Skip to content
TaskBerry

Privacy Policy

Effective date: 2 September 2026

1. Introduction

TaskBerry is a day planning application for freelancers and professionals. It is operated by Groeien met Gydo, a company registered in the Netherlands (KvK: 81071698, VAT: NL003525719B18), with its registered address at Van Houweningenstraat 70, 1052 TR Amsterdam, The Netherlands.

This Privacy Policy explains what personal data we collect when you use TaskBerry, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (GDPR) and the Dutch UAVG (Uitvoeringswet AVG).

Groeien met Gydo is the data controller for your own personal data: your account, your settings, your tasks, your billing record. For personal data about other people that you put into TaskBerry, such as a client name or a pasted e-mail from a colleague, you are the controller and we act as your processor. Section 5a sets out both roles and what follows from each.

By creating an account and using TaskBerry, you acknowledge that you have read and understood this policy. If you have questions or concerns, please contact us at privacy@taskberry.app.

2. Data We Collect

We collect only the data that is necessary to provide and improve TaskBerry. Below is an overview of what we collect and why.

Account data

Your email address is required to create and maintain a TaskBerry account. We use it to send you a magic-link login email and, where applicable, important service notifications. We do not collect your name unless you voluntarily provide it.

Task data

The core purpose of TaskBerry is task management. When you use the app, we store the tasks you create, including their titles, descriptions, labels, dates, time entries, size estimates, deadlines, completion status, and any value statements you attach. This data belongs to you and is stored in our database under your user account.

AI conversation data

When you use the AI assistant, we store two different things, and we keep them for different lengths of time.

Transcripts. Your messages and the assistant's replies, word for word, in the coach_sessions table. This is the part most likely to contain other people's data, because it holds anything you pasted in. We keep it for 90 days.

Session summaries. One short line per working day about what you decided, in the berry_session_digest table. This is what lets the assistant remember earlier sessions. We keep it for 12 months. Before a summary is stored we run an automatic filter over it (see section 4).

You can delete your conversation history at any time from your account settings, and individual summaries from the assistant's memory page.

Context notes

You can provide personal context to help the AI assistant understand your working style and situation — for example, "I work four days a week" or "Mondays are for client calls." These notes are stored in our database and included in AI prompts when you use the assistant. You control what context notes exist and can delete individual notes at any time.

Usage settings

We store your personal preferences such as your daily capacity in minutes and your workday end time. These settings are used to power the capacity bar and overflow indicators on your day board.

Billing data

When you subscribe to a paid plan, we store your Stripe customer ID, plan tier (Free or Pro), and subscription status. We do not store your credit card number, card expiry, or any other raw payment instrument data. Payment card data is handled exclusively by Stripe and never touches our servers.

Technical data

Our hosting infrastructure (Vercel and Supabase) automatically logs server-side technical data including IP addresses, HTTP request paths, timestamps, and browser user agent strings. These logs are used for security monitoring, abuse prevention, and diagnosing technical issues.

3. How We Use Your Data

We process your personal data only for specific, documented purposes. The GDPR requires us to identify a legal basis for each purpose. Here is an overview:

PurposeLegal basis
Providing and operating the TaskBerry service (authentication, task storage, settings, labels, capacity tracking)Contract performance — Art. 6(1)(b) GDPR
Sending your messages and relevant task context to the model provider that powers the AI assistant, named in Section 5 (Google Gemini today, Anthropic Claude if we ever move your account)Contract performance — Art. 6(1)(b) GDPR
Processing subscription payments via Stripe and managing your plan tierContract performance — Art. 6(1)(b) GDPR
Storing AI conversation transcripts and session summaries so the assistant can refer back to earlier sessionsContract performance — Art. 6(1)(b) GDPR. Remembering earlier sessions is part of the assistant you subscribed to, not a separate interest of ours. You can delete your history at any time. (Until August 2026 this row named Art. 6(1)(f) legitimate interest. We changed it because 6(1)(b) describes what is actually happening and because it matches how we describe our role in section 5a.)
Server-side access logs for security monitoring and abuse preventionLegitimate interest — Art. 6(1)(f) GDPR. Our legitimate interest is protecting the security and integrity of the service.
Sending the occasional email to help you get started or come back: right after you sign up, two days after you begin, shortly before your trial ends, and if you stop using TaskBerry for a whileLegitimate interest — Art. 6(1)(f) GDPR. Our legitimate interest is helping people who signed up but drifted away get value from the product. You can opt out anytime with the one-click link in the email or the toggle in your account settings. One email is NOT covered here and you receive it either way: the notice that your trial has ended. That is a change to your access, and withholding it would move you to the free plan unannounced.
Sending the founder a message on every new signup (your email address, language and signup method), so that he can help you personallyLegitimate interest — Art. 6(1)(f) GDPR. Our legitimate interest is offering personal help at the start.
Retaining billing and transaction records for tax and accounting purposesLegal obligation — Art. 6(1)(c) GDPR (Dutch tax law, 7-year retention requirement)
Measuring aggregate usage through Google Analytics to understand how the product is usedConsent — Art. 6(1)(a) GDPR. Analytics cookies are only placed after you give explicit consent via our cookie banner.
Recording which screens you open in TaskBerry and which steps you take, so we can see where the product gets in the way and improve itLegitimate interest — Art. 6(1)(f) GDPR. Our legitimate interest is improving a small product based on how it is actually used. We record the screen, the step and the moment, never the content of your tasks or notes. This data goes to no third party and is deleted with your account. You can object with the toggle under Account, Privacy and data, after which we record nothing.

Within TaskBerry, we do not use your data for automated decision-making that produces legal or similarly significant effects. We do record which screens you open and which steps you take, to see where the product gets in the way; no decision about you follows from it, and you can switch it off under Account, Privacy and data. If you grant marketing consent, TaskBerry shares conversion data with Meta (see section 5 and section 8), which lets Meta optimise your ads on its own basis. We do not sell your personal data to any third party.

4. AI Assistant

The AI assistant runs on a large language model provided by another company. Today that is Google Gemini, from Google LLC, and it is what every account uses. We have also built the option to run the assistant on Claude, from Anthropic, so that we can compare the two. Nobody is on Claude yet. Section 5 lists both, and says which one is live.

When you send a message to the assistant, that message goes to whichever of those two is configured for your account, together with relevant context such as your tasks for the day and any context notes you have set. The reply comes back and is shown to you. If we ever move your account, this page says so first.

Google's use of your data: We use a paid Gemini API plan. Under Google's paid API terms, Google does not use your data to train, improve, or develop its AI models. Your messages are processed in real time to generate a response. Google may retain conversation data for up to 55 days for abuse monitoring purposes under its API usage policies, after which it is deleted from Google's systems.

Anthropic's use of your data, if we ever switch you: Anthropic states that it does not use inputs or outputs from its commercial API to train its models by default. It deletes API inputs and outputs within 30 days. If a conversation is flagged by its abuse systems, it keeps that conversation for up to 2 years and the classification scores for up to 7 years. Those periods are Anthropic's, not ours, and they are longer than Google's on the flagged path.

Storage on our side: transcripts are kept 90 days and daily session summaries are kept 12 months, both tied to your account and readable only by you. Section 7 sets out the periods in full.

What we strip out of a summary: a summary is kept far longer than a transcript, so before one is stored we remove e-mail addresses, phone numbers and bank account numbers, and we remove the names of other people that the material identified as people. Names of projects, clients and companies stay, because without them a summary recalls nothing useful. Two things do this: the model is instructed to write roles rather than names, and a separate automatic filter runs over the result whether or not the model followed that instruction.

The filter is not perfect and we would rather say so than imply otherwise. It catches contact details reliably. It catches a person named in a pasted conversation or introduced with a title such as "Dr.". A name written in plain prose, with nothing around it to mark it as a person, can get through.

There is one shape it only half catches. A first name followed by a surname with two linking words, such as "Jan van der Berg", loses the first name while part of the surname can stay. The same name written without the first name is removed in full.

Summaries written before August 2026 predate this filter and were never run through it. We did not rewrite them, because editing your stored memory after the fact would change words you never asked us to change. You can read them on the assistant's memory page and delete any of them.

A copy in your browser: your current conversation is also stored in your own browser so it survives closing the tab. That copy is removed when you sign out, and otherwise after 90 days, the same period we keep transcripts. Clearing your browser data removes it immediately.

Transparency: The AI assistant is always clearly identified as an automated AI system. You are never talking to a human when using this feature.

Your control: You can delete your entire AI conversation history at any time from your account settings. If you prefer not to use the AI assistant, you can simply not use that feature — all other parts of TaskBerry work without it.

Pasting other people's messages: the assistant is built to take a pasted e-mail or chat and turn it into tasks, so material written by other people is a normal part of using it. When you do that, you decide what goes in and why, and we process it on your instruction. Section 5a explains what that means for who is responsible. Keep what you paste to what you need for the work.

What not to paste: special-category data under Art. 9 GDPR, such as health information, and financial account numbers. There is no reason for either to be in a task, and the assistant sends whatever you paste to the model provider configured for your account, which is named in Section 5.

5. Data Processors (Sub-processors)

We work with a limited number of trusted third parties to operate TaskBerry. Each processor is bound by a Data Processing Agreement (DPA) and may only process your data according to our documented instructions. Meta is the exception: for the Meta Business Tools (the Meta Pixel and the Conversions API), Meta and TaskBerry act as joint controllers. In that role Meta is not a sub-processor under our DPA but an independent controller, and this data sharing is governed by the Meta Business Tools terms, including the joint controller addendum.

The Status column distinguishes processors that are actively handling user data today ("Active") from those whose data path is wired in the codebase or planned for an upcoming feature but not yet processing live customer data ("Pre-disclosed"). We list pre-disclosed processors so that you have notice of every processor that could receive your data, even before the corresponding feature is enabled.

ProcessorPurposeLocationStatusDPA
Supabase Inc.Database, authentication and storageEU (Frankfurt, Germany)Activesupabase.com/legal/dpa
Vercel Inc.Web application hosting, edge functions and CDNEU/US (SCCs in place)Activevercel.com/legal/dpa
Vercel Inc. (Vercel Analytics)Aggregated website usage analytics (EU-hosted)EU/US (SCCs in place)Active (analytics consent required)vercel.com/legal/dpa
Google LLC (Gemini API)AI assistant processingUS (SCCs + DPF)Activecloud.google.com/terms/data-processing-addendum
Anthropic Ireland, Limited (Claude API)AI assistant processing, as a second option alongside Gemini. Not in use. Disclosed 1 August 2026; the earliest date any account can be moved to it is 31 August 2026.US (SCCs; Anthropic is not certified under the EU-US Data Privacy Framework). The contracting entity for customers in the EEA is Anthropic Ireland, Limited; the processing itself runs on US infrastructure.Pre-disclosed (not yet processing)anthropic.com/legal/data-processing-addendum
Stripe Inc.Payment processing and subscription managementEU/US (SCCs + DPF; EU data residency available)Activestripe.com/legal/dpa
Upstash Inc.Rate limiting and Redis cacheUS (SCCs in place)Activeupstash.com/trust/dpa
Resend, Inc.Transactional and lifecycle email deliveryUS (SCCs in place)Activeresend.com/legal/dpa
Google LLC (Google Analytics)GA4 website analyticsUS (SCCs + DPF)Active (analytics consent required)analytics.google.com/terms/dpa
Atlassian (Trello)Task import integrationUS (SCCs in place)Pre-disclosed (no live customers yet)atlassian.com/legal/data-processing-addendum
Google Workspace (Gmail)Inbound email integration (planned) and receipt of internal signup noticesUS (SCCs + DPF)Pre-disclosedcloud.google.com/terms/data-processing-addendum
Meta Platforms Ireland Ltd.Advertising pixel (Meta Pixel) and server-side conversion measurement (Conversions API)IE/US (SCCs + DPF)Active (only with marketing consent)facebook.com/legal/terms/businesstools
LinkedIn CorporationAdvertising pixel (LinkedIn Insight Tag)US (SCCs + DPF)Pre-disclosed (not yet wired)linkedin.com/legal/l/dpa
Google LLC (Google Ads)Advertising conversion trackingUS (SCCs + DPF)Pre-disclosed (not yet wired)cloud.google.com/terms/data-processing-addendum

Meta appears in this table for completeness, but it is not a processor: for the Meta Business Tools, Meta is a joint controller, as explained above. For Meta, the DPA column points to the Meta Business Tools terms, not to a data processing agreement.

5a. When we are the controller, and when we are your processor

TaskBerry has two roles, and which one applies depends on whose data it is. This is the same split throughout: in our privacy policy, in our DPA, and in our data protection impact assessment.

Your own data: we are the controller. Your e-mail address, your settings, your tasks, your billing record, our server logs. We decide what we do with those and why, and sections 3 and 7 set out the legal basis and the retention period for each.

Data about other people that you put into TaskBerry: you are the controller and we are your processor. Client names on a label, a pasted e-mail from a colleague, a meeting transcript. You decide what goes in and what it is for. We process it to run the product, on your instruction, and our sub-processors in section 5 do the same under contract with us.

Under Art. 28 GDPR that second role needs a written agreement. If you are on Pro, you already have one: our Data Processing Agreement applies to your account automatically as part of our terms, with no request and no e-mail. You can ask for a signed copy if your own administration needs one.

Schrems II and the EU-US Data Privacy Framework

Following the Court of Justice of the European Union's "Schrems II" judgment (Case C-311/18), transfers of personal data to the United States require additional safeguards beyond Standard Contractual Clauses (SCCs). Several of our US-based sub-processors — Resend, Google LLC, Meta Platforms, LinkedIn Corporation, and Upstash — combine SCCs with their certification under the EU-US Data Privacy Framework (DPF), an adequacy decision adopted by the European Commission on 10 July 2023 (Commission Implementing Decision (EU) 2023/1795).

Stripe offers EU data residency for primary processing and additionally relies on SCCs and DPF certification for incidental transfers. Resend relies on SCCs; we are tracking its DPF certification status and will update this disclosure when confirmed. We monitor ongoing legal challenges to the DPF (often referred to as "Schrems III") and will update this policy if the adequacy decision is invalidated or materially modified.

Anthropic is the exception, and we would rather point at it than let you find it. It relies on SCCs alone. We checked the official Data Privacy Framework participant list on 1 August 2026 and Anthropic does not appear on it, active or inactive, so there is no second safeguard behind the SCCs the way there is for Google and Stripe. That is one of the reasons no account is on it and the switch stays closed.

Under Article 15 GDPR you have the right to obtain information about the safeguards we rely on for any third-country transfer of your personal data, and under Article 21 GDPR you have the right to object to processing based on legitimate interest, including international transfers. You may exercise these rights by contacting privacy@taskberry.app.

6. International Data Transfers

Some of our processors are located in the United States. Transferring personal data from the European Economic Area (EEA) to the US is only permitted when adequate safeguards are in place.

For all US-based processors (Vercel, Google, Stripe, Upstash, and Anthropic once it is in use), we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission (Commission Implementing Decision (EU) 2021/914) as the legal mechanism for transferring your data. SCCs impose contractual obligations on the recipient to protect your data to EEA standards.

Google and Stripe also participate in the EU-US Data Privacy Framework (DPF), which provides an additional adequacy mechanism recognised by the European Commission. Participation in the DPF means these companies are certified to handle EU personal data in compliance with EU data protection requirements. Anthropic does not participate in the DPF (checked against the official participant list on 1 August 2026), so for Anthropic the SCCs are the only mechanism. Our contract there is with Anthropic Ireland, Limited, which is the entity Anthropic names for customers in the EEA, but the processing runs on US infrastructure, so it is still a transfer.

Our primary database (Supabase) is hosted in Frankfurt, Germany, within the EU, so no international transfer occurs for your core application data.

You can request a copy of the applicable SCCs or DPA for any processor by contacting us at privacy@taskberry.app. You can also access each processor's own DPA via the links in Section 5 above.

7. Data Retention

We retain your data for as long as necessary to deliver the service and meet our legal obligations. The table below sets out the specific retention periods for each category.

Every period below describes our active systems. Our database provider keeps encrypted backups for about 30 days, so a deleted row can still sit in a backup for that long before the backup itself rotates out. Backups are only ever used to restore the service after a failure.

Data categoryRetention period
Account data and task dataFor the duration of your account, plus 30 days after account deletion (to allow accidental-deletion recovery)
AI conversation transcripts (what you and the assistant said, word for word)90 days from the date of the conversation, or until account deletion, whichever comes first. You can also delete your history manually at any time. Until August 2026 this was 12 months; we shortened it because transcripts hold anything you pasted in, including other people's messages.
AI session summaries (one line per working day about what you decided)12 months from the date of the session, or until account deletion, whichever comes first. Contact details and other people's names are filtered out before a summary is stored, within the limits set out in section 4. Summaries written before August 2026 predate that filter. You can delete individual summaries from the assistant's memory page.
What the assistant changed for you (the hours it booked, the notes it added, and the value it replaced so you could undo it)90 days from the change, or until account deletion, whichever comes first. It holds copies of task titles and note text, so it gets the same short window as a transcript rather than the longer one for summaries. The billing record of an hour is separate and follows the seven-year row below.
The copy of your current conversation in your own browserUntil you sign out, and in any case no longer than 90 days. Clearing your browser data removes it immediately.
Context notesFor the duration of your account. You can delete individual notes at any time.
Billing records and transaction data7 years from the date of the last transaction, as required by Dutch tax law (Artikel 52 AWR)
Server access logs (Vercel and Supabase)Maximum 90 days, after which logs are automatically purged
Google Analytics data14 months, as configured in our Google Analytics account. Only collected after explicit consent.
Google Gemini (Google-side processing)Up to 55 days for abuse monitoring under Google's paid API terms, after which Google deletes the data from its systems
Anthropic Claude (Anthropic-side processing). Not in use today.Deleted within 30 days. If Anthropic's abuse systems flag a conversation, it keeps that conversation for up to 2 years and the scores behind the flag for up to 7 years. Anthropic's periods, not ours, and longer than Google's on the flagged path.
In-app screen visits (which screen, when, how long)90 days. These rows read like your working day, so we keep them briefly.
Milestones (sign-up, onboarding finished, first task, first AI use, first payment)730 days. Two years is the minimum that lets us compare one year with the previous one.
Internal signup notices in the founder's mailbox12 months

When you request account deletion, we will delete your personal data from our active systems within the 30-day grace period. Data that we are required to retain for legal reasons (such as billing records) will be isolated and not used for any other purpose.

8. Cookies

TaskBerry uses a small number of cookies. We distinguish between strictly necessary cookies (which do not require your consent) and optional analytics cookies (which require your explicit consent before being placed).

Strictly necessary cookies

These cookies are essential for the service to function and are placed regardless of your cookie preferences.

Cookie namePurpose
supabase-auth-tokenStores your authentication session so you remain logged in between page loads and browser sessions. Contains a JWT that expires and is automatically refreshed.
taskberry-consentStores your cookie consent preference (accepted or declined) so we do not show the cookie banner on every visit.

Analytics cookies

taskberry_utm — remembers which campaign brought you here, so we can tell which ad or link works. Only set after you accept analytics cookies, and only when you arrive through a tagged link. Expires after 180 days.

These cookies are placed only after you give your explicit consent via our cookie banner. You can withdraw your consent at any time via the Cookie Settings link in the footer.

Cookie namePurpose
_gaGoogle Analytics. Distinguishes unique users by assigning a randomly generated number as a client identifier. Expires after 2 years.
_gidGoogle Analytics. Used to distinguish users. Expires after 24 hours.

Marketing and advertising cookies

When you grant analytics consent, we use Google Analytics 4 and Vercel Analytics to measure how the site is used in aggregate. When you grant marketing consent, we use the Meta Pixel to measure ad performance and to optimise our advertising campaigns. The LinkedIn Insight Tag and Google Ads conversion tracking belong to the same marketing category and may run on the same basis. No tracking, marketing, or advertising scripts run without your explicit consent for the relevant category.

Alongside the Meta Pixel in your browser, and only when you have granted marketing consent, we share certain data directly from our server with Meta through the Conversions API. This covers your email address, which we hash with SHA-256 beforehand so it is never sent in readable form, your IP address, your user agent, and the Meta cookie identifiers _fbp and _fbc. We use this data only to measure ad conversions, for example when a trial turns into a paid subscription. Limited Data Use applies to these events, an extra restriction on how Meta may process the data. The identifiers we capture (_fbp, _fbc, the IP address, and the user agent) are stored only transiently and deleted the moment the conversion is sent to Meta.

The marketing cookies involved include _fbp and _fbc (Meta), _gcl_au, _gcl_aw, _gac_* (Google Ads conversion linker), and lidc, bcookie, UserMatchHistory (LinkedIn Insight Tag, third-party from licdn.com). The LinkedIn and Google pixels are not yet wired; we will update and re-disclose that list before either of those pixels is activated.

You can manage or withdraw your cookie consent at any time by clicking the Cookie Settings link in the footer of any page. Withdrawing consent for a category stops the corresponding scripts from collecting new data.

9. Your Rights

Under the GDPR, you have the following rights regarding your personal data. These rights apply to the extent permitted by applicable law and may be subject to certain conditions or limitations.

Right of access (Art. 15)

You have the right to request a copy of all personal data we hold about you, along with information about how it is processed — including the purposes, categories of data, and recipients.

Right to rectification (Art. 16)

If any of the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct it. Much of your data (tasks, labels, context notes) can be corrected directly within the application.

Right to erasure (Art. 17)

Also known as the "right to be forgotten." You can request that we delete your personal data. We will honour this request within 30 days, except where we have a legal obligation to retain certain data (such as billing records under Dutch tax law).

Right to restriction of processing (Art. 18)

In certain circumstances — for example, if you contest the accuracy of your data, or if processing is unlawful but you do not want erasure — you can request that we restrict how we use your data while the issue is being resolved.

Right to data portability (Art. 20)

Where processing is based on your consent or on a contract, and carried out by automated means, you have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV). You can also ask us to transmit this data to another controller where technically feasible.

Right to object (Art. 21)

Where we process your personal data on the basis of legitimate interest, you have the right to object to that processing. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. You can object to the use of server logs for security purposes, for example.

Right to withdraw consent (Art. 7(3))

Where processing is based on your consent (such as Google Analytics), you can withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before the withdrawal. You can withdraw analytics consent via the Cookie Settings link in the footer.

How to exercise your rights

To exercise any of the rights above, send an email to privacy@taskberry.app. Please include enough information for us to identify your account (your email address is sufficient). We will respond within 30 days of receiving your request. If your request is complex or we receive a high volume of requests, we may extend this period by a further two months, and we will inform you of this extension within 30 days.

If you are not satisfied with our response, or if you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Dutch data protection authority:

You also have the right to lodge a complaint with the supervisory authority in the EU member state where you habitually reside, work, or where the alleged infringement took place.

10. Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, accidental loss, disclosure, or destruction.

  • Encryption in transit: All communication between your browser and TaskBerry servers is encrypted using TLS (Transport Layer Security). Connections over plain HTTP are automatically redirected to HTTPS.
  • Encryption at rest: Your data is stored on Supabase (hosted on AWS Frankfurt) and Vercel, both of which encrypt data at rest using AES-256 at the infrastructure level.
  • Access controls: Our database uses Row Level Security (RLS), which means each user can only access their own data. API routes verify your identity on every request using a signed JWT. Service-role database access (which bypasses RLS) is restricted to server-side webhook processing only and is not accessible to client-side code.
  • Authentication: TaskBerry uses magic-link authentication via Supabase. We do not store passwords. Sessions expire and tokens are automatically refreshed.
  • No data sales: We do not sell, rent, or trade your personal data to any third party for any purpose. We share data with processors only to the extent necessary to operate the service.

Despite these measures, no system is completely secure. In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and, where required, inform affected users without undue delay.

11. Children

TaskBerry is not directed at children under the age of 16 and we do not knowingly collect personal data from minors. The service is a professional productivity tool intended for use by adults.

If you are under 16, please do not use TaskBerry or provide any personal data through the service. If we become aware that we have inadvertently collected personal data from a child under 16, we will delete that data as promptly as possible. If you believe we may have collected data from a minor, please contact us at privacy@taskberry.app.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the service, our processing activities, or applicable law. The date at the top of this page always shows when the policy was last updated.

For material changes — meaning changes that significantly affect your rights or how we process your data — we will notify you at least 30 days before they take effect. We will do this via email to the address associated with your account, and/or via an in-app notice when you log in.

For minor clarifications or corrections (such as fixing a typo or updating a link), we may update the policy without advance notice.

Record of sub-processor notices

Our DPA promises 30 days' notice before a new sub-processor starts processing. This is where that clock is on the record, so you can check it rather than take our word for it.

Sub-processorDisclosed onEarliest date it may start processing
Anthropic Ireland, Limited (Claude API), for the AI assistant1 August 202631 August 2026

Continuing to use TaskBerry after a policy change takes effect constitutes your acknowledgement of the updated policy. If you do not agree with the changes, you can request deletion of your account by emailing privacy@taskberry.app.

13. Contact

If you have questions about this Privacy Policy, want to exercise your rights, or have a concern about how we process your data, please contact us:

  • Email: privacy@taskberry.app
  • Company: Groeien met Gydo
  • Address: Van Houweningenstraat 70, 1052 TR Amsterdam, The Netherlands
  • KvK: 81071698

We aim to respond to all privacy-related enquiries within 5 business days. For formal rights requests (access, erasure, portability, etc.), we will respond within 30 days as required by the GDPR.