How TaskDeck looks after your work.
Where your data lives, who can reach it, and what we keep and for how long, written from how TaskDeck is built today.
Where it runs
AWS in the United States
TaskDeck runs in Amazon Web Services’ us-east-1 region. The app and this site are served from S3 behind CloudFront; the API and its database run on a server with an encrypted disk.
Locked-down servers
Only the web ports are open. There is no SSH; administration goes through AWS Systems Manager.
Encrypted in transit
Everything is served over HTTPS, with TLS 1.2 or 1.3 on the API and the MCP server, and plain HTTP is redirected.
Daily backups
A snapshot of the server every day, with the last seven kept.
Secrets stay secret
Encrypted at rest
Tokens and keys you give TaskDeck are stored encrypted: sign-in provider tokens, the Slack and GitLab connections, your AI provider key, routine tokens and OpenAI keys, webhook secrets and incoming URL tokens.
Used once
The key or token for an import is used for that import only and erased when it ends.
Passwords
Passwords are stored as bcrypt hashes, never as text.
Signing in
Your choice of sign-in
A password, a passkey, or your Google, GitHub or GitLab account.
Sessions
The app’s session cookie can’t be read by scripts, every change is checked against request forgery, and a session ends after 12 hours without activity unless you choose to stay signed in on that device.
Rate limits
Signing in, registering, resetting a password and signing in with a passkey are limited to 10 attempts a minute.
AI assistants and agents
OAuth for every connection
Assistants connect over OAuth with PKCE. Access tokens last an hour and refresh tokens 30 days, and they work only on the MCP server.
You set the reach
When you approve a connection, you choose whether it acts as you or as one of your AI agents, and an agent’s connection reaches only the projects you grant.
No restructuring
An AI agent can never change the structure of a project, board or column, and can be a member or a viewer, never an admin.
Revoke at any time
Revoking a connection in your profile cuts off its token at once.
Who sees what
Roles
Admins, members and viewers, set per project.
Board access
Give a member every board, or only the ones you select.
Private notes
Notes on a card are visible only to the person who wrote them, not even to admins.
Routine sessions
While a routine session holds a card, only that session can change it.
On the record
Every change records who made it, a person or an AI agent, whether it came through an assistant connection, an automation or an integration, and the IP address it came from. IP addresses are never shown in the app or returned by the API.
Your data, your call
Delete your account
Delete account in your profile removes your account and the projects only you were in. Shared work stays, without your name or the IP addresses of your changes.
Error reports
Errors in the API are reported to Sentry, without personal data by default. The app and this site send none.
Analytics
Only this site uses analytics, and only after you agree; Cookie settings in the footer change your choice. The app has none.
A question, or something to report?
Write to us and we will get back to you.
Security
Questions about security
Where is my data stored?
In Amazon Web Services’ us-east-1 region, in the United States.
Do you keep backups?
Yes. A snapshot of the server every day, with the last seven kept.
Is there single sign-on or two-factor codes?
No. You can sign in with a passkey, or with your Google, GitHub or GitLab account.
Which services handle my data?
The privacy policy lists every one, and what each of them does.
Give your next project a clear starting point.
Create a board, add your first task, and bring your team together.
No credit card required · Free forever plan