Taskora Privacy Policy
Last Updated: August 24, 2026
1. Introduction & Scope
Taskora, Inc., a Delaware corporation ("Taskora," "we," "us," or "our"), provides a web application, autonomous AI agents ("Agent Services"), and a Chrome Extension that automate operational workflows for service and trade businesses. This Privacy Policy explains how we collect, use, disclose, and share information across our website (gettaskora.com), our product, and our Agent Services.
This policy applies to individuals in the United States and is intended to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"). Residents of other U.S. states may have rights under their state's law where it applies to us; contact us as described in Section 13 and we will honor any request applicable law requires. The choices described in Sections 4 and 10 are available to every U.S. visitor, whichever state's laws apply. We do not currently offer the Services in the European Union, and this policy does not address the EU General Data Protection Regulation.
Two different roles. We handle two kinds of data very differently.
- Website/marketing data — what we collect when you visit gettaskora.com or fill out a form. We make our own decisions about this (we act as a "business" under the CCPA), and as explained in Section 4, some of it counts as a "sale/share" for advertising, described in Section 6.
- Customer Data — the credentials, agent activity, recordings, and connected-system content your Agents touch. Here Taskora acts as a "service provider" and processes this data only to run the Service for you, on the customer's documented instructions. We never sell it, share it, or use it for advertising.
2. Notice at Collection — Categories of Personal Information
We handle two kinds of data very differently, and the tables below reflect that.
A. Website & marketing data
Personal information we collect from website visitors at gettaskora.com. Some of this is sold or shared for advertising and visitor identification on the basis described in Section 4. In California and the other states where we require opt-in, the advertising and visitor-identification technologies described in Section 4 run only if you opt in. In other U.S. states they may run unless you decline, opt out, or send a Global Privacy Control signal (Section 10).
| CCPA Category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Name, email, IP address, online/device identifiers | Online/device identifiers, cookies, IP address, and a hashed email (used as an advertising identifier for match-based advertising) — not your name |
| Internet/network activity | Pages viewed, interactions, referring/exit pages, cookie data | Yes |
| Professional/employment info | Company, job title, work email, professional profile resolved from a visit | No — this is received from our visitor-identification provider, not sold or shared by us |
B. Customer & product data
Personal information we process when you use the product and Agent Services. We never sell or share any of this — we process it only as your service provider, to run the Service for you.
| CCPA Category | Examples |
|---|---|
| Account & commercial information | Account ID, plan, billing/transaction records |
| Sensitive personal information | Account log-ins and the credentials you provide for connected systems, and the contents of communications an Agent sends or receives on your behalf through connected channels (including session recordings that capture such communication content) — used only to operate your Agents. Because you choose which systems an Agent connects to, the sensitive personal information an Agent encounters depends on those systems — where present on a connected system, it may also include categories such as Social Security or other government ID numbers, financial account or payment card numbers, precise geolocation, or health information |
| Customer Data (agent operations) | Task instructions, Agent conversations, Playbooks, session recordings, content accessed on the systems you connect (where conversations or recordings capture the contents of communications sent through connected channels, they are also sensitive personal information — see above). This category is not a fixed list — it reflects the record and file content on the systems you direct an Agent to access |
We collect each category from the sources in Section 3, use it for the purposes in Section 5, and retain it as described in Section 8. We disclose some categories to our service providers to run the Service (Sections 6 and 7); those disclosures are not a sale or share.
3. Information We Collect
Website Visitors
When you visit gettaskora.com, we collect information you voluntarily provide through forms (such as contact or demo requests), and we automatically collect device and usage information through cookies and similar technologies. We also use website-visitor-identification technology that may identify the company or the individual associated with a website visit — including name, job title, and professional profile information — for marketing and sales purposes. See Section 4 (Cookies, Tracking & Online Advertising) for details and your choices.
Account Information
When you sign in to the Taskora dashboard or extension, we collect your email address and authentication credentials, profile information you provide (such as names), and limited audit logs (IP address, user agent) for security monitoring.
Customer Credentials (Agent Services)
To operate Agents on your behalf, we collect and store credentials you provide for your own and third-party systems — including logins, API keys, access tokens, and multi-factor authentication materials such as one-time-passcode seeds and authenticator codes ("Customer Credentials"). We do not collect biometric identifiers — such as fingerprint, voiceprint, or facial-recognition data — as part of Customer Credentials. We keep Customer Credentials in an encrypted vault. They're decrypted only to operate your Agents — for example, when an Agent signs in or sends on your behalf — for the duration of that work, or to help you when you ask. You can delete Customer Credentials anytime from the dashboard. We never sell, share, or use Customer Credentials for advertising or to train AI.
Agent Activity & Conversation Data (Agent Services)
When you use Agent Services, we process the task instructions you give Agents, Agent conversation history across supported channels, the Playbooks Agents author, and activity and execution logs. The contents of communications an Agent sends or receives on your behalf through connected channels are sensitive personal information under the CCPA; we process them only as described in Sections 2B and 10.
Agent Session Recordings (Agent Services)
Agent Sessions that involve browser automation are recorded to provide audit, support, debugging, and security. These are recordings of the Agent's own automated browser sessions on the systems you connect, not of your visits to our website — how we collect website data (including consent-gated session replay on some pages) is described in Sections 2A and 4. Recordings may capture navigation, clicks, form interactions, screenshots, and page content accessed by the Agent on the platforms you connect. Recordings that contain personal information are treated as Customer Data and, where they capture message or communication content, as sensitive personal information (see Section 2B), and are processed only as a service provider.
Extension Usage & Automation Data
The Taskora Chrome Extension operates only on a fixed list of supported platforms and on Taskora's own domains ("Supported Platforms"). On a Supported Platform, the extension observes — in your browser's local memory — the API responses the platform loads, so it can act on the record you're viewing. This observed data is not sent to Taskora automatically. Captured record data is transmitted to the Taskora backend only when you, or an automation you've configured, start an action — for example, running a task from the side panel or a compliance indicator, enabling auto-run for a task, or editing a previously-checked record while the side panel is open. To show compliance indicators on list pages, the extension sends only record identifiers (not their contents) and receives status back. It uses local browser storage to cache run history, temporary logs, and user-specific encryption keys, and it does not read, capture, or monitor your activity on other websites.
Device & Log Data
We collect standard application logs (timestamps, request URLs, HTTP status codes) to monitor stability and security. Remote logging in the extension is disabled by default; when enabled, sensitive headers are redacted.
Sources of Personal Information
We collect personal information from the following categories of sources: (a) directly from you (forms, account setup, support requests); (b) automatically from your device and browser (cookies, log data, the extension); (c) from our business customers and their personnel, where you interact with systems an Agent operates on a customer's behalf; and (d) from advertising and website-visitor-identification providers, who provide professional/contact information matched to a website visit.
4. Cookies, Tracking & Online Advertising
Our website uses cookies and similar technologies for three purposes:
- Strictly necessary — security, load balancing, and core site function, including our consent manager. These cannot be turned off.
- Analytics — to understand how visitors use the site and improve it. Basic, cookieless usage analytics run on every visit. Analytics cookies, and on some pages session replay (a recording of how you interact with that page), run only after you accept analytics cookies, wherever you are located; withdrawing acceptance stops them.
- Advertising & visitor identification — to market Taskora and measure campaigns. This category includes:
- Advertising and match-based advertising with advertising platforms (including social networks' advertising services): we may share online identifiers and activity for ad targeting and measurement (including cross-context behavioral advertising), and may provide a hashed (pseudonymized) version of your email as an advertising identifier to a platform's customer-matching and conversion-measurement tools. These platforms use it for their own advertising purposes, so it is a sale and a share.
- Website-visitor-identification technology (currently Rb2b; see Section 10 to opt out with it directly) that matches a website visit to a company or individual and returns professional/contact information to us for sales follow-up.
When you first visit gettaskora.com we present a notice at collection and cookie/tracking choices, and a link to this policy. If your browser sends a Global Privacy Control (GPC) signal, we apply the opt-out automatically. You can change your choices at any time from the Consent Preferences link in the site footer.
Whether these technologies wait for your opt-in depends on your location, which we determine from your IP address.
Opt-in states. In California and the other states where we require opt-in, the advertising and visitor-identification technologies described in this Section do not run, and we do not make personal information (including a hashed email) available to those recipients, unless and until you opt in.
Other U.S. states. These technologies may run from the time the page loads unless you have opted out or your browser sends a GPC signal. If you decline in the notice or opt out later, they stop on your browser going forward. Whatever your state, you can also opt out with our visitor-identification provider directly and ask us to delete any professional profile information it returned to us about your visit (Section 10).
Strictly necessary cookies are unaffected everywhere. Where the advertising and visitor-identification technologies run, we treat our use of them as a "sale" and a "share" of personal information as the CCPA defines those terms. To withdraw a prior opt-in or to opt out at any time, see Section 10 (Your Privacy Rights and Choices). On pages where you can choose to play video content (for example, product demos or explainer videos), the advertising and visitor-identification technologies above run only if you opt in, wherever you are located, and we do not disclose information identifying you as having viewed specific video content except with your consent or as permitted by law. Our Cookie Notice at gettaskora.com/terms/cookies lists the specific cookies, trackers, and platforms we use; we update it when we add or change one.
5. How We Use Information
We use information to: provide, operate, and secure the Services and Agent Services; execute the workflows and Agent tasks you initiate; authenticate users and maintain sessions; provide support; monitor stability, detect abuse, and prevent fraud (including misuse of free trials); communicate with you; market and advertise our Services and identify prospective customers (website and marketing data only); comply with law; and, in de-identified and aggregated form only (on data that is not personal information), conduct internal research and improve the Service — for example, generic starter templates and the general reliability of our automation. We do not reuse one customer's specific procedures for another customer. Marketing emails include a working unsubscribe mechanism you can use at any time, and we honor opt-out requests for any marketing calls or text messages.
We keep your Customer Data, Customer Credentials, Playbooks, Agent session recordings, and Agent conversations confidential and isolated to your account. We don't disclose them to other customers, use them in the prompts or retrieval served to other customers, or use them in any way that identifies you to, or reveals their content to, other customers — and we never use any of them for advertising. Our AI providers process this content only under enterprise/business terms that do not permit them to train their models on it; we do not use consumer or free AI tiers, and we do not opt in to any provider data-sharing or model-training program. As described above, we may use de-identified, aggregated data — which never identifies you or reveals your content — to improve the Services and our models.
6. How We Disclose, Sell, and Share Personal Information
Service providers / sub-processors. We disclose personal information to vendors that process it on our behalf, under contracts that limit their use to providing services to us (Section 7 table). For a business purpose we disclose personal information to those service providers; the categories are listed in the 12-month disclosure below. These disclosures are not a sale or share.
Sale and share (website/marketing data only). As described in Section 4 (only with your opt-in in California and the other opt-in states; in other U.S. states unless you decline, send a GPC signal, or opt out), we may make personal information of website visitors available to advertising platforms and to our website-visitor-identification provider. Under the CCPA these disclosures are a "sale" and a "share" — they count as such because those recipients use the identifiers and activity for their own purposes (ad targeting and measurement, and building or enriching their own identity graphs), not merely as a service provider to us. What we may make available is limited to online/device identifiers, cookies, IP address, internet/network activity (browsing), and a hashed (pseudonymized) version of your email used for match-based advertising and conversion measurement — not your name. The professional and employment details we learn about a visitor (such as company and job title) are received back from our visitor-identification provider; that is a collection, not something we sell or share. We do not sell or share your name, Customer Data, Customer Credentials, Agent activity, session recordings, sensitive personal information, or the personal information of any individual we know to be under 16.
Categories disclosed, sold, or shared in the preceding 12 months. As of the Last Updated date above, in the preceding 12 months:
- We sold or shared (as those terms are defined by the CCPA) the following categories of personal information: identifiers (specifically online/device identifiers, cookies, and IP address); and internet/network activity — to advertising platforms and to our website-visitor-identification provider. We did not sell or share your name, a hashed version of your email, or professional/employment information.
- We disclosed for a business purpose the following categories of personal information to our service providers: identifiers; internet/network activity; commercial information; professional/employment information; sensitive personal information (credentials); and Customer Data. For credentials and Customer Data, this is the purpose-limited processing described in Section 2B (Customer & product data) — used only to operate your Agents, and never sold, shared, or used for advertising.
Legal and safety. We may disclose information to comply with law, respond to lawful requests, enforce our terms, or protect the rights, safety, and security of Taskora, our users, or others.
Business transfers. If Taskora is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.
Categories of third parties. The third parties to whom we disclose, sell, or share personal information fall into these categories: service providers and sub-processors (Section 7); advertising and website-visitor-identification platforms (Section 6, for the website/marketing data described above); legal, regulatory, and government authorities where required or permitted by law; and, in a business transfer, an acquirer or successor. The current platforms in each category are listed in our Cookie Notice at gettaskora.com/terms/cookies, and we will provide that list on request (Section 10).
7. Sub-Processors
We use trusted vendors (sub-processors) to help provide the Services, and share data with them only to the extent necessary. The categories of sub-processors we use, and what they process, are:
| Category | Purpose | Data Processed |
|---|---|---|
| Cloud hosting & Agent runtime | Host and run Agent Services | Agent data, conversation history, encrypted Customer Credentials, and the content and screenshots of pages an Agent navigates |
| Browser automation & session recording | Run browser automation and record Agent Sessions | Browser session data, screenshots, page content accessed during Agent Sessions |
| AI model providers | AI model inference across the platform | Prompts, task context, conversation content |
| Authentication & database | Authentication and data storage for the dashboard | Account information, app data |
| Usage analytics & logging | Usage metrics, system logs, error reports (sensitive content stripped where possible) | Telemetry, logs, and (with your analytics consent) website session-replay recordings (Section 4) |
| Email & support | Email delivery and in-app support | Contact and message data |
| Advertising & visitor-identification | Marketing, ad measurement, website-visitor identification — these are recipients of a CCPA sale/share, not service providers (Section 6) | Website-visitor online identifiers, internet/network activity, and, where used, a hashed email (advertising identifier) |
We may add or replace sub-processors as our services evolve; the categories above reflect our current use, and we will provide our current list of sub-processors on request. We require our service-provider sub-processors to provide CCPA service-provider protections.
8. Data Retention
We retain personal data only as long as necessary for the purposes described, or per the criteria stated, except where law requires longer retention (for example, tax, accounting, or dispute records) — then we keep only what that law requires, for as long as it requires:
| Data Type | Retention |
|---|---|
| Account data | Until you request deletion or your account is closed |
| Agent conversation history & Playbooks | Retained until you request deletion |
| Agent session recordings | Typically 30 days; deletable on request (except where a legal hold or an active security investigation applies) |
| Customer Credentials (sensitive personal information) | Until you delete them or your account is closed |
| Application / audit logs | No longer than necessary for security, debugging, and audit purposes, except where retained longer for security investigations or as required by law |
| Website analytics / advertising / visitor-ID data | As long as necessary for the purposes described, and no longer than the relevant platform's standard retention period; professional profile information returned by our visitor-identification provider is deleted on request (Section 10) |
| Extension local cache | Short-lived; cleared locally on your device (and on uninstall) |
| Trial data (unconverted) | The same retention rules above apply to trial accounts; if a trial ends without converting, the account's data is deleted like any closed account, or earlier on request |
9. Security
We maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the data, including encryption of data in transit and at rest (including Customer Credentials), access controls, logical isolation of Agent data between customers, and data minimization. A current summary of our security measures is available to customers on request. If we experience a security incident affecting your personal information, we will notify you as required by applicable state and federal law. No method of transmission or storage is completely secure.
10. Your Privacy Rights and Choices
California residents (CCPA). Subject to applicable law, California residents have the right to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose, sell, or share it — and receive the specific pieces in a portable and, to the extent technically feasible, readily usable format;
- Delete personal information we have collected from you;
- Correct inaccurate personal information;
- Opt out of the sale and sharing of your personal information;
- Limit how we use sensitive personal information — we only use sensitive personal information (like account credentials and the communications content described in Section 2B) to run the Service you asked for and for security, audit, and fraud-prevention as part of operating it — never to profile you for advertising or any unrelated purpose. To submit a request to limit how we use sensitive personal information, email support@gettaskora.com; and
- Non-discrimination for exercising your rights. We do not offer financial incentives in exchange for personal information.
Everyone: how to opt out of sale/share and tracking. These choices are available to every visitor, whatever your state. Use the cookie and tracking notice, or the Consent Preferences or Do Not Sell or Share My Personal Information links in the site footer, to decline or opt out of the advertising and visitor-identification technologies described in Section 4, or to withdraw analytics acceptance (which stops session replay). Your choice stops those technologies on your browser going forward; it is stored in your browser, so you may need to repeat it in another browser. We honor Global Privacy Control (GPC) browser signals as a valid request to opt out of sale/share, and apply the opt-out automatically on detection. You may also opt out of our website-visitor-identification provider (Rb2b, via Retention.com) directly at https://app.retention.com/optout, and you may email support@gettaskora.com to have us delete any professional profile information that provider returned to us about your visit.
How to exercise other rights. Submit a request to support@gettaskora.com. We will verify your request as required by law. You may use an authorized agent.
Requests about Customer Data. Where we process personal information on a business customer's behalf as a service provider (Agent operations, connected-system data), requests from that customer's end users should be directed to the customer; we will reasonably assist our customers in responding to verifiable consumer requests.
11. Chrome Extension Permissions
The Taskora Chrome Extension (Manifest V3) runs only on a fixed list of supported platforms and on Taskora's own domains. On those platforms it observes the platform's own API responses in your browser's local memory so it can act on the record you're viewing; this data is sent to Taskora only when you, or an automation you've configured, start an action (for example, running a task, enabling auto-run, or editing a checked record with the side panel open). To show compliance indicators on list pages it sends only record identifiers, not their contents. Other than requests to Taskora's own services and to the supported platforms themselves, the only external request it makes is to load optional celebration graphics. It does not inject into, capture data from, or monitor unrelated websites, and it follows the Chrome Web Store Limited Use policy.
The extension's current permissions include: storage (settings, tokens, cached config); cookies (to authenticate API calls to the supported platforms on your behalf); alarms (scheduled background refresh); sidePanel (the Taskora side-panel interface); tabs (tab metadata, to show or hide the side panel per tab); scripting (to run automations and read records on the supported platforms); notifications (run, compliance, and status alerts); and activeTab. Host permissions are limited to the supported platforms and Taskora's own domains. Our Chrome Web Store listing is the authoritative, current source for the complete permission and host list; if it ever differs from the summary above, the Web Store listing controls.
12. Children's Privacy
The Services are intended for business use and not for anyone under 18. Separately, and because the CCPA specifically restricts it, we do not knowingly collect personal information from anyone under 16, and we do not sell or share the personal information of consumers we know to be under 16. If we learn we have collected such information, we will delete it promptly.
13. Changes & Contact
We review this policy at least every 12 months as the CCPA requires, update it as needed, and revise the "Last Updated" date. Material changes will be communicated as required by law.
- Privacy & general requests: support@gettaskora.com
- Formal legal notices: legal@gettaskora.com
- Mail: 206 Knowles Street, Raleigh, NC 27603