TurtleTask

Privacy Policy

We collect what the service needs to work and nothing for its own sake. No advertising, no analytics trackers, no selling of data.

Effective 10 September 2026.

Scope

This policy covers this website (turtletask.app) and the hosted TurtleTask application. For the personal data your organisation puts into TurtleTask — the names and work of your team — your organisation is the controller and we act as its processor under the data processing terms; questions about that data should go to your organisation's admins first.

What we collect

  • Account data. Your email address, display name and, for password sign-in, a hash of your password. If you use single sign-on, the identifier your identity provider gives us. If you enable two-factor sign-in, an encrypted authenticator secret and hashed recovery codes.
  • Organisation data. Whatever your organisation puts in the plan: tasks, comments, attachments, people, time off, and the history of changes to them, each attributed to the account or API key that made it.
  • Billing data. On the Team plan, the identifiers Stripe gives us for your customer record and subscription, and invoice history. Card details are entered on Stripe's pages and never reach us.
  • Technical data. Server logs recording requests, IP addresses, browser type, and sign-in outcomes. These exist for security — rate limiting, abuse prevention, incident investigation — and troubleshooting.
  • Correspondence. Emails you send us.

We do not collect anything from this website beyond ordinary server logs. There are no forms, accounts or trackers here.

How we use it

  • To run the service: sign you in, show your organisation its plan, send emails the service needs (password resets, sign-in links, notices to admins about account and plan changes), and bill the Team plan.
  • To keep it secure: detect abuse and investigate incidents.
  • To support you when you write to us.

Our legal bases are performance of our contract with your organisation, our legitimate interest in running a secure service, and compliance with law. We do not send marketing email, and we do not use your data to train models.

Who we share it with

Only the providers needed to run the service, each bound by a contract that limits what they may do with it: hosting and backup storage, payment processing (Stripe, for the Team plan), and email delivery. The current list is available on request. We share data with authorities only where the law requires it, and we tell you when we are allowed to.

We never sell personal data or share it for advertising.

Cookies

The application sets strictly necessary cookies only: a session cookie once you sign in, a cookie remembering a browser that has passed two-factor sign-in (for up to 30 days, if you ask for that), and a short-lived cookie during single sign-on. Browser storage also remembers view preferences such as your chosen gantt layout. None of these are used for tracking, and this website sets none at all.

Retention

  • Organisation data is kept while the organisation exists, then for 30 days after closure so it can still be exported, then deleted from live systems; backup copies expire on a fixed schedule after that. An admin can request deletion at any time on the same timetable.
  • Account data for a deactivated user is kept while the organisation exists, because the change history that attributes their work to them is part of the organisation's record. An admin can delete the account instead, which removes it.
  • Server logs are kept for a limited period for security purposes, then deleted.
  • Billing records are kept for as long as tax law requires.

Your rights

Under UK GDPR and EU GDPR you can ask to access, correct, delete, or export your personal data, to restrict or object to its processing, and to complain to a supervisory authority — in the UK, the Information Commissioner's Office. For data in your organisation's plan, your organisation's admins can do most of this directly (edit, export, delete); for anything else, email us and we respond within 30 days.

The service is for organisations and is not directed at children.

Contact

Privacy questions and requests: [email protected], subject line "Privacy". We will update this policy when our practices change and note the effective date at the top; material changes are emailed to organisation admins.