Task Attaché
Privacy notice

An attaché who talks is no use to anybody.

This is the full version of what happens to what you type. It is written to be read rather than to be survived, and it says what is not done as plainly as what is.

Applies to agentattache.com and the app at app.agentattache.com · Updated

What is collected

The app itself carries no analytics library, no advertising pixel and no session-replay recorder. That is a property of the code, not a promise about intent: there is nothing of that kind in it to switch on.

Diagnostic reports

When the app breaks, everything useful about why is on your device, where we cannot see it. A diagnostic report is how a crash gets fixed without you having to notice it, describe it, or write to us at all.

On the App Store version, this is off until you turn it on, in Settings under Diagnostics. Test builds installed through TestFlight always send one, because reporting problems is the whole purpose of a test build.

A report holds:

What a report never holds: your tasks, notes, lists, tags, due dates, standing orders, email address, password, or passkey, and nothing you have typed or dictated. The event labels are chosen from a fixed list written into the app rather than generated from what is on screen, so a report has no way to pick up your content even by mistake.

Reports go to our own server and nowhere else. They are not sold, not shared, and not used to build a profile of you or to advertise anything.

What leaves for a model provider, and when

The AI features are the only thing that sends your content anywhere. When you use one, the task text that feature is working on is sent server-side to:

Both are used through their business API terms rather than their consumer products. Your list, your reminders and your data never require a model: if you never touch an AI feature, nothing of yours is sent to one. Your email address is not sent with the content.

What is never done

The sandbox

The no-account sandbox mints a throwaway account whose address is at an unroutable domain, so nothing in the system can email a sandbox owner even by mistake. Sandboxes are disposable by design and are reaped. If you later sign in with a real address from that same session, the work you did is carried into your real account, once, and never between two real accounts.

Getting your data out, and getting rid of it

There is no one-click export yet. That is a real gap rather than a policy, and a data-export surface is the next thing being built. Until it lands, the free Model Context Protocol server can read everything in your account programmatically, which is a working if technical way out.

Deletion is by request and is done by hand. There is no self-serve delete button yet, so either route below works and both reach a person. Enter the address on your account and everything held for it goes. No retention argument will be made at you. A delete button is on the build list, and this paragraph will change when it lands.

By email: privacy@agentattache.com, from the address on the account. Or use the form, which needs no mail client:

Where it is kept, and children

The service runs on Cloudflare's platform, with the database and files stored there. Backups exist so an accident is recoverable.

Task Attaché is not directed at children under 13 and accounts are not knowingly created for them.

When this changes

The date at the top moves whenever this page does. A change that materially widens what is collected or where it goes will be announced to account holders by email before it takes effect, not discovered afterwards.