Legal

Privacy Policy

Last updated 4 September 2026

The short version

  • · DiaTask stores what you put into it: your account, your tasks, your messages and calls.
  • · Your data is not sold, rented, or used to build advertising profiles.
  • · A few outside services are involved only where the feature needs them, and each is named below.
  • · You can ask for a copy of your data, or for your account and its contents to be deleted.

Who runs this service

DiaTask is operated by the person or organisation running this installation, reachable at [email protected]. They decide what is collected and why, and they are who to write to about anything on this page.

The service runs on infrastructure the operator controls, including its own database and its own file storage. It is not built on a third-party analytics or advertising stack.

What is collected

Only what a feature actually needs. Nothing here is gathered speculatively.

Account

Email address and a password stored only as an Argon2id hash - the password itself is never kept. Optionally a display name, time zone and language.

Your planning data

Tasks, projects, tags, comments, recurrence, follow-up checks and their answers, reschedules, and the daily statistics computed from them.

Telegram

If you link Telegram: your Telegram user and chat identifiers, and the messages you exchange with the bot, so tasks can be captured and follow-ups answered there.

Community and spaces

Your profile, connections, posts, space memberships and messages, including files you attach and reactions you leave.

Calls

Who took part and when, chat messages sent during a call, files shared in it, and - for someone joining by link - the display name they typed and a session identifier. Audio and video are not recorded.

Files

Attachments, avatars and call backgrounds you upload, stored in the operator's own object storage and readable only through short-lived links issued to you.

AI features

Text you send to the assistant, and the notes it writes back. These reach an AI provider only when one is configured; see below.

Security and diagnostics

Sign-in sessions and their rotation, anti-bot verification results, webhook events received from integrations, and error logs with identifiers redacted.

Why it is used

To run the product you signed up for: to plan and check your tasks, deliver follow-ups where you asked for them, hold calls and conversations, and keep your account secure. Security records exist to detect abuse and to recover from mistakes, not to profile you.

There is no advertising here, no behavioural tracking, and no sale or rental of personal data to anyone.

Who else is involved

Each of these is used for one purpose, and only when the matching feature is switched on.

Cloudflare Turnstile

Tells a person from a bot on public forms such as sign-up and password reset.

Telegram

Delivers and receives bot messages, when you have linked your Telegram account.

LiveKit

Carries the audio and video of a call between participants.

An AI provider

Answers assistant requests and, where enabled, prepares call notes. Which provider depends on what the operator or you configured; if none is configured, nothing is sent anywhere.

Google sign-in

Only if you choose to sign in with Google, and only to confirm the email address of the account.

Files, tasks, messages and backups stay on the operator's own infrastructure and are not handed to any of the services above.

Cookies

No advertising or analytics cookies are set. The cookies in use are the ones that make signing in work, and each is limited to this site:

daily_checker_refresh

Keeps you signed in between visits and lets your session be renewed.

daily_checker_csrf

Protects your requests from being forged by another site.

daily_checker_call_guest

Identifies a guest session for someone who joined a call by link.

daily_checker_call_guest_csrf

The same protection as above, for a guest.

daily_checker_google_oauth_state

A short-lived value that guards the Google sign-in exchange.

How long it is kept

Your account data stays while your account exists. Tasks, projects and their history remain until you delete them or the account.

Call history - who took part, chat messages and files from a call - is available for 30 days after the call ends, then stops being served. Guest sessions expire shortly after the call they belong to. Files you delete are removed from storage by a background job, usually within the hour.

Where AI notes are used, the transcript and the report they produce are deleted 30 days after the call ends, on the same schedule and without anyone having to ask. Audio is never written to disk.

Your choices

You can view and correct your details in Settings, export your tasks and tags from there, remove individual items at any time, and disconnect Telegram or any AI provider you added.

To request a copy of everything held about you, or to have your account and its contents deleted, write to [email protected]. Deletion removes your account, your content and your files; some records may briefly persist in backups before those rotate out.

How it is protected

Passwords are hashed with Argon2id and never stored in readable form. Sessions use short-lived access tokens with rotating refresh sessions. Files are reachable only through signed links that expire in a minute, and never by guessing an address. Public forms are protected against automated abuse, and sensitive values are kept out of logs.

No system is perfect. If you believe an account or a piece of data has been exposed, please write to the address above and say so plainly - it will be treated as urgent.

Children

This service is meant for adults and is not directed at children. If you believe a child has created an account, write to the address above and it will be removed.

Changes to this policy

When this policy changes, the date at the top changes with it. Changes that affect what is collected or who it is shared with will be announced in the product rather than made quietly.

Questions about anything here? Write to [email protected].
Privacy Policy · DiaTask