Privacy Policy

What we collect, why, where it lives, how long we keep it and how to take it back. Plain language first; the legal bases follow.

Version 2026-09-13-v1. Reviewed: Reviewed and approved by Wesley Lowman, 2026-09-13. Questions: support.

This policy explains what personal data Lowman Enterprises, LLC (d/b/a Auritron, “TaskSaber”, “we”) collects when you use the TaskSaber web app, iOS and Android apps, API and agent endpoint, and this website; why we collect it; where it lives; how long we keep it; who else processes it; and the choices you have. We are the data controller for the data described here. TaskSaber uses an account and stores your workspace on our servers. Your browser or app may keep a local cache. An internet connection is required to sign in and sync.

1. What we collect

Account data. Your email address, a random account identifier, sign-in timestamps and your chosen plan. Passwords are handled by Amazon Cognito; we never see them. If you enable multi-factor authentication, Cognito stores the enrolment.

Workspace content. The tasks, projects, comments, tags, due dates, dependencies and other material you create, and the organization memberships, roles and invitations you set up. This is the data the Service exists to hold; we do not analyse it for advertising and do not use it to train machine-learning models.

Billing data. Purchases are sold through Link (Stripe) as merchant of record. Stripe collects your name, billing address and payment details on its hosted checkout; we receive only the resulting subscription status, plan, seat count, invoice identifiers and amounts, and the webhook events needed to keep your access correct. We never receive or store card numbers.

Integration authorizations. If you connect GitHub, Jira or Slack, we store the authorization token that service issues so we can act on your request, encrypted with a dedicated key. We access those services only when you trigger an import, update or read from inside TaskSaber; there is no background synchronization.

Agent credentials and usage. If you create an agent credential, we store a salted hash of it (never the secret itself), its label, scopes, creation and last-use times, and a monthly usage count per account.

Email records. A log of the transactional and lifecycle emails we send you (recipient, template, timestamp, delivery outcome) and a suppression list of addresses that bounced, complained or unsubscribed, so we stop sending.

Operational and security logs. Server logs (IP address, user agent, request path, status, timing) and an audit trail of administrative access to our infrastructure, including access to the database that stores your content.

What we do not collect. This website sets no advertising or analytics cookies and runs no third-party tracking. The app uses a session cookie and a CSRF token on our API origin only. We do not collect precise location, contacts, photos or device identifiers beyond what your browser or the app stores send with each request.

2. Why we use it and our legal bases

To provide the Service you asked for and perform our contract with you (account, content, billing, integrations, agents, transactional email); to meet legal obligations (tax and accounting records held by Link, security logging, responding to lawful requests); and for our legitimate interests in keeping the Service secure, preventing abuse and fraud, and improving it using aggregate, non-content metrics. Product-update emails are sent only where permitted and always with a one-click unsubscribe link.

3. Where your data is stored

The Service runs on Amazon Web Services in the US East (N. Virginia) region. Workspace content and billing records are stored in databases encrypted with a customer-managed encryption key whose policy denies decryption to everyone except the running application — including our own administrators — and logs every policy change. Data is encrypted in transit with TLS.

4. Who processes it for us

Amazon Web Services (hosting, identity via Cognito, email delivery via SES, storage and backups). Stripe, Inc. and Link (payments, invoicing, tax, refunds and disputes, as merchant of record under their own privacy policy). GitHub, Atlassian and Slack — only if you connect them, and only for the requests you trigger. Apple and Google distribute the native apps through their stores under their own terms. We do not sell personal data and do not share it with advertisers.

5. How long we keep it

Account data and workspace content: for as long as your account exists. Continuous backups of the content database are kept for 35 days and cannot be used to restore data you have deleted. Billing webhook receipts: about 30 days after processing. Email send logs and the suppression list: retained so we do not email people who asked us to stop. Infrastructure audit logs: up to seven years, as security and compliance records. Server request logs: 90 days.

6. Deleting your account

You can delete your account yourself from Settings. Deletion is authenticated, so we know it is you. It revokes your sessions, agent credentials and integration authorizations, cancels any subscription at the end of the paid period, erases your workspace content and your sign-in identity, and shows you each stage’s progress. If you own an organization that still has other members, deletion is paused until you transfer ownership to another member (nothing is revoked while it waits); an organization with no other members is erased with your account. Afterwards we keep only: Link’s billing and tax records (which Link controls), the security audit trail, the suppression-list entry for your address if you had opted out of email, and a minimal record that a deletion request for your account identifier was completed — kept so that a restored backup can never resurrect your data. Deletion requests sent by email are answered by asking you to sign in and use the Settings flow, because we cannot verify identity by email alone.

7. Your rights and choices

You can export your content at any time as JSON or CSV from the app, correct it directly, delete it, disconnect integrations, revoke agent credentials, and unsubscribe from product-update email with one click. Depending on where you live you may also have rights to access, portability, restriction, objection or to lodge a complaint with a supervisory authority; contact support@tasksaber.com and we will respond within 30 days. We do not make decisions about you by automated means that have legal or similarly significant effects.

8. Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

9. International transfers

If you use the Service from outside the United States your data is transferred to and processed in the United States as described above. Where required, we rely on the standard contractual protections our processors provide.

10. Cookies and similar technologies

The web app sets a session cookie (HttpOnly, Secure) and a CSRF token on our API origin so you stay signed in and requests can be verified. The browser also keeps a local cache of your workspace for speed. Neither this website nor the app uses advertising, analytics or cross-site tracking cookies, and we do not respond differently to “Do Not Track” signals because we do not track. Stripe’s hosted checkout sets its own cookies under Stripe’s policy.

11. Notice to residents of California and other US states

In the past twelve months we have collected the categories described in section 1 (identifiers, account and billing information, content you provide, internet activity such as server logs). We use them for the purposes in section 2 and disclose them only to the processors in section 4. We do not sell personal information and do not share it for cross-context behavioural advertising, and we have no actual knowledge of selling or sharing data of anyone under 16. You have the right to know, access, correct, delete and port your data and not to be discriminated against for exercising those rights; exercise them from the app or by emailing support@tasksaber.com. We do not use or disclose sensitive personal information for purposes other than providing the Service.

12. Security and incident notice

We protect data with encryption in transit and at rest, per-tenant access controls enforced at the database, hashed credentials, audit logging and monitored alarms. No system is perfectly secure. If a breach affects your personal data we will notify you and any required authority without undue delay and in any case as required by law.

13. Legal requests

We disclose personal data to authorities only when legally compelled by a valid request, and we notify affected users unless legally prohibited.

14. Changes

The version and review date appear at the top of this page. For material changes we will notify account holders by email or in the app before they take effect.

15. Contact

Lowman Enterprises, LLC (d/b/a Auritron), Alabama, United States — support@tasksaber.com.

Account deletion information