Legal

Privacy policy.

TaskBridge stores the minimum it needs to keep two systems honestly in sync, encrypts the credentials that make that possible, and deletes them the moment you disconnect.

Draft — pending operator approval This document describes the system truthfully but has not yet been reviewed or adopted by the operator. Items marked “operator decision” are unconfirmed. It is not yet in force.

Scope

This policy covers the hosted TaskBridge application at tasks.bvdm.ai and this website at taskbridge.bvdm.ai.

This website

This website is static. It sets no cookies, runs no analytics, embeds no third-party resources, and collects nothing.

Account data

  • Email address. Used to send single-use sign-in links and to enforce the invite allowlist. Sign-in links expire in 15 minutes.
  • Sessions. A session identifier in an HTTP-only cookie, valid up to 30 days. No advertising or analytics cookies are set by the application.

Provider data

  • OAuth tokens. Access tokens for your Linear and Todoist connections are stored only as AES-256-GCM ciphertext. Disconnecting a provider deletes the ciphertext immediately.
  • Work data. To keep bridges correct, TaskBridge stores bridge configuration, task links between Linear issues and Todoist tasks, their state history, discovery snapshots of your teams and projects, verified webhook deliveries, and reconciliation run records.
  • What is never collected. Your Todoist planned dates, reminders, priorities, ordering, personal labels, private comments, and personal subtasks are never read for decisions and never written. TaskBridge holds no advertising profiles and shares no data with third parties for marketing.

Deletion

  • Disconnecting a provider deletes the stored token ciphertext immediately.
  • Deleting a bridge removes its configuration and history from TaskBridge. It never deletes or edits anything in Linear or Todoist.
  • To have your account and its remaining records removed, contact the operator (see Support).

Operator decisions — not yet confirmed

Pending operator approval The following require the operator’s decision before this policy can be adopted:
  • Controller identity and contact address for privacy requests.
  • Retention periods for webhook deliveries, reconciliation runs, and logs (no automatic expiry is currently documented).
  • Hosting and email sub-processors (where the service and its outbound mail run).
  • Jurisdiction and the applicable legal basis (e.g., GDPR position for EU users).

Changes

Material changes to this policy will be published on this page with a revised date before they take effect.

Draft · not yet in force · last edited 2026-08-12