Privacy Policy
Cotask keeps your tasks, account, and subscription information so the app works for you. No ads, no cross-app tracking, and no data sold or shared with advertisers.
Effective 29 September 2026
Who we are
Cotask is a task manager for iOS and macOS, made by Pedro Schott. Questions about this policy or your data: pedroschott.work@gmail.com.
What we store
- Your account. The email address you sign up with, and a password stored only as a salted hash by our authentication provider. We never see your password.
- What you create. Tasks, notes, projects, due dates, statuses and the links you attach — including each link's page title and site favicon, which the server resolves once when the link is added.
- History. A record of major changes to your tasks and projects: what changed, when, and whether it came from you (and from which kind of device — iPhone, iPad, Mac or the widget) or from an agent.
- Files. Files and images you attach to tasks, including their names, sizes, and storage metadata.
- Subscriptions. Your account identifier, subscription purchases, entitlement status, and purchase history needed to manage Cotask Pro through Apple and RevenueCat. We do not receive your payment card details.
- Agent access. Names and hashed API keys for the agents you connect, plus the authorizations you grant to MCP clients such as ChatGPT or Claude.
We use RevenueCat to manage purchases, verify subscription access, and understand subscription performance. We do not use advertising SDKs, track you across apps or websites, or build advertising profiles. We never sell your data.
Where it lives
Your data is stored in a Supabase project (PostgreSQL) hosted on AWS in the São Paulo region (sa-east-1), and in an encrypted cache on your own devices so the apps work offline. Every row is protected by Row Level Security keyed to your user id: only your signed-in session — or an agent you have authorized — can read or write it.
Authentication emails and subscriptions
Supabase manages account authentication. Resend delivers account confirmation, sign-in, password reset, and email-change messages from our domain. These providers process your email address and the information needed to deliver and secure the message. Apple processes purchases; RevenueCat manages subscription status using your account identifier and purchase receipts. These services may keep operational logs needed for security and reliable delivery.
Agents you connect
When you add Cotask as a connector in ChatGPT, Claude or another MCP client, that assistant can read and manage your tasks and projects on your behalf until you revoke it. Anything it creates arrives as a draft for you to accept or dismiss. What you send to that assistant, and what it does with it, is governed by that company's own privacy policy — not this one. You can revoke access at any time in Settings → Agents.
Link previews
When a link is attached to a task, our server fetches that page once to read its title and favicon. The request comes from our server, carries no information about you, and only the title and icon URL are stored.
Deleting your data
You can delete individual tasks and projects at any time. To remove everything, open Settings → Delete Account in the iOS app (or Settings → General → Delete account on the Mac). Deleting the account immediately and permanently removes your tasks, projects, links, history, filters, agent keys and authorizations, along with the account itself. It cannot be undone. If you cannot access the app, email us and we will delete the account for you.
Children
Cotask is not directed to children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes in a material way, we will update this page and the effective date above.