Privacy Policy
Effective September 16, 2026
task pup is a daily planner with an optional Google Calendar connection. This policy explains how Yashaswi Sunkara (“we” or “us”) handles information when you use task pup on this site.
Information we collect and use
- Your account: a username, a salted password hash, and session records so you can sign in. We do not store your password in plain text or require an email address to register.
- Your planner: tasks, dates, durations, groups, scheduled times, completion history, and dog preferences and care activity, your task group color preferences, and your automatic task carryover setting. We use these to save your plans and provide the planner and virtual dog features.
- Browser and service information: your browser sends the selected date and local time zone to load calendar events. We use IP-based sign-in limits to prevent abuse. Hosting providers may process IP addresses, browser details, request timestamps, and operational logs to deliver and secure the service.
- Support: if you email us, we receive your email address and the information you choose to include to respond to your request.
Google Calendar access
Connecting Google Calendar is optional. With your permission, task pup reads events from your primary calendar for the day you view. We use event titles, start and end times, all-day and busy/free status, event identifiers, and links to display events and arrange automatic tasks around busy times. We check cancellation and your attendance response to exclude cancelled or declined events. We request only the event fields needed for this display and scheduling, including your attendance response. We do not request event descriptions, locations, or attendee contact details.
The Google permission allows reading calendar events; the current integration only queries your primary calendar. task pup cannot create, edit, or delete Google events. You authorize access on Google's website, and we never receive your Google password.
Google access and refresh tokens are encrypted in our server database and associated with your planner account. They let the app refresh your calendar connection without asking you to sign in to Google each time. Google tokens are not sent to your browser.
How information is shared
Cloudflare processes account and planner data, encrypted Google credentials, and calendar requests as our backend and database provider. Our website hosting provider, Vercel, serves the public pages and may process ordinary web request information. Google processes requests when you authorize, refresh, or revoke calendar access. We use these services to operate task pup.
We do not sell personal information or use Google user data for advertising, credit decisions, or training general-purpose AI models. We do not share Google data with unrelated apps. Any transfer of Google data is limited to providing the features you authorize, security needs, or legal obligations as permitted by Google's policies. Humans do not read Google user data unless you explicitly authorize access to specific data for support, or access is necessary for security or legal compliance.
task pup's handling and transfer of Google API data complies with the Google API Services User Data Policy and the Google Workspace API policy, including their Limited Use requirements.
Storage, retention, and security
Account information, saved plans, and dog data remain in our database until deleted. Google event content is processed temporarily on the server and held in browser memory for display; it is not saved to our database. A failed refresh may leave the last successful events visible until you change days, disconnect, log out, or close the page.
Your browser's local storage holds your task pup sign-in token. Sessions expire after 30 days and are revoked when you log out. Temporary tab storage may keep an unfinished task while you connect Google. You can clear browser storage in your browser settings; doing so does not delete your server account. task pup does not include advertising or analytics scripts.
We use HTTPS, hashed account passwords and session tokens, and encrypted Google credentials. No storage or transmission method is completely secure. Hosting providers may retain operational logs or backup copies according to their retention processes; these copies may not disappear immediately when active data is deleted.
Disconnecting and deleting your data
In task pup, open Account → Disconnect to remove stored Google credentials and pending connection records from the active database and clear displayed events in that tab. We also attempt to revoke Google's authorization. You can independently remove task pup's access in your Google Account connections. Logging out alone does not disconnect Google or delete saved plans.
You can edit or delete individual tasks in the planner. To request access to or deletion of your account, saved plans, dog data, or other personal information, email bgn2bs@virginia.edu with your username and request. We may need to verify account ownership before acting. Never send your password or Google credentials. There is currently no self-service account deletion or password recovery. Information needed to meet legal obligations or investigate abuse may be retained for those purposes.
Changes and contact
We will update this page and its effective date when this policy changes. If we introduce materially different uses of Google data, we will provide notice and obtain any required consent before that use.
For privacy questions or requests, contact Yashaswi Sunkara at bgn2bs@virginia.edu.