This page describes how TaskShelf protects the data you keep in it. It covers what is in place today. Questions not answered here can be sent to support@taskshelf.app.
1. Encryption in transit
Every connection to TaskShelf uses HTTPS with TLS. HTTP Strict Transport Security (HSTS) is enabled with a two-year max-age, so browsers refuse to connect over plain HTTP. Requests we make to Google, Microsoft, Slack, GitHub, and Dodo Payments also use TLS.
The web app sends a Content Security Policy and refuses to be framed by other sites.
2. How your data is stored
Workspace data (tasks, projects, comments, members, and settings) is stored in a PostgreSQL relational database. Files you attach are stored separately in object storage. Both are hosted on Amazon Web Services (AWS) in the Asia Pacific (Singapore) region, ap-southeast-1.
The database and file storage are encrypted at rest with AES-256. Calendar event titles, meeting links, and the OAuth tokens for connected accounts are also encrypted by TaskShelf with AES-256-GCM before they are written, so they are unreadable in the database itself.
3. Infrastructure
The database, file storage, and server functions run on AWS. The web app is served by Vercel. AWS holds SOC 2 Type II and ISO 27001 certifications, and Vercel holds a SOC 2 Type II report.
These are our providers' certifications, not ours. TaskShelf does not currently hold a SOC 2 report or ISO 27001 certification of its own.
4. Workspace isolation
PostgreSQL row-level security is enabled on every table. A workspace's data is isolated at the database layer, not only in the interface. A signed-in user can read and change rows only in workspaces they belong to.
Tables that hold billing records, rate limits, calendar events, and internal state grant no access to signed-in users at all. They are reached only through server functions that check who is asking.
Public share links are served by a server function that returns only the shared item. They do not grant access to the rest of the workspace.
5. Authentication
TaskShelf has no passwords. You sign in with a one-time code or link sent to your email, or with Google, Microsoft, Apple, or GitHub.
Two-factor authentication with an authenticator app is available to every user. Once you enrol, the database itself refuses access to your workspaces from a session that has not completed the second factor.
You can sign out of every other session from Settings.
6. Who can see your data
Nobody outside your workspace can see its content, except a small number of TaskShelf staff who access it only to operate the Service or to help when you ask for support.
Connected calendars are private to the person who connected them. No other user, including a workspace administrator, can read them.
7. Payments
Payments are processed by Dodo Payments, the merchant of record. Card details are entered on Dodo's checkout. TaskShelf never receives, sees, or stores a card number.
8. Backups
The database is backed up daily. Each backup is kept for 7 days and then deleted.
9. Your data is yours
You can export your workspace at any time from Settings: tasks as CSV, and the workspace structure and tasks as JSON. The REST API gives access to the same data.
Deleted tasks and projects stay in Trash for 30 days, then are permanently removed. Deleting a workspace or an account takes effect immediately. Copies in backups are gone once those backups expire, 7 days later.
After an account is deleted, we keep its email address so the same address cannot start a new free trial. Nothing else from the account is kept.
We do not sell customer data. We do not use customer data to train any model.
10. API and integrations
The REST API authenticates with bearer API keys and is limited to 120 requests per minute per key. Webhooks we send are signed with HMAC-SHA256.
Webhooks we receive from Slack, GitHub, and Dodo Payments are verified by signature before they are processed. Slack and Dodo Payments webhooks older than 5 minutes are rejected. Calendar access is read-only.
11. Subprocessors
These providers process customer data on our behalf. This list is updated when a provider changes.
- Amazon Web Services: database, file storage, and server functions, in the Singapore region
- Vercel: web hosting and cookieless page analytics
- Dodo Payments: payments, as merchant of record
- Resend: transactional email
- Sentry: error reporting
- Google: analytics and ad measurement (only with your consent), sign-in, and Google Calendar if you connect it
- Microsoft, Apple, GitHub, Slack: only if you sign in with or connect one of them
12. Reporting a vulnerability
If you find a security issue in TaskShelf, email support@taskshelf.app with the details and steps to reproduce it. We reply within 24 hours. Please give us reasonable time to fix the issue before disclosing it, and do not access data that is not yours.
Our security.txt file lists the same contact.
13. Incidents
If we confirm a breach that affects your data, we notify affected customers by email within 72 hours of confirming it, with what happened, what data was involved, and what we are doing about it.