TaskKoala

Privacy policy

Last updated: 10 June 2026

This policy explains how TaskKoala (“we”, “us”, “our”) handles your personal data when you use our website and application. We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who we are

TaskKoala is operated from the United Kingdom. For data protection queries, contact us at [email protected].

What data we collect

Depending on how you use the service, we may process:

  • Account data — name, email address, and authentication credentials (password stored in hashed form).
  • App content — tree names, leaf titles, priorities, status, and related timestamps you create in the app.
  • Billing data — subscription status and payment references. Card details are handled by our payment provider; we do not store full card numbers.
  • Technical data — IP address, browser type, device information, and logs needed for security and operation.
  • Communications — messages you send to us for support.

How we use your data

We use personal data to:

  • Provide and maintain your account and the focus, tree, and leaf features you request.
  • Process payments and manage subscriptions.
  • Send service emails such as verification, security, or billing notices where applicable.
  • Keep the service secure, prevent abuse, and fix errors.
  • Comply with legal obligations.

Our lawful bases under UK GDPR typically include contract (running the service you signed up for), legitimate interests (security, improvement, and fraud prevention), and legal obligation where required. Marketing emails, if we send any, would rely on consent or soft opt-in only where permitted.

Sharing your data

We do not sell your personal data. We may share it with:

  • Service providers — hosting, email delivery, Fathom Analytics (privacy-friendly website analytics), and payment processing. They act as processors under contract and only use data on our instructions.
  • Authorities — when required by UK law or to protect rights and safety.

Some providers may process data outside the UK. Where that happens, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses.

Retention

We keep account and app content while your account is active. If you delete your account, we delete or anonymise personal data within a reasonable period, except where we must retain information for legal, tax, or dispute purposes (for example billing records).

Cookies and similar technologies

We use essential cookies and similar technologies for authentication, security, and remembering preferences (such as appearance settings). These are necessary for the service to function. We do not use non-essential tracking cookies unless we clearly tell you and, where required, obtain consent.

Your rights

Under UK data protection law you may have the right to:

  • Access a copy of your personal data.
  • Rectify inaccurate data.
  • Erase data in certain circumstances.
  • Restrict or object to processing in certain circumstances.
  • Data portability for data you provided, where applicable.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with the Information Commissioner’s Office (ICO) — ico.org.uk.

To exercise your rights, contact us using the details above. We may need to verify your identity before responding.

Children

The service is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data to us, please contact us so we can delete it.

Changes to this policy

We may update this policy from time to time. We will post the new version on this page and adjust the “last updated” date. Significant changes may be highlighted in the app or by email where appropriate.

Related documents

Please also read our terms of service. For product questions, see the FAQ.