Legal
Privacy Policy
Effective date · 4 July 2026
Tasks is a task manager built by Foways. We keep it quiet by design, and we take the same approach to your data: collect only what the product needs to work, be plain about how it is used, and make it easy to take it back. This policy explains what we collect, why, who we share it with, how long we keep it, and the choices and legal rights you have.
Who we are
“Tasks” (the “Service”) is operated by Merieu Private Limited(“we”, “us”, or “our”), the company behind the Foways brand. Merieu Private Limited is the data controller for the personal information described in this policy.
This policy applies to the Tasks apps — the web app and the iOS and Android apps — and this marketing site. If you have any questions about it, or want to exercise your privacy rights, you can reach us at [email protected].
If you are in the European Economic Area (EEA) or the United Kingdom, you can contact us at [email protected] about your personal data, and you have the right to lodge a complaint with a supervisory authority — in the EEA, your national data-protection authority; in the UK, the Information Commissioner’s Office (ICO).
Information we collect
We collect a small, deliberate set of information:
- Account details. To create an account you provide your name and email address. You either choose a password or sign in through a third-party identity provider (for example, your existing Google or Apple account), in which case that provider confirms your email to us. We never see the password you use with a third-party provider. We also record your time zone, detected from your device, so dates and reminders line up with your day.
- Your content. The things you create in the app — projects, lists, tasks, notes (including your daily notes), tags, comments, and any file attachmentsyou upload (up to 10 MB each), which are stored through our self-hosted application backend (Convex). Free-text fields can hold whatever you type, so please treat them as you would a private notebook. This content is yours; we store and process it so the Service can show it back to you and to people you share it with.
- Team and sharing data. If you share a project or list, or invite a teammate, we record the email address you invite, the role you assign (Owner, Editor, or Viewer), and who has access to what. If you invite someone who does not yet have an account, we hold that email only to deliver and manage the invitation (see Invitations below).
- Support and community data. If you post to our in-app Support forum or report a bug, we store your post, any screenshots you attach, and basic context about the app screen you were on, so we can reproduce and fix problems. Forum posts are visible to other signed-in users; the technical context attached to a bug report is visible only to you and our staff.
- Technical, usage & diagnostic data. With your consent, we and our providers receive basic technical information when you use Tasks — such as your device type and operating system or browser, app version, approximate region (inferred from your IP address by our providers; we do not store your IP address in the app ourselves), and the actions you take in the product. We use PostHog for product analytics and Sentry for crash and error diagnostics. Analytics and diagnostics are off until you opt in: on the web, we ask for your consent before any analytics or diagnostics identifier is set; on the mobile apps, they stay off by default and are only ever switched on by you in Settings. Either way you can withdraw your consent at any time from Settings. We also deliberately minimise what we collect even after you opt in: automatic event capture and session recording are turned off, we send only specific events we have chosen, we replace your email address with just its domain (for example, “gmail.com”) before it reaches these tools, and we strip identifiers out of the URLs and error messages we send. We do not use any of this to build advertising profiles, and we do not sell it.
We do notask for, and the Service does not require, special-category (sensitive) personal information. Please don’t store it in your tasks or attachments either.
How we use your information
We use the information above to:
- provide, maintain, and operate the Service;
- authenticate you, keep your account secure, and remember your preferences;
- enable sharing and collaboration on the projects and lists you choose to share;
- send you transactional email that the Service needs to function — email verification, password resets, and project or list invitations;
- respond to your support requests and forum posts;
- where you have opted in, understand how the product is used, and diagnose crashes and errors, so we can fix problems and improve it;
- protect against abuse, enforce our terms, and meet legal obligations.
We send no marketing email and the Service has no push notifications. We will not email you to sell you anything.
Legal bases for processing
Where data-protection law (such as the EU/UK GDPR) requires a legal basis, we rely on the following, depending on the situation:
- Performance of a contract — to create and run your account and give you the Service you signed up for: your account details, your content, sharing, and the transactional email the Service depends on (email verification, password resets, and project or list invitations).
- Your consent (Article 6(1)(a) GDPR) — for product analytics and crash and error diagnostics. These stay off until you opt in, and you can withdraw your consent at any time from Settings, without affecting anything we did before you withdrew it.
- Our legitimate interests — to keep the Service secure, prevent abuse, respond to support requests, and deliver the invitations you send. Where we rely on legitimate interests we have weighed them against your rights, and you can object (see Your rights).
- Compliance with legal obligations — where the law requires us to keep or disclose information.
This is a general summary and not legal advice.
Sharing and service providers
We do not sell your personal data, and we do not share it for advertising. We share it only in these limited ways:
- With people you choose. Content in a shared project or list is visible to its members according to their role. When you invite someone, your name and the content you share become visible to them.
- With our service providers (sub-processors). We rely on a small number of trusted third parties to run the Service on our behalf. Each processes your information only to provide their service to us and is bound to protect it: Convex (our self-hosted application backend and database, which stores your account, your content, and the files you upload), Resend (transactional email), PostHog (product analytics), and Sentry (crash and error diagnostics). If you choose to sign in with Google or Apple, that provider authenticates you.
- For legal reasons. If we are required to by law, or to protect the rights, safety, and security of our users, the public, or Merieu Private Limited.
- In a business transfer. If Merieu Private Limited is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we will let you know before your information becomes subject to a different policy.
Invitations.When you invite someone to a project or list, we send them an email on your behalf that identifies you by the name on your account and names what you’re inviting them to, so they can decide whether to accept — we do this on the basis of our legitimate interest in enabling collaboration. Unaccepted invitations expire automatically. If you receive one you didn’t expect, you can ignore it, or write to [email protected] to have your address suppressed from future invitations.
Cookies and local storage
Tasks does not use advertising or tracking cookies.
- Strictly necessary.We use cookies and similar technologies that are strictly necessary to sign you in and keep your session secure, and we use your browser’s or device’s local storageto remember preferences such as your chosen theme, density, and layout. These don’t require consent and can’t be turned off without breaking the app.
- Analytics and diagnostics. Our analytics provider (PostHog) and, on error, our diagnostics provider (Sentry) set their own identifiers to measure usage and diagnose crashes, on the privacy-minimised basis described above. These are set only after you opt in, are never used for advertising, and you can withdraw your consent at any time from Settings.
Data retention and deletion
We keep your information for as long as your account is active and for as long as we need it for the purposes described in this policy.
- The Bin. When you delete items inside the app, they go to a Bin and remain recoverable until you empty it. Emptying the Bin purges those items.
- Deleting your account. You can delete your account at any time from Settings → Account → Delete account. Doing so removes your account, your content (projects, lists, and tasks), your day notes, your forum posts and comments, and the files you have uploaded. Limited copies may persist briefly in routine backups (see Backups below) before they age out.
- Operational data. Some operational data has a fixed, short lifespan: detailed activity-log entries are condensed into aggregate daily counts after about 30 days, and short-lived security records — rate-limit counters, and expired sign-in, verification, and invitation tokens — are cleared automatically within a day or so.
- Backups. Some information may persist for a limited period in routine backups after deletion, and we may keep information where we are required to comply with the law, resolve disputes, or enforce our agreements.
Your rights
Depending on where you live, you have rights over your personal data — including the right to access it, to correct it, to export/receive a portable copy of it, to delete it, to object to or restrict certain processing, and to withdraw consent where you have given it.
You can act on many of these directly in the app: edit your details and content, manage sharing, and delete your account. For anything you can’t do in-product — including a formal access or portability request, or a complete erasure — write to [email protected] and we will help. We aim to respond within one month, as the law requires.
You also have the right to complain to your local data-protection authority — in the EEA, your national supervisory authority; in the UK, the Information Commissioner’s Office (ICO).
Automated decision-making
We do not make decisions about you solely by automated means that produce legal or similarly significant effects, and we do not profile you for advertising. Our analytics are used in aggregate to understand and improve the product, not to evaluate you individually.
Children
Tasks is not directed to children, and we do not knowingly collect personal information from anyone under the age of 13 (or the minimum age required in your country, such as 16 in parts of Europe). If you believe a child has provided us with personal information, please contact us and we will delete it.
Security
We take reasonable technical and organizational measures to protect your information — including encryption in transit, access controls that check your identity and permissions on every request, rate limiting to curb abuse, and reputable infrastructure providers. We also minimise the personal data that reaches our analytics and diagnostics tools by design. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to keep your data safe and to address issues promptly if they arise.
International transfers
Your primary application data — your account and your content — is held on our own self-hosted backend. Some of our processors may process data in other countries, including the United States: our analytics provider (PostHog), our diagnostics provider (Sentry), and our transactional-email provider (Resend).
Where personal data leaves the EEA or the UK, we rely on an appropriate safeguard — such as the EU Standard Contractual Clauses(with the UK International Data Transfer Addendum) and, where available, the provider’s certification under the EU–US Data Privacy Framework— as set out in that provider’s data processing agreement. You can ask us for more detail at [email protected].
Changes to this policy
We may update this policy from time to time as the product and the law evolve. When we make material changes, we will update the effective date above and, where appropriate, let you know in the app or by email. Your continued use of the Service after an update means you accept the revised policy.
Contact us
Questions, requests, or concerns about your privacy? Write to us at [email protected] and we will get back to you. Our legal identity as data controller, and how to reach us if you are in the EEA or UK, are set out above under Who we are.