Privacy Policy
Last updated: May 14, 2026
Effective date: May 14, 2026
Chask, Inc. ("Chask", "we", "our", "us") values your privacy. This Privacy Policy describes what information we collect, how we use it, who we share it with, and the rights you have over it when you use the Chask service ("Service"). Chask is an AI-native product, and this policy is specific about what data is sent to our LLM provider and how it is handled.
Table of Contents
1. Information We Collect
a) Information You Provide
- Account registration data (name, email address, password hash)
- Profile information (optional: bio, avatar, "About me" self-description)
- Goal and task content you create (statements, descriptions, milestones, tasks, journal notes, vision boards, story extracts)
- Chat messages you send to Chask's AI features
- Persona traits and preferences (when persona features are enabled)
- Availability windows and scheduling preferences
- Workspace settings and customizations
- Communications with our support team
b) Data Sent to AI/LLM Features
When you use AI-powered features, the following data is sent to our LLM provider (OpenAI) for processing. See §4 below for details on retention and training.
- Goal statements, descriptions, and refinement inputs
- Task and milestone content
- Chat conversation history within a goal
- Your "About me" profile context (used to personalize outputs)
- Persona traits when persona features are enabled
- Milestone structure, dependency graph, and scheduling windows
- Natural-language availability strings
- Story extracts you submit for goal analysis
c) Automatically Collected Information
- Device and browser information
- IP address, request headers, and request paths (captured by our error-monitoring provider — see §3(d))
- Usage patterns and feature interactions (only if analytics consent is given — see §7)
- Performance metrics and Web Vitals
- Session and authentication logs
d) Cookies and Local Storage
We use the following cookies and browser-storage items:
cookie-consent— your analytics preference (functional, ~1 year)sb-access-token,sb-refresh-token— Supabase authentication (essential, session)_ph_*— PostHog product analytics (analytics; only set if you consent)- Stripe checkout cookies — set on the Stripe payment domain during checkout
We also store the following items in your browser's local storage. They never leave your device and are cleared on logout:
chask:v2:ui:goal:<goalId>— UI state per goal (expanded sections, filters, sort order)chask:v2:chat:<goalId>— local copy of chat history for a goalchask:v2:llm-requests:<goalId>— local LLM request log for debuggingchask:v2:*— general app state and user preferences
e) Payment Information
- Billing details are processed by Stripe. We do not store credit card numbers on our servers.
- We retain transaction history and invoice metadata.
- We retain your Stripe customer ID and your workspace's subscription status.
f) Cross-Account Integrations
If you connect Chask to an external service, we receive and store data from that service to provide the integration:
- Google Calendar OAuth — refresh and access tokens are encrypted at rest using AES-256-GCM. We use these tokens to read and write the calendar events you authorize. You can revoke this connection at any time in your Chask settings or from your Google account.
2. How We Use Information
We use your information for the following purposes:
a) Service Provision
- Create and manage your account
- Deliver features and personalized experiences
- Enable goal and task management functionality
- Support workspace collaboration features
b) AI/LLM Processing
- Generate goal breakdowns, milestones, task suggestions, and scheduling proposals
- Provide chat-based assistance grounded in your goal context
- Summarize and analyze progress to surface insights
Chask does not train any of its own models on your data, and our LLM provider (OpenAI) does not use API customer data to train its models by default (see §4).
c) Communication
- Send service updates and feature announcements
- Provide security alerts and account notifications
- Respond to support requests
- Send optional marketing communications (only with your consent; opt-out at any time)
d) Security and Fraud Prevention
- Detect and prevent unauthorized access
- Monitor for abusive or malicious behavior
- Protect against spam and harmful activity
- Maintain system integrity and security
e) Analytics and Improvement
- Understand usage patterns and feature adoption (only if you consent to analytics cookies)
- Identify and resolve performance issues and bugs
- Develop new features based on aggregated user needs
f) Legal Compliance
- Respond to legal requests and obligations
- Enforce our Terms of Service
- Protect our legal rights and property
- Comply with applicable regulatory requirements
3. Sharing of Information
We share your information only with trusted subprocessors who help us operate the Service. A complete list is available on our Subprocessors page.
a) Infrastructure Providers
- Supabase — primary database, authentication, real-time, and storage. Hosted in a US-based AWS region.
- Redis-compatible cache — short-lived caching of AI responses (default TTL 30 minutes, up to 1 hour for planning outputs). The cache key is derived from request parameters; only generated AI outputs are cached, not raw personal data.
b) AI/LLM Provider
- OpenAI — current production models are
gpt-5.3-codex,gpt-4o, andgpt-4o-mini. Used for goal breakdown, planning, milestones, scheduling, chat, and content generation.
Data sent: goal content, task descriptions, chat messages, your "About me" context, persona traits when enabled, milestone structure, scheduling windows, and the other items listed in §1(b).
Training and retention: OpenAI does not use API customer data to train its models by default (per OpenAI API terms in effect since March 2023). OpenAI retains API request data for up to 30 days for abuse monitoring unless a Zero Data Retention (ZDR) agreement is in place. Chask does notcurrently have a ZDR agreement with OpenAI; we are evaluating one for future enterprise availability.
c) Payment Processor
- Stripe — handles all payment processing and subscription management. We send your user ID, workspace ID, selected tier, and pricing. Card numbers go directly to Stripe and are never stored by us.
d) Analytics and Monitoring
- Sentry — error monitoring and performance tracing. Sentry captures stack traces, request paths, IP address, browser metadata, and Chask context tags (goal ID, workspace ID, user ID — all UUIDs). We apply a
beforeSendscrubbing filter to strip authorization headers, cookie headers, and request/response bodies for routes that may carry personal content (e.g.,/api/nlp/*and/api/goals/*). We do not send LLM prompts or completions to Sentry. - PostHog — product analytics. Only loaded if you consent to analytics cookies. Autocapture and session recording are disabled.
e) Communication
- Resend — transactional email delivery (verification, password resets, account notifications, invitations).
f) Cross-Account Integrations
- Google Calendar — when you connect Google Calendar, we read and write the events you authorize. OAuth tokens are encrypted at rest (AES-256-GCM).
g) Legal and Compliance
- Law enforcement (when legally required)
- Legal advisors (under confidentiality agreements)
- Regulatory authorities (for compliance purposes)
- Business transfers (merger, acquisition, or asset sale)
Privacy Commitments
- We do not sell your personal information.
- We do not share your data for cross-context behavioral advertising.
- We do not train any of our own models on your data.
- All subprocessors are bound by data-processing agreements and confidentiality.
4. AI and LLM Data Processing
Chask is an AI-native product. AI processing is required for the core experience — goal breakdown, planning, milestones, scheduling, and chat all rely on our LLM provider.
a) What Data We Send to OpenAI
When you use AI features, we send the relevant subset of the following to OpenAI:
- Goal statements, descriptions, and refinement inputs
- Task and milestone content; dependency graphs
- Chat messages within a goal
- Your "About me" profile context (to personalize tone and vocabulary)
- Persona traits when persona features are enabled
- Scheduling windows and natural-language availability strings
- Story extracts you submit for goal analysis
Your name, email address, password, billing information, and Sentry telemetry are never sent to OpenAI.
b) How OpenAI Uses Your Data
- OpenAI processes your data only to generate the AI response Chask requests.
- OpenAI does not use API customer data to train its models (per OpenAI API terms in effect since March 2023).
- OpenAI retains API request data for up to 30 days for abuse monitoring, then deletes it. Chask does not currently have a Zero Data Retention agreement; we are evaluating one.
See OpenAI's policy: https://openai.com/privacy
c) Your Control Over AI Processing
Chask is an AI-native product. Processing your goal data through our LLM provider is required for the core features and there is no way to use Chask without AI processing. If you do not want your data processed by an LLM, do not create an account, or delete your account to stop processing (see §5(c)).
You still control:
- AI-generated content lives in your account — you can delete any piece at any time.
- Analytics cookies (PostHog) are opt-in via Settings → Privacy.
- Marketing emails are opt-in.
- Sentry telemetry is scrubbed per §3(d).
d) AI Accuracy Disclaimer
AI-generated suggestions may be inaccurate, incomplete, biased, or out of date. You are responsible for verifying outputs before acting on them. See the Terms of Service for the full AI-generated content disclaimer.
e) No Automated Decisions With Legal Effect
Chask uses AI to suggest goals, plans, tasks, and schedules. You always take the final action. We do not make automated decisions that produce legal or similarly significant effects about you (within the meaning of GDPR Article 22).
5. Data Security and Retention
a) Security Measures
- Encryption in transit (TLS 1.2+) and at rest (database-level)
- OAuth tokens encrypted at rest with AES-256-GCM
- Row-Level Security policies enforce per-user data access in our database
- Multi-factor authentication for administrative access
- Secure coding practices and code review
- Security audit logs for authentication, authorization, and rate-limit events
Chask is currently in beta. We do not yet hold SOC 2 or ISO 27001 certification, and we do not yet conduct scheduled penetration testing. We will update this section as those programs come online.
b) Data Retention Periods
- Active account data: retained while your account is active.
- Soft-deleted media: 14 days, then purged.
- Soft-deleted notes, vision boards, and journal items: retained until the next purge cascade runs against your account.
- Hard account deletion: 30-day grace period from your deletion request, then full cascade purge of your goals, tasks, milestones, profile, workspace memberships, and authentication record.
- Deletion certificates: we retain a record proving your account was deleted, with no personal content, for 7 years for regulatory reporting.
- In-app notifications: 90 days after delivery once you have read them, and 12 months at the outside whether or not you read them. You can delete any notification sooner from the notification panel.
- Security and audit logs: 90 days.
- Analytics history: 30, 90, or 365 days depending on your tier.
- Backups: retained by our database provider per our subscription plan's standard backup window. Deleted data may persist in backups for that window before being overwritten.
- Legal hold: if we are subject to a legal hold, affected data is retained as required by law for the duration of the hold.
Retained after account deletion
A purge erases your goals, tasks, milestones, profile, workspace memberships and authentication record. These records lawfully survive it (GDPR Art. 17(3)), and we issue an internal certificate stating exactly how many were kept:
- Credit-ledger and billing records: retained in de-identified form — replaced with a non-reversible key so they can no longer be traced back to you — because accounting and tax law require the transaction history to remain reconcilable. Card details and invoices are held by Stripe, not by us.
- Credit-grant audit records: your email address and any free-text notes are erased; the amount, category and workspace are kept as a financial audit trail.
- Email unsubscribe entries: retained with your address, and deliberately not de-identified. If we erased it, an address that later re-entered our systems by any route would start receiving mail again — deleting your account must not undo your objection to being emailed.
- Subscription-downgrade records: retained de-identified. They are how we recognise a repeated billing event from Stripe, so discarding them could cause a past event to be processed a second time.
- The deletion certificate: proof the erasure happened, carrying no personal content, kept for 7 years as described above.
Shared workspace content you uploaded but that belongs to a workspace outliving your account is unlinked from you rather than deleted. Copies of erased data also persist in our provider's routine backups until they age out of the backup window.
c) Account Deletion
You can request account deletion at any time:
- Go to Account Settings → Delete Account, type the confirmation phrase, and submit.
- Your account is marked for deletion and you are signed out.
- You have 30 days to change your mind. During the grace period, sign back in and use the cancellation flow in Account Settings (or email privacy@chask.ai).
- After 30 days, a scheduled job permanently purges your data and we issue an internal deletion certificate.
- A small set of records — de-identified financial and billing entries, your email unsubscribe entry, and the deletion certificate — is retained, as described in §5(b) under “Retained after account deletion”.
d) Security Limitations
- No system is completely secure. We cannot guarantee absolute security.
- You are responsible for keeping your password secure.
- Report security issues to security@chask.ai.
- As a beta product, additional risks exist (bugs, downtime, data loss). Keep your own copies of anything you can't afford to lose.
e) Data Breach Notification
If we discover a breach affecting your personal information, we will notify you without undue delay, and no later than 72 hours where required by applicable law. The notification will include what happened, what data was affected, what we are doing about it, and steps you can take to protect yourself.
6. Your Rights
Your privacy rights depend on your location. You can exercise most rights directly from Settings → Privacy, which includes self-serve data export (JSON) and deletion requests.
a) Rights for All Users
- Access your personal data and a summary of how we use it
- Correct inaccurate or incomplete information
- Delete your account and associated data
- Export your data as JSON (data portability). Goals, milestones and tasks nest, so the export is a structured file rather than a spreadsheet.
- Opt out of marketing communications
b) Additional Rights for EU/EEA/UK Users (GDPR)
If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights:
- Right to be forgotten: request complete deletion of your data
- Right to restrict processing: limit how we use your data
- Right to object: object to specific data-processing activities
- Right to withdraw consent: withdraw consent at any time
- Right to lodge a complaint: file complaints with your data-protection authority
- Right to data portability: receive your data in machine-readable format
- No automated decision-making with legal effect: see §4(e)
EU/UK representative (GDPR Art. 27): We have not appointed a formal representative at beta launch. We will appoint one prior to general availability if our processing of EU/UK residents' data meets the threshold under GDPR Article 27. EU/UK users may direct privacy requests to privacy@chask.ai in the meantime.
UK ICO: https://ico.org.uk
c) Additional Rights for California Users (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act and California Privacy Rights Act:
- Know what personal information we collect about you
- Know whether we sell or share personal information (we do not)
- Request deletion of your personal information
- Correct inaccurate personal information
- Limit use of sensitive personal information
- Non-discrimination for exercising your privacy rights
Global Privacy Control (GPC): we honor GPC signals where technically feasible. If your browser sends a GPC header, we treat it as an opt-out signal for analytics cookies on the same basis as toggling analytics off in your privacy settings.
d) Additional Rights for Other US States
If you are in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another US state with a comprehensive privacy law, you have rights similar to those described above. Contact privacy@chask.ai to exercise them.
e) How to Exercise Your Rights
The fastest path is Settings → Privacy (export, deletion request, analytics opt-out are all self-serve there).
For anything else, email privacy@chask.ai with:
- Your name and the email address on your account
- The right you want to exercise
- Verification information (we'll confirm your identity for security)
We respond within 30 days (or as required by applicable law).
7. Cookies and Tracking Technologies
a) Cookies We Set
cookie-consent— your analytics preference (functional, ~1 year)sb-access-token,sb-refresh-token— Supabase authentication (essential, session)_ph_*— PostHog product analytics (analytics; only set if you consent)- Stripe checkout cookies — set on Stripe's payment domain during checkout
b) Third-Party Cookies
PostHog cookies are set by PostHog. Stripe cookies are set by Stripe during checkout. Both honor your consent choice from cookie-consent.
c) Managing Cookies
You can control cookies through:
- In-app cookie preferences: Settings → Privacy → Consent. Toggling analytics off opts you out of PostHog immediately.
- Browser settings: block all cookies or specific sites. Disabling essential cookies will prevent you from signing in.
- Global Privacy Control: we honor GPC signals as described in §6(c).
d) Do Not Track
We treat browser Do-Not-Track signals the same as a Global Privacy Control signal for our own analytics. Third-party services may not honor DNT.
8. International Data Transfers
Chask, Inc. is incorporated in Delaware, United States. Our infrastructure and most subprocessors are US-based.
a) Where Your Data Is Processed
- Stored in US-based AWS regions via Supabase
- Transmitted to US-based subprocessors (Sentry, PostHog, Stripe, Resend, Redis cache)
- Sent to OpenAI for AI processing (US)
- Google Calendar OAuth — Google's global infrastructure
See our Subprocessors page for each vendor's processing location and transfer mechanism.
b) Transfers From EU/EEA/UK to the US
For EU, EEA, and UK users, we transfer data to the US using:
- Standard Contractual Clauses (EU Commission 2021/914) with all subprocessors not certified under another framework.
- EU-US Data Privacy Framework (DPF) with vendors certified under it.
- Data Processing Agreements with every subprocessor.
- Your account creation serves as informed consent to these transfers for users who actively sign up.
c) Your Rights Regarding Transfers
- Request detailed information about specific transfers
- Object to specific transfers (may limit Service functionality)
- Request a copy of the safeguards we use
- Contact your local data-protection authority with concerns
9. Children's Privacy
Chask is intended for users 18 and older. We do not knowingly collect personal information from anyone under 18.
If we learn that an account belongs to someone under 18, we delete the account and associated data without delay. Because Chask does not serve users under 18, COPPA (which applies to children under 13) does not apply to us.
If you believe a child has created an account on Chask, contact privacy@chask.ai and we will act promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 30 days before material changes take effect. The "Last updated" date at the top of this page is the authoritative version pointer. Continued use of the Service after the effective date constitutes acceptance.
11. Contact Us
For questions about this Privacy Policy or to exercise your rights:
- Privacy and data-subject requests: privacy@chask.ai
- Security vulnerability reports: security@chask.ai
- Legal notices: legal@chask.ai
Entity: Chask, Inc., a Delaware corporation (United States). Mailing address available on request via legal@chask.ai.
If we appoint a formal EU/UK Article 27 representative or designate a US-state DPA contact, this section will be updated.