← Back to TaskFlow
Privacy Policy
Effective date: 18 April 2026 · Last updated: 25 September 2026
1. Who we are
TaskFlow is a task and appointment management SaaS product operated by
Ease AI (“TaskFlow”, “we”, “us”). Contact:
privacy@ease-ai.my.
This policy explains what personal information TaskFlow collects, how we
use it, how we share it, and the rights you have over it.
2. Scope
This policy covers:
- The public marketing site at
taskflow.ease-ai.my.
- Per-tenant workspace subdomains (e.g.
<yourbrand>.taskflow.ease-ai.my).
- Our admin operations console at
admin.taskflow.ease-ai.my.
- All background integrations (Google Calendar, WhatsApp via Baileys, Telegram alerts).
3. Information we collect
3.1 Account & workspace data
- Name, email address, optional phone number for the admin who signs up.
- Company name, optional logo uploaded during onboarding.
- Team-member names, emails, optional WhatsApp numbers and Telegram chat IDs you choose to add.
- Tasks, projects, appointments, notes, and attachments created inside your workspace.
- Authentication artefacts: password hashes (bcrypt), session cookies, CSRF tokens.
3.2 Google Calendar data (opt-in)
If an admin connects a Google account via the in-app Connect Google
Calendar button, TaskFlow stores:
- An OAuth refresh token and short-lived access token, both encrypted at rest with AES-256-GCM.
- The email address of the connected Google account (for display only).
- The IDs of the Google calendars the admin selects to sync.
- A mirror of events from those calendars: title, time, location, attendees, description. This mirror is kept only so TaskFlow can send reminders, expose the events on the UI, and detect changes.
TaskFlow requests only the three OAuth scopes it needs:
calendar.events (read/write events),
calendar.readonly (list calendars) and
drive.file (only the Google Drive files a user explicitly picks
in the Drive file picker to attach to a task). For an attached Drive file,
TaskFlow stores its name, link and file ID on the task; it cannot see any
other file in your Drive. TaskFlow does not read or store
contacts, Gmail content, or any data outside the calendars the admin
explicitly selects and the files a user explicitly attaches.
Disconnection: an admin can revoke TaskFlow's access at any
time from the in-app Settings page, or directly via
myaccount.google.com/permissions.
On disconnect, stored tokens are cleared; existing calendar events in your
workspace remain visible so historical context is not lost, but no further
sync is performed until you reconnect.
3.3 WhatsApp integration data
If your workspace connects a WhatsApp account via QR code scan:
- A Baileys session auth state is stored in a server file so the session survives restarts. This contains cryptographic keys to your WhatsApp account. It stays on the TaskFlow server.
- Phone numbers TaskFlow is configured to send reminders to.
- The text of automated messages TaskFlow sends.
- Incoming messages TaskFlow acts on: messages containing
@task, @sub or @meet, replies to TaskFlow's own task cards, and — only if an admin turns on the optional stand-up feature — stand-up replies. TaskFlow stores the task created from such a message and any photo or document sent with it. All other messages in a group are ignored and not stored.
3.4 Operational / log data
- Server logs (requests, errors, timestamps). Kept for up to 14 days.
- Admin alert events pushed to our internal Telegram channel (for example, a failed login burst). These contain no message bodies.
- Daily database backups (MySQL), retained for 14 days.
4. How we use information
We use the information above strictly to:
- Operate your TaskFlow workspace and its features (tasks, reminders, reports).
- Sync appointments with Google Calendar and send WhatsApp reminders before events start.
- Authenticate users and enforce admin-only actions.
- Detect abuse or misuse (rate limiting, failed-login alerts).
- Back up data so we can restore your workspace if something goes wrong.
- Contact you about service issues, security incidents, or material changes.
TaskFlow does not sell personal information and does not use Google user
data for advertising.
5. Google API Services user data policy compliance
TaskFlow's use and transfer of information received from Google APIs
adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. In practice:
- Google Calendar data is used only for the features you see in the UI (sync, display, reminders).
- Google Calendar data is never sold or shared with third parties.
- Google Calendar data is never used for advertising.
- Google Calendar data is not read by humans except with your explicit consent for debugging, or where required by law.
6. Sharing
We share personal data only with the following categories:
- Your own team members. Data inside your workspace is visible to the team members you add.
- Infrastructure providers. Our servers run on VPS infrastructure located in Malaysia / Singapore. The hosting provider may process data incidentally while operating the hardware but does not read it.
- Google. When you connect Google Calendar, your Google account metadata and calendar events flow between TaskFlow and Google per their standard terms.
- AI processing (Groq, Inc.). When someone sends an
@task, @sub or @meet message, its text and the names of your team members are sent to Groq's API so TaskFlow can understand who the task is for, what it is and when it is due. It is used only to create or update that task.
- Telegram. Operational alerts to our internal admin chat pass through Telegram's infrastructure.
- WhatsApp (via Baileys). Reminder messages you configure flow through the WhatsApp Web protocol to your connected number.
- Legal requirements. We will disclose data if compelled by a valid Malaysian legal process, and will challenge overbroad requests.
7. Retention
- Workspace content: retained as long as your workspace is active. On written request to delete your workspace, content is removed within 14 days and backups roll off within an additional 14 days.
- Google OAuth tokens: retained until you disconnect, after which tokens are cleared from the database.
- Server logs: 14 days.
- Database backups: 14 days rolling.
8. Your rights
Subject to local law (we operate under Malaysia's PDPA 2010 by default), you can:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your account and workspace (contact us in writing).
- Export your workspace data (contact us; we will provide a MySQL dump).
- Withdraw Google Calendar consent at any time without affecting the rest of the service.
To exercise these rights, email
privacy@ease-ai.my.
We aim to respond within 30 days.
9. Security
TaskFlow uses bcrypt for password hashing, AES-256-GCM for at-rest
encryption of OAuth tokens, TLS 1.2+ for all in-transit traffic, and
cookie-based JWT session tokens with a 7-day rolling lifetime that always end after 90 days at most. We keep the
software patched and monitor for anomalies, but no system is absolutely
secure — if you discover a vulnerability, please email
security@ease-ai.my.
10. Cookies
TaskFlow sets a small number of functional cookies:
app_session_id — your authenticated session.
member_session — team-member session.
google_oauth_state — short-lived CSRF token used only during the Google consent flow.
We do not set advertising or tracking cookies.
11. Children
TaskFlow is a business product and is not directed at children under 13. We
do not knowingly collect personal data from children.
12. Changes
We may update this policy as the product evolves. Material changes will be
announced inside your workspace and by email to the workspace admin. The
“Last updated” date at the top always reflects the current version.
13. Contact