Privacy Policy
Last updated: September 2026
1. Who We Are (Data Controller)
fanTask is operated out of Romania, European Union. We are the data controller for personal data collected through the fanTask service (fantask.ro). For privacy matters, contact us at:
2. What Personal Data We Collect
We collect and process the following categories of data:
Account Information
Your name (or display name) and email address, collected when you create an account or contact us. Used to identify your account and communicate with you about the service.
Task and Project Data
Tasks, task descriptions, comments, assignees, status history, and other content you create within fanTask. This may include names of team members if you assign tasks to others. This data is content you explicitly input and is associated with your account and workspace.
AI Context Content
The persistent AI Context field you write for each project — typically architectural notes, coding conventions, and project constraints. This is content you intentionally author and store. It may indirectly contain personal data (e.g. a team member's name mentioned in a note).
Usage and Technical Data
Basic server logs including IP addresses, request timestamps, and MCP endpoint access patterns. These are collected automatically and used to monitor service health, debug issues, and detect abuse. We do not run third-party analytics scripts (e.g. Google Analytics) on this marketing site or in the product.
Billing Information
For paid subscriptions, billing is handled via Stripe. We receive limited billing metadata (e.g. last 4 digits of card, country, subscription status) but do not store full payment card details — these are held by Stripe, our payment processor. Stripe's privacy policy applies to payment processing.
3. Cookies and Session Storage
fanTask uses a small number of strictly necessary cookies for authentication. We do not use advertising cookies, tracking pixels, or analytics cookies.
| Cookie name | Purpose | Type |
|---|---|---|
ot_access_token | Authenticates your session with the fanTask API | Strictly necessary |
ot_refresh_token | Allows refreshing your session without re-logging in | Strictly necessary |
Because these cookies are strictly necessary for the service to function, we do not require separate consent for them under ePrivacy rules. You can delete them at any time by logging out or clearing your browser cookies, which will end your session.
This marketing website (fantask.ro) does not set any cookies beyond those used for navigation. No tracking or analytics cookies are used on the public-facing pages.
4. Infrastructure and Data Location
fanTask is hosted on infrastructure we operate directly — we run our own PostgreSQL database and PostgREST API stack rather than relying on a managed third-party SaaS data store. This means your task data, project data, and AI Context content are held in database instances that we control and are not shared with third-party analytics platforms.
Our servers are hosted within the European Union. Your data is stored and processed within the EU. If this changes, we will update this policy and notify affected users in advance.
Third-party processors we currently use (and their purposes):
- Stripe — payment processing (EU-hosted where available)
- Email provider (TBD) — transactional email delivery for account notifications
Note: This list will be updated before commercial launch to reflect the actual email provider used. A Data Processing Agreement (DPA) should be in place with each sub-processor.
5. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases:
- Contract performance — processing account information and service data is necessary to provide the service you signed up for (Art. 6(1)(b) GDPR).
- Legitimate interests — server logs and basic security monitoring to keep the service secure and functioning (Art. 6(1)(f) GDPR), balanced against your privacy interests.
- Legal obligation — retaining invoicing records to comply with Romanian and EU accounting/tax law (Art. 6(1)(c) GDPR).
6. Data Retention
We retain your data as follows:
- Active accounts: Data is retained for as long as your account is active or as needed to provide the service.
- After account closure: Your task and project data is retained for 90 days to allow you to export or migrate, after which it is permanently deleted.
- Server logs: Retained for up to 90 days for security and debugging purposes, then deleted.
- Billing records: Invoices and payment records are retained for the period required by Romanian and EU tax law (typically 5–10 years), as we have a legal obligation to do so.
7. Your Rights Under GDPR
As an EU resident, you have the following rights with respect to your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Right to data portability: Receive your data in a structured, machine-readable format (e.g. JSON export of your tasks and project data) so you can transfer it.
- Right to restriction of processing: Ask us to limit processing of your data in certain circumstances.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at hello@fantask.ro with the subject "Privacy Request". We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP) or your local EU data protection authority.
8. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include encrypted connections (HTTPS/TLS), authentication tokens with short expiry windows, and access controls on our infrastructure.
However, no system is completely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected users without undue delay.
9. Children's Privacy
fanTask is a professional tool intended for adults and software development teams. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email at least 14 days before they take effect. The current version will always be available at this URL with a "last updated" date. Continued use of the Service after the effective date of changes constitutes acceptance.