Intended public publisher: Amrita Singh. Publisher identity verification is pending.
Your workspace & your information
Privacy policy
Last updated
TaskVegas connects your workspace, selected services, and AI tools. This page explains the information involved in those connections and the current limits on retention and deletion.
Workspace and sign-in information
TaskVegas stores your workspace name and ID, its settings, provider connection metadata, saved redirects, and records needed for sessions and authorized AI access. Hashed recovery keys and sign-in records let you return to the same workspace.
Website actions use your workspace session and CSRF protection. AI clients use OAuth grants with approved scopes, tool identities and authorization contracts. TaskVegas stores the client, authorization and token records needed to enforce those permissions; searching the catalog does not grant access.
Account sign-in uses Auth0 and an enabled identity provider, such as Google. TaskVegas requests the openid sign-in scope and stores a hashed binding of the provider's issuer and account subject, the sign-in method, and its workspace association. It does not store your login-provider access or refresh tokens, email address, phone number, name, or profile as account profile data.
Auth0 and Google may process information such as your email address, name, and profile to authenticate you. Their handling of that information is covered by their own policies. If you enter personal information in a workspace name, redirect, or tool request, that information is handled as described below.
Essential cookies
TaskVegas uses an essential workspace session cookie with a seven-day lifetime and a separate account sign-in flow cookie with a ten-minute lifetime. These support authentication and protect the connection between your browser and a sign-in attempt. Expiry limits their use; it does not guarantee immediate deletion of the corresponding stored records.
The TaskVegas site has no advertising or analytics SDK. The main app loads fonts from Google Fonts, which involves requests from your browser to Google's font services. These support and policy preview pages use system fonts and load no third-party assets.
Provider connections and AI requests
When you connect a service using your own key or credential, TaskVegas stores the secret in Azure Key Vault and stores connection settings and metadata with your workspace. TaskVegas uses those credentials to make the requests you authorize.
Tool requests send selected inputs to the relevant connected provider. Results are returned to the requesting AI host or client, such as ChatGPT or Claude. Inputs or results can include personal information, documents, URLs, or other content you choose to use. Review what you send and the policies of your provider and AI host; their storage and use of that content are separate from TaskVegas.
TaskVegas runs on Microsoft Azure and uses Azure storage and Key Vault to operate the service. Auth0 handles account authentication. These services process the information needed to provide their functions.
Optional provider referral links
Provider setup may show an optional referral link alongside the ordinary provider website link. TaskVegas may earn a commission on qualifying signups or purchases through an approved referral; the link includes a commission disclosure. You can use the ordinary provider link or your existing account.
TaskVegas does not add affiliate tracking cookies, pixels, a tracking SDK, click receipts or visitor-specific referral identifiers. It does not add workspace IDs, credentials, search prompts or account information to these links. Opening either link sends your browser to the selected provider, which receives the usual network request information and may use its own cookies and attribution under its own policies. TaskVegas website setup links suppress the browser referrer; your AI host controls its own handling of links returned through MCP.
Hosted guidance and discovery
Enabled design tools process your brief using a pinned bundled design engine within resource and usage limits. The engine does not make network requests or write project files. TaskVegas returns the guidance to your requesting AI host or browser and does not save the brief or generated result in its activity history. Operation metadata and usage counters are retained as described below.
The public catalog includes bounded metadata and source links from public repositories, the official MCP Registry, news and selected blog feeds. Candidates are review leads until an adapter is reviewed and released. Sharing a public link saves that URL, an optional repository URL and review metadata in a private workspace-bound receipt; it does not fetch, install or execute the linked project.
Link-submission receipts have a 30-day logical expiry, after which application access is denied, and production periodically attempts to remove expired receipts. This periodic cleanup can fail or be delayed; expiry is not a guarantee of instant physical erasure. Do not submit credentials, private links or sensitive personal information.
Shared redirects
TaskVegas persists redirect titles, short links, destination URLs, and related workspace settings. The public redirect preview exposes the title and destination URL to anyone who opens that link. Do not put credentials or private information in a destination URL you share. Following the redirect sends your browser to the destination service, which has its own privacy practices.
Activity and abuse prevention
TaskVegas keeps activity metadata such as the tool and provider used, time, and outcome. Some provider job IDs are also retained to support follow-up requests. Request hashes and related operation IDs are stored to help prevent duplicate write actions. The activity history is limited to the latest 50 entries and a 24-hour logical window, with cleanup occurring when the data is accessed or updated.
Usage counters and hashed IP-based abuse counters help enforce limits and protect the service. Hashing an IP address does not make it anonymous. Your IP address is also processed as part of the network requests needed to operate the service.
Retention and deletion limits
Workspace information and saved settings remain stored until removed through available controls or an operator process. Some session, authentication, authorization, activity, and usage records become invalid or fall outside their active window before they are physically removed. Discovery-link receipts have periodic cleanup after their logical expiry; TaskVegas does not run a scheduled physical purge of all other expired records, so some expired authentication and workspace records may remain in storage.
Disconnecting a provider removes its active connection and requests deletion of its stored credential. Azure Key Vault soft deletion retains a deleted secret for the vault's configured recovery period. This is not immediate permanent erasure. Disconnecting does not cancel jobs already submitted to the provider and does not erase information already sent to that provider or an AI host.
TaskVegas does not currently provide a self-service control to delete a complete workspace or account. The planned contact channel for access, correction or deletion requests is awaiting activation, so it cannot currently receive requests. Once available, requests will need an ownership check and a review of what can be removed; this draft does not promise immediate or automatic deletion.
Your choices and contact
You can manage saved redirects, disconnect providers, revoke AI access, and sign out using the available workspace controls. Keep your recovery key private: it provides access to your workspace.
The planned address for privacy questions or requests is help@taskvegas.si. This mailbox is not active yet; requests sent there cannot currently be received. See the support page for its activation status. Do not email provider keys, recovery keys, passwords, or verification codes.
This page may be updated as the pilot changes. The date above identifies the latest revision. See the terms of use for pilot usage expectations.