Legal

Privacy Policy

Last updated 28 September 2026

In short

  • TaskFlow 365 is a work tool. It holds what you and your colleagues put into it — tasks, messages, files, meetings — for your organisation.
  • There is no advertising, no analytics or tracking SDK, and we do not sell data.
  • We record the IP address and browser or device user-agent for app-distribution activity, secret-wallet access and support requests.
  • Accounts are closed, not erased. A closed account cannot sign in, and the work it contributed stays in the organisation's workspace.

1. Who we are

TaskFlow 365 ("we") provides a workspace for organisations: tasks and projects, team chat, calls and meetings, time tracking, a secret wallet and app distribution, on the web and in apps for Android and iOS.

Your account belongs to an organisation — usually your employer — and that organisation decides who is in its workspace and what they can do. We run the service for it. This policy explains what the service itself collects and does. Questions: umer.iftikhar@ideas.com.pk.

2. What we collect

Your account.

  • Name, email address, role in the organisation, department, job title, and optionally a phone number and a profile photo.
  • Your password, stored only as a one-way bcrypt hash. If you sign in with Microsoft or Google, there may be no password at all.
  • If you sign in with Microsoft, the service receives your Microsoft account id, name, email, department and job title, and your Microsoft profile photo if you have not uploaded one of your own.
  • When you last signed in, and your notification preferences.

Your work. What you and your colleagues create:

  • Tasks, subtasks, projects and milestones, with their history of changes, reminders and due dates.
  • Time entries: when a timer started and stopped, and any note.
  • Meetings: title, agenda, date, attendees, notes, and when each attendee joined and left a call.
  • Contacts your organisation stores: name, email, phone, company and department.
  • Chat messages, reactions, polls, voice notes and attachments. Up to 10 files of 50 MB each can be sent in a message.

Calls and recordings.

  • Audio and video calls are relayed through a media server we run ourselves (LiveKit). The server does not record calls.
  • On the web, a participant can choose to record a meeting from their own browser. That recording is uploaded and attached to the meeting.
  • Voice notes you record in chat are uploaded as attachments.

Secret wallet.

  • Credentials and files your organisation stores in the wallet.
  • A log of who created, viewed, downloaded, changed or shared each secret, including the IP address and user-agent of each access.

App distribution.

  • App builds your organisation uploads for its testers.
  • A log of each upload, download, link click, deletion, access change and tester-group change. Each entry includes the IP address and user-agent it came from.

Your devices.

  • A push-notification token for each phone you use the app on, so notifications and incoming calls can reach you.
  • On iPhone, a separate call-notification token.

Support requests.

  • What you type into the support form: email, and optionally your name, company name and message.
  • The IP address and user-agent it was sent from, to deal with abuse.

Server logs. Like most web services, our servers log each request: IP address, user-agent, the address requested and the time.

What we do not collect.

  • No advertising identifiers and no analytics, crash-reporting or tracking SDKs.
  • No location.
  • No access to your phone's address book or calendar app.

3. Microsoft 365 and Google

An organisation can connect its Microsoft 365 or Google account. When it does, you are asked to consent, and the service uses that access as follows.

Microsoft — permissions: User.Read, User.ReadBasic.All, Calendars.ReadWrite, Files.Read.All, Sites.Read.All, offline access. The service:

  • reads your profile and photo, and your mailbox time zone;
  • searches your organisation's directory when you look for a colleague;
  • lets you browse OneDrive and SharePoint to attach a file. It stores a link to that file, not a copy;
  • creates, updates and removes events on your own calendar for TaskFlow meetings and task reminders.

Google — permissions: calendar, directory (read-only), Drive (read-only), contacts (read-only). Used in the same way: your profile, directory search, attaching Drive files, and events on your primary calendar.

What calendar events contain. Title, description, time, location, a link back to TaskFlow 365, and the attendees' email addresses.

Access tokens for these services are encrypted with AES-256-GCM before they are stored.

4. Permissions on your phone

The mobile app asks for these only when you use the feature that needs them:

  • Camera — taking a photo to send, and video in calls.
  • Microphone — calls and voice notes.
  • Photos and storage — choosing a file or picture to send, and saving one you received.
  • Notifications — messages, reminders and assignments.
  • Calls — showing an incoming call on the lock screen, and keeping a call running in the background.
  • Battery optimisation exemption (Android, optional) — so incoming calls are not delayed.

5. How we use it

  • To run the service: show your organisation's work to the people in it, deliver messages, calls and notifications, and keep calendars in step.
  • To keep it secure: verify sign-ins, enforce roles and permissions, record who accessed sensitive items, and investigate abuse.
  • To answer support requests.

We do not use your data for advertising, we do not sell it, and we do not build profiles of you for anyone else.

6. Who can see your data

  • People in your organisation, according to the roles and permissions your organisation sets. Examples: a task is visible to the people it is shared with, a chat to its participants, and a secret only to those it is granted to.
  • Your organisation's owner and administrators can manage accounts, read audit and distribution logs, and close accounts.
  • Other organisations cannot see your data. Each organisation's workspace is separate.
  • The TaskFlow 365 team uses a platform console that shows organisation-level details: the plan, seat count and the owner's name. It is not a way to read your organisation's tasks, messages or secrets.

Files. Attachments are delivered through web links. Someone who obtains the link to a file may be able to open it without signing in, so treat file links like the files themselves.

7. Services we rely on

  • Hosting. The service, its database, file storage and call server run on servers we operate.
  • Google Firebase Cloud Messaging — push notifications to the Android and iOS apps.
  • Apple Push Notification service — incoming calls on iPhone.
  • What a notification contains. Its title and text, for example a task title or the sender's name and message preview. An incoming call carries the caller's name and the conversation title.
  • Microsoft and Google — only if your organisation connects them (section 3).
  • Email. Invitations, reminders and similar messages are sent through an email server configured for the service.

We disclose data to others only when the law requires it.

8. How it is protected

  • Traffic to the service is encrypted in transit (HTTPS).
  • Passwords are stored only as bcrypt hashes.
  • Secret-wallet items and app builds are encrypted at rest with AES-256-GCM, each with its own data key.
  • Microsoft and Google access tokens are encrypted before storage.
  • Signing out revokes your session on the server.
  • On the web, your session is kept in the browser's local storage. In the mobile app it is kept in the device's secure storage.

No system is perfectly secure. If you believe your account has been misused, tell your organisation's administrator or write to us.

9. How long we keep it

  • Your organisation's workspace data is kept for as long as the organisation uses the service.
  • App builds: only the newest five uploaded builds of each app are kept. Older ones are deleted automatically every night, unless a tester has been given access to them. The activity log about a build is kept after the build itself is gone.
  • Deleted chat messages: the text is removed and the attachments are deleted. A marker that a message existed remains in the conversation.
  • Deleted contacts are removed.
  • Logs — audit, secret-wallet, distribution and server logs — are kept so that activity can be accounted for.
  • Support requests are kept so that they can be followed up.
  • The database is backed up nightly.

10. Closing your account

You can ask for your account to be deleted from the support page without signing in, or ask your organisation's owner. We do not tell the person submitting the form whether an account exists for that address.

What happens, precisely.

  • Your account is closed: it can no longer sign in on the web or in the app.
  • It is not erased. The tasks, comments, messages, files and time entries you contributed are part of your organisation's records and stay in its workspace, still showing your name.

If you want to ask about your personal details beyond closing the account, write to umer.iftikhar@ideas.com.pk.

11. Your choices

  • You can change your name and photo, and your email and push-notification settings, in your profile. The phone number is edited in the mobile app.
  • You can turn off notifications, and deny camera, microphone or photo access, in your phone's settings. The features that need them will then not work.
  • Depending on where you live, you may have rights to access, correct or object to the use of your personal data. Because your organisation controls its workspace, many requests are best made to it first. You can always write to us as well.
  • The service is meant for work and is not directed at children.

12. Changes and contact

If what the service collects or does changes, we will update this page and the date at the top.

Contact: umer.iftikhar@ideas.com.pk, or the support page.