← Back to NeroTask

Privacy Policy

Effective July 22, 2026

NeroTask (nerotask.com) is a local-first task manager. This policy explains what data the app uses and when it leaves your device.

Local storage (default)

When you use NeroTask without signing in, your tasks, projects, tags, notes, and attachments are stored on your device (IndexedDB in the web app or the NeroTask iOS app). That data stays on your device. We do not receive your task content in this mode.

Optional cloud sync

If you choose to sign in and subscribe to sync, your task library is stored in our cloud database and storage (Supabase) so it can sync across your devices. This can include tasks, lists, tags, contexts, notes, recurrence data, attachments, app preferences, sync status, and related metadata. Sync is optional and not required to use the app locally.

Calendar, reminders, and notifications

Google Calendar overlay is optional. If you connect Google Calendar in Settings, NeroTask requests read-only access to your calendar list and the events in calendars you choose to display. We store an encrypted OAuth refresh token in Supabase and use it to fetch calendar information through our server when a NeroTask calendar surface needs it. Event ranges may be cached on your device so the overlay loads quickly, but they are not imported as Nero tasks, included in cloud task sync or backups, or used to write changes back to Google Calendar.

We use Google Calendar information only to provide the calendar overlay you requested. We do not sell it, use it for advertising, or use it to train generalized artificial-intelligence or machine-learning models. We do not transfer it to third parties except the infrastructure providers needed to operate the integration as described in this policy. Disconnecting Google Calendar in Settings revokes the Google token when possible, deletes the stored connection and token, and clears the device's cached Google Calendar events.

NeroTask's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In the NeroTask iOS app, Apple Calendar access is handled on device through Apple's EventKit permission. Apple Calendar events stay on your device and are not sent to our servers.

Apple Reminders import is optional. In local iOS mode, reminders are read on device and staged locally for import. If you are signed in and use cloud reminders sync, reminder titles, notes, due dates, reminder identifiers, and handled/delete status may be stored in Supabase so your Inbox triage state can sync across signed-in devices.

Task due-date reminders are optional. On iOS, local notifications are scheduled on device. On the web/PWA, enabling push reminders stores a browser push subscription endpoint and keys in Supabase so reminders can be delivered. You can disable reminders in Settings or revoke notification permission in your browser or iOS Settings.

Support messages

If you use Contact support in Settings, we receive the email address and message you submit, plus basic diagnostic details you choose to include (for example browser and sync status).

Analytics and error monitoring

We use Vercel Analytics and Vercel Speed Insights on the production site. These services collect aggregated usage and performance metrics, not your task content.

We also use Sentry to collect client error reports when the app crashes or throws an unexpected error. Reports may include browser type, app version, and a pseudonymous account id if you are signed in. Sentry is configured not to send default personal information, and NeroTask scrubs common sensitive fields such as emails, tokens, task titles, notes, filenames, and backup data before sending reports. Error reports are not intended to include your task content.

Third-party services

We use service providers only to operate NeroTask: Supabase for authentication, database, storage, realtime, and edge functions; Stripe for web billing; Apple for iOS in-app purchases and platform permissions; Google for Google sign-in and optional Google Calendar access; Vercel for hosting, analytics, and performance insights; and Sentry for error monitoring. We expect these providers to protect user data consistently with this policy and their own privacy and security obligations.

What we do not do

Data retention

Local data remains until you delete the app, clear local data in Settings, or remove it from the app. On the web, clearing browser storage also removes local data. Cloud account data remains until you close your account. Local-only profiles can be deleted from Settings → About → Danger zone. When signed in, closing your account from the same screen deletes the Supabase auth account, associated cloud application data, and data for that account on the current device. Local copies on other devices are not removed automatically. Stripe or Apple may retain purchase, tax, fraud-prevention, and transaction records according to their own legal obligations and policies.

Support messages and diagnostic/error records are retained only as long as reasonably needed for support, security, debugging, business records, and legal compliance.

Your choices

You can use NeroTask locally without an account, save a backup, disconnect Google Calendar, disable reminders, revoke Apple Calendar or Apple Reminders access in iOS Settings, clear local profile data, or close your account from Settings. You can also contact us to ask about access, correction, deletion, or other privacy requests.

Legal

See our Terms of Service for subscription billing, cancellation, and refunds.

Contact

Questions about this policy? Contact support in NeroTask Settings (opens the in-app form), or email support@nerotask.com.