Privacy Policy
Updated: July 20, 2026
What data we collect
Your account email and name. Location data — only while a GPS session or timer is actively running; nothing is collected in the background outside an active session. Access tokens for your trackers (Redmine, Yandex Tracker, Bitrix24, and others) — to sync tasks and time.
How we use data
Data is used only to run the service — time tracking, routes, and syncing with your task tracker. We never sell your location, never share data with third parties, and never show ads.
How we store data
The cloud version runs on servers in Russia. All data is transmitted over a secure connection (TLS); tracker access tokens are stored encrypted on the server, and on-device in the Android Keystore.
Your rights
You can fully delete your account along with all data at any time — from your profile settings or by contacting support.
Self-hosted
If you self-host Taskloc, you are the data controller — data never leaves your infrastructure.
Cookies and local storage
The site sets three cookies, and every one of them is strictly necessary: nuxt-session keeps your sign-in session for 30 days and is not readable by page scripts (httpOnly); oauth_web_state lives for 10 minutes and protects tracker sign-in from a forged response (httpOnly as well); i18n_redirected stores the chosen interface language for about a year. There are no advertising or analytics cookies, we plug in no third-party counters, and fonts are served from our own servers — so we do not ask for separate cookie consent.
Your browser's local storage (localStorage) keeps: a cache of your profile, including email and name; a persistent browser identifier — a random number created at first sign-in (not a device fingerprint), sent to the server with requests so that your devices can be told apart in the session list; caches of the organization list, settings, and reference data; the address of your Redmine, so you do not have to type it again. Tab storage (sessionStorage) holds the identifier of an unfinished payment while you pay. All of it stays in your browser only and is removed when you clear the site data.
Interface errors are sent to GlitchTip — an error collector we run on our own server. It is enabled by an instance setting: if the setting is empty, no reports are sent at all. GlitchTip sets no cookies and leaves nothing in browser storage.
The only request to an outside service in the whole application is map tiles. If the organization picked the public map source (it is the default), the browser loads them straight from tile.openstreetmap.org, and OpenStreetMap sees your IP address and the address of the page the request came from. With our own tile source the map loads from our servers and nothing leaves them.
Contact
For questions about data processing, write to .