Privacy Policy
Last updated: 22 August 2026
This policy explains what Magnetask collects, why, who it is shared with, and how long it is kept. Magnetask is operated by Lemon Qube LLC, 2810 N Church St #872615, Wilmington, DE 19802, United States. For any privacy question or request, contact privacy@magnetask.app.
1. What we collect
Account data. Your name, email address, profile photo if you set one, and the workspace you belong to. If you sign in with Google, we receive your name, email and profile photo from Google — we never receive your Google password.
Task data. Everything you create in Magnetask: tasks, descriptions, deadlines, assignees, comments, pipelines and activity history.
Connected-tool data. When you connect a tool such as Slack, we receive content from that tool so we can turn it into tasks. See section 3, which describes exactly what is read and what is kept.
Billing data. Plan, subscription status and billing identifiers. We never see or store your card details — payments are handled entirely by Stripe.
Operational data. Sign-in sessions and the devices used, so you can review and revoke them; plus standard server logs.
2. How we use it
To provide the service: create and manage tasks, notify assignees, run your workspace and process your subscription. We also use aggregated, non-identifying operational data to keep the service reliable.
We do not sell your data. We do not use your data or your messages to train third-party AI models, and our AI provider is contractually bound not to train on data submitted through their API.
3. Connected tools, and exactly what we keep
What is read and stored differs per integration, so each one is described separately. This section grows as we add integrations.
Slack. With your permission, Magnetask joins channels and reads messages in order to identify requests that should become tasks. Concretely:
- Messages are checked first by local, non-AI logic running on our own servers. Most messages are resolved this way and are never sent anywhere else.
- Only messages that this local logic cannot confidently judge, and messages that become tasks, are sent to our AI provider (see section 4) to extract a task from them.
- When a message becomes a task, we keep the original message text so you can see the task’s context and open it in Slack.
- For messages that do not become tasks, we do not keep the message text. We keep only a de-identified list of word stems, used to improve detection accuracy, which cannot be reassembled into the original message. Names, email addresses, channel references and dates are replaced with placeholders before this is stored.
- Your Slack access token is encrypted at rest (AES-256-GCM) and is used only to act on your behalf within your workspace.
- Disconnecting Slack stops all access immediately.
Everyone in a workspace where Magnetask is installed should be aware that messages in connected channels are processed as described above. As the customer, you are responsible for informing your team and for having a lawful basis to connect the tool.
4. Who we share it with (subprocessors)
We use the following providers to run Magnetask. Each processes data only to provide their service to us.
- Anthropic — AI extraction: turning a message into a structured task. Receives message content for the messages described in section 3. Does not train on it.
- Supabase — database hosting. Stores all application data.
- Vercel — application hosting and delivery.
- Inngest — background job processing (task extraction, reminders, scheduled work).
- Stripe — payments and subscription billing. Handles card data directly; we never receive it.
- Resend — transactional email (assignment, due-soon and overdue notifications).
- Slack and any other tool you choose to connect — as the source of the data you asked us to process.
5. How long we keep it
- Account and task data — for as long as your account is active. Deleting your workspace or account deletes it: tasks, drafts, notes, comments, integration tokens and the content brought in from connected tools are removed and cannot be recovered.
- A record that the account existed — kept after deletion: the name, the email address, and when and why it ended. Nothing else — no tasks, no message content, no access tokens — and the account can no longer be signed in to. We keep this so we can answer questions about a closed account and tell a closure you asked for apart from one we made. You can ask us to erase that too, and we will, except where tax or accounting law requires us to keep the billing record.
- De-identified detection data from messages that did not become tasks — automatically deleted after 45 days.
- Messages queued for processing — expire after 7 days and are deleted within 30 days.
- Billing records — retained as long as required by tax and accounting law.
6. Security
Data is encrypted in transit. Access tokens for connected tools are encrypted at rest with AES-256-GCM. Each workspace’s data is isolated, and database-level row security is enabled. Access to production systems is limited to those who need it.
No service can promise perfect security. If a breach affects your data, we will notify you and any relevant authority as required by law.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict processing, and to complain to a data protection authority.
You can edit your profile and delete your account or workspace from within Magnetask at any time. Deleting removes your data but leaves the minimal record described in section 5 — your name, email address, and when and why the account ended. For anything else, including erasing that record, email privacy@magnetask.app and we will respond within 30 days.
Where the UK or EU GDPR applies, we act as the processor for the content you bring in from connected tools, and your organisation is the controller. We are the controller for your account and billing data.
9. International transfers
Our providers may process data in countries outside your own, including the United States. Where required, these transfers rely on Standard Contractual Clauses or another approved safeguard.
10. Children
Magnetask is a workplace product and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
If we make a material change we will update the date at the top and, where the change is significant, notify account owners by email before it takes effect.