advertising and visitor-identification technologies described in this Section do not run, and we do not make personal information (including a hashed email) available to those recipients, unless and until you opt in.

Other U.S. states. These technologies may run from the time the page loads unless you have opted out or your browser sends a GPC signal. If you decline in the notice or opt out later, they stop on your browser going forward. Whatever your state, you can also opt out with our visitor-identification provider directly and ask us to delete any professional profile information it returned to us about your visit (Section 10).

Strictly necessary cookies are unaffected everywhere. Where the advertising and visitor-identification technologies run, we treat our use of them as a "sale" and a "share" of personal information as the CCPA defines those terms. To withdraw a prior opt-in or to opt out at any time, see Section 10 (Your Privacy Rights and Choices). On pages where you can choose to play video content (for example, product demos or explainer videos), the advertising and visitor-identification technologies above run only if you opt in, wherever you are located, and we do not disclose information identifying you as having viewed specific video content except with your consent or as permitted by law. Our Cookie Notice at gettaskora.com/terms/cookies lists the specific cookies, trackers, and platforms we use; we update it when we add or change one.

5. How We Use Information

We use information to: provide, operate, and secure the Services and Agent Services; execute the workflows and Agent tasks you initiate; authenticate users and maintain sessions; provide support; monitor stability, detect abuse, and prevent fraud (including misuse of free trials); communicate with you; market and advertise our Services and identify prospective customers (website and marketing data only); comply with law; and, in de-identified and aggregated form only (on data that is not personal information), conduct internal research and improve the Service — for example, generic starter templates and the general reliability of our automation. We do not reuse one customer's specific procedures for another customer. Marketing emails include a working unsubscribe mechanism you can use at any time, and we honor opt-out requests for any marketing calls or text messages.

We keep your Customer Data, Customer Credentials, Playbooks, Agent session recordings, and Agent conversations confidential and isolated to your account. We don't disclose them to other customers, use them in the prompts or retrieval served to other customers, or use them in any way that identifies you to, or reveals their content to, other customers — and we never use any of them for advertising. Our AI providers process this content only under enterprise/business terms that do not permit them to train their models on it; we do not use consumer or free AI tiers, and we do not opt in to any provider data-sharing or model-training program. As described above, we may use de-identified, aggregated data — which never identifies you or reveals your content — to improve the Services and our models.

6. How We Disclose, Sell, and Share Personal Information

Service providers / sub-processors. We disclose personal information to vendors that process it on our behalf, under contracts that limit their use to providing services to us (Section 7 table). For a business purpose we disclose personal information to those service providers; the categories are listed in the 12-month disclosure below. These disclosures are not a sale or share.

Sale and share (website/marketing data only). As described in Section 4 (only with your opt-in in California and the other opt-in states; in other U.S. states unless you decline, send a GPC signal, or opt out), we may make personal information of website visitors available to advertising platforms and to our website-visitor-identification provider. Under the CCPA these disclosures are a "sale" and a "share" — they count as such because those recipients use the identifiers and activity for their own purposes (ad targeting and measurement, and building or enriching their own identity graphs), not merely as a service provider to us. What we may make available is limited to online/device identifiers, cookies, IP address, internet/network activity (browsing), and a hashed (pseudonymized) version of your email used for match-based advertising and conversion measurement — not your name. The professional and employment details we learn about a visitor (such as company and job title) are received back from our visitor-identification provider; that is a collection, not something we sell or share. We do not sell or share your name, Customer Data, Customer Credentials, Agent activity, session recordings, sensitive personal information, or the personal information of any individual we know to be under 16.

Categories disclosed, sold, or shared in the preceding 12 months. As of the Last Updated date above, in the preceding 12 months:

Legal and safety. We may disclose information to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and security of Taskora, our users, or others.

Business transfers. If Taskora is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

Categories of third parties. The third parties to whom we disclose, sell, or share personal information fall into these categories: service providers and sub-processors (Section 7); advertising and website-visitor-identification platforms (Section 6, for the website/marketing data described above); legal, regulatory, and government authorities where required or permitted by law; and, in a business transfer, an acquirer or successor. The current platforms in each category are listed in our Cookie Notice at gettaskora.com/terms/cookies, and we will provide that list on request (Section 10).

7. Sub-Processors

We use trusted vendors (sub-processors) to help provide the Services, and share data with them only to the extent necessary. The categories of sub-processors we use, and what they process, are:

We may add or replace sub-processors as our services evolve; the categories above reflect our current use, and we will provide our current list of sub-processors on request. We require our service-provider sub-processors to provide CCPA service-provider protections.

8. Data Retention

We retain personal data only as long as necessary for the purposes described, or per the criteria stated, except where law requires longer retention (for example, tax, accounting, or dispute records) — then we keep only what that law requires, for as long as it requires:

9. Security

We maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption of data in transit and at rest (including Customer Credentials), access controls, logical isolation of Agent data between customers, and data minimization. A current summary of our security measures is available to customers on request. If we experience a security incident affecting your personal information, we will notify you as required by applicable state and federal law. No method of transmission or storage is completely secure.

10. Your Privacy Rights and Choices

California residents (CCPA). Subject to applicable law, California residents have the right to:

Everyone: how to opt out of sale/share and tracking. These choices are available to every visitor, whatever your state. Use the cookie and tracking notice, or the Consent Preferences or Do Not Sell or Share My Personal Information links in the site footer, to decline or opt out of the advertising and visitor-identification technologies described in Section 4, or to withdraw analytics acceptance (which stops session replay). Your choice stops those technologies on your browser going forward; it is stored in your browser, so you may need to repeat it in another browser. We honor Global Privacy Control (GPC) browser signals as a valid request to opt out of sale/share, and apply the opt-out automatically on detection. You may also opt out of our website-visitor-identification provider (Rb2b, via Retention.com) directly at https://app.retention.com/optout, and you may email support@gettaskora.com to have us delete any professional profile information that provider returned to us about your visit.

How to exercise other rights. Submit a request to support@gettaskora.com. We will verify your request as required by law. You may use an authorized agent.

Requests about Customer Data. Where we process personal information on a business customer's behalf as a service provider (Agent operations, connected-system data), requests from that customer's end users should be directed to the customer; we will reasonably assist our customers in responding to verifiable consumer requests.

11. Chrome Extension Permissions

The Taskora Chrome Extension (Manifest V3) runs only on a fixed list of supported platforms and on Taskora's own domains. On those platforms it observes the platform's own API responses in your browser's local memory so it can act on the record you're viewing; this data is sent to Taskora only when you, or an automation you've configured, start an action (for example, running a task, enabling auto-run, or editing a checked record with the side panel open). To show compliance indicators on list pages it sends only record identifiers, not their contents. Other than requests to Taskora's own services and to the supported platforms themselves, the only external request it makes is to load optional celebration graphics. It does not inject into, capture data from, or monitor unrelated websites, and it follows the Chrome Web Store Limited Use policy.

The extension's current permissions include: storage (settings, tokens, cached config); cookies (to authenticate API calls to the supported platforms on your behalf); alarms (scheduled background refresh); sidePanel (the Taskora side-panel interface); tabs (tab metadata, to show or hide the side panel per tab); scripting (to run automations and read records on the supported platforms); notifications (run, compliance, and status alerts); and activeTab. Host permissions are limited to the supported platforms and Taskora's own domains. Our Chrome Web Store listing is the authoritative, current source for the complete permission and host list; if it ever differs from the summary above, the Web Store listing controls.

12. Children's Privacy

The Services are intended for business use and not for anyone under 18. Separately, and because the CCPA specifically restricts it, we do not knowingly collect personal information from anyone under 16, and we do not sell or share the personal information of consumers we know to be under 16. If we learn we have collected such information, we will delete it promptly.

13. Changes & Contact

We review this policy at least every 12 months as the CCPA requires, update it as needed, and revise the "Last Updated" date. Material changes will be communicated as required by law.