Privacy Policy
Last updated: August 19, 2026
1. Overview and Scope
This Privacy Policy explains how Taklet handles information when you use the Taklet website, web application, iPhone application, or Mac application, together called the "Service." Taklet is a team productivity product used to coordinate people, organizations, projects, and work.
This Policy describes the current product behavior found in those applications. Some features are available only on certain platforms or to users with particular roles.
2. Information You and Other Users Provide
Taklet handles information that you or another authorized user enters, including:
- Account and profile information: name, email address, authentication information, user identifier, organization, role, account status, time zone, avatar, and notification preferences. If you do not upload a profile image, the web application uses your email address, encoded as a URL seed, or your user identifier to request a default avatar from DiceBear.
- Organization and membership information: organization names, membership, roles, managers, project access, invitations, invitation links, and relationships with external collaborators.
- Workspace content: projects, tasks, subtasks, descriptions, notes, priorities, due dates, assignments, recurrence, pipeline placement, comments, status updates, reactions, check ins, trackers, calendar items, project notes, links, and related collaboration history.
- Files and images: task attachments, file names, file types, file sizes, upload details, profile images, and project images.
- Communications: contact form entries, support messages, feedback, reports, and other messages sent to Taklet.
An organization manager or another authorized user may provide information about you, invite you, assign work to you, add you to a project, or include your name in workspace content.
3. Information Created or Collected During Use
Use of the Service can create or collect the following information:
- Session and request information: login state, session tokens, IP address, browser or app information, request details, timestamps, and security or reliability logs handled by Taklet and its providers. A DiceBear default avatar request also sends the email address or user identifier placed in its request URL, together with ordinary request metadata.
- Product records: activity entries about certain workspace changes, notification records, read state, comment or update view times, and settings used to coordinate the product. Activity entries support collaboration and are not a complete audit record of every action on every platform.
- Push notification information: when the iPhone app registers for notifications, Taklet stores an Apple push token with the user identifier, platform, app identifier, app version, device name, environment, and update times.
- Diagnostics: the iPhone and Mac applications create operating system logs used for troubleshooting. Current log paths can include account or workspace identifiers, counts, names, link addresses, search text, dates, and error details. These logs stay on the device unless you or the device platform makes them available to Taklet or another recipient. The current native application code does not include a dedicated remote crash reporting service or Google Analytics.
4. Web Analytics
Taklet loads Google Analytics for audience and usage measurement from the root web layout, so the tag is present on public pages and signed in application routes. Google Analytics receives the complete page address as page location, along with page and session information, browser and device details, referral information, network information, and approximate location derived from network information. Depending on the route, the complete page address can contain a project name slug, a task identifier in the task query parameter, or an invitation code in a join address. Google Analytics can set first party cookies such as _ga and related cookies to distinguish visits and sessions.
The current web application loads Google Analytics without an in product analytics consent control. It does not change its behavior in response to browser Do Not Track or Global Privacy Control signals. You can use browser controls or content blocking tools to limit or delete analytics cookies. Taklet does not display third party advertising in the Service.
5. Cookies and Storage on Your Device
- The web application uses cookies for Supabase authentication and sessions. It also uses browser storage for interface preferences, panel state, ordering, and indicators showing what a user has already seen.
- Google Analytics can use first party cookies as described above.
- The iPhone and Mac applications store authentication sessions in the device keychain and store application preferences on the device.
- The Mac application keeps an encrypted application support cache containing selected workspace information so the application can open with recent data. Its encryption key is stored in the keychain, and the application removes that cache when the user signs out.
6. How Taklet Uses Information
Taklet uses information to:
- Authenticate users and maintain account sessions.
- Operate organizations, memberships, projects, tasks, and collaboration features.
- Apply roles, project membership, external access, and user preferences.
- Store, synchronize, and display content to authorized users.
- Send invitations, account messages, reminders, and other requested notifications.
- Notify Taklet operators about new account creation and handle account, contact, and support messages.
- Measure web use and understand how web pages are reached and used.
- Respond to contact and support messages.
- Protect accounts, investigate errors or misuse, and maintain reliability.
- Meet legal obligations and enforce the Terms of Service.
7. Collaboration and Visibility
Taklet is designed for shared work. Your name, profile image, organization, role, assignments, workspace content, activity, and read state can be visible to organization members, project members, managers, or external collaborators who have access to the relevant organization, project, or task.
External collaborators may belong to a different organization while receiving access to a shared project. Their organization may also manage their account or membership. Workspace managers can change roles, invitations, project membership, and access. If access changes, a user may lose access to content that the user originally created.
8. Files, Images, and Links
Task attachments are stored in private storage and delivered through temporary access links for authorized users. Uploaded profile and project images are served from publicly readable storage, which means anyone who obtains the image address can retrieve the image. Do not use an uploaded profile or project image for sensitive material.
If you do not upload a profile image, the web application requests an automatically generated default avatar from DiceBear. The request URL includes your email address, encoded as the avatar seed, or your user identifier when an email address is unavailable. DiceBear also receives ordinary request metadata when your browser loads that image.
Public marketing previews on the website load portrait images from Pravatar. The current image addresses use fixed demonstration image number tokens rather than account or workspace values. When your browser loads one of those images, Pravatar receives the requested image address and token together with ordinary request metadata.
When a user asks Taklet to identify the title of a web link, the Taklet server contacts that address and reads a limited part of the returned page. The destination site can receive ordinary request information from that contact, such as network and request details.
The native applications access files only after a user chooses a file through a system file picker for an available upload or image feature. The iPhone app separately asks for notification permission when push notifications are enabled.
9. Providers and Other Recipients
Taklet uses the following services for current product functions:
- Supabase for authentication, database, real time synchronization, file storage, and the public Mac release feed and downloads.
- Netlify for web hosting and web request handling.
- Resend to deliver account, invitation, notification, reminder, contact, and support email.
- Apple Push Notification service to deliver enabled iPhone push notifications.
- Google Analytics for web audience and usage measurement, including complete page addresses on public pages and signed in application routes as described in Web Analytics.
- DiceBear to generate a default profile avatar when you have not uploaded one. Its request URL can include your email address, encoded as the avatar seed, or your user identifier, together with ordinary request metadata.
- Pravatar to supply fixed portrait images used in public marketing previews. It receives the requested image address and fixed image number token together with ordinary request metadata.
These providers receive information needed to perform their functions. Taklet may also disclose information when required by law, to protect rights or safety, to investigate misuse, or as part of a financing, acquisition, reorganization, or transfer of the Service. A successor may receive information subject to applicable law and the privacy notice in effect for its processing.
10. Email and Notification Choices
Taklet can send email and in app notifications about accounts, invitations, assignments, tasks, projects, status updates, calendar items, due dates, trackers, and reminders. When browser permission is granted, the web application can display a browser notification after a new in app notification arrives while the Taklet tab is not visible. The iPhone app can also send push notifications through Apple when permission is granted. The current Mac application does not register for push notifications.
Email, browser, and push content can include the names and details of relevant people, organizations, projects, tasks, updates, calendar items, or trackers.
Available notification preferences can be changed in Taklet settings. Browser notification permission can be changed in browser settings, and iPhone push permission can be changed in system settings. Messages needed for account access, security, legal notice, or operation of the Service may not have an optional setting.
11. Mac Downloads and Updates
The Mac application is distributed as a direct download. It uses Sparkle to check a public Taklet update feed for signed application updates. Automatic update checks are enabled in the application configuration. Visiting the download route, checking the feed, or downloading an update sends ordinary request information to the hosting and storage providers, such as IP address, request time, and software or device request details.
12. Retention
Retention depends on the type of information, whether an account or organization is active, the needs of shared collaboration, security and support needs, provider backup cycles, and legal obligations. Shared workspace records may need to remain available to other authorized members after one member leaves.
Technical logs, email delivery records, deleted records, and provider backups can follow different retention cycles. Taklet does not state a single retention period for every category in this Policy.
13. Account Deletion and Data Copies
The iPhone and Mac applications provide an account deletion request in profile settings. The web application does not currently provide a self service account deletion or data export control. You can contact team@taklet.com for deletion help or to request access to or a copy of your information.
The result of a deletion request depends on the record and the rights of other workspace members. Shared content, collaboration history, security records, provider backups, and records that must be kept for legal reasons may remain after an account request. Contact Taklet if you need confirmation about the scope or status of a request.
14. Privacy Choices and Rights
Depending on where you live and how Taklet is used, applicable law may give you rights to know about, access, correct, delete, restrict, object to, or receive a copy of certain personal information, or to withdraw consent where consent applies. You may also have a right to complain to a privacy authority.
Send a request to team@taklet.com. Taklet may ask for information needed to verify your identity, authority, account, and relationship to the relevant organization. An organization may need to handle a request about content it controls, and Taklet may assist that organization.
15. Security
Taklet uses technical and organizational measures intended to protect information. The Service uses account controls, role and project access rules, encrypted network connections, private storage for task attachments, device keychain storage for native sessions, and an encrypted Mac workspace cache. No service, device, database, or transmission method can be guaranteed to be completely secure.
16. Children
Taklet is designed for business and team collaboration and is not directed to children. If you believe a child provided personal information without appropriate permission, contact Taklet so the situation can be reviewed.
17. Processing Across Locations
Taklet and its providers may process information in the locations where they operate or provide infrastructure. Privacy rules and transfer requirements vary by location. You can contact Taklet with a question about processing that applies to your use of the Service.
18. Changes to This Policy
Taklet may update this Policy as the Service changes. The date above will identify the current version. If applicable law requires another form of notice or consent for a change, Taklet will use that process before the change applies to the affected processing.
19. Contact
Taklet is the name used for the Service in this Policy. Privacy questions and requests can be sent to team@taklet.com.