Privacy Policy

Last updated: April 17, 2026

1. Overview

Trillitask ("we", "us", "our") operates the trillitask.com website and related AI assistant service (the "Service"). This Privacy Policy explains what data we collect, how we use it, and the choices you have. By using Trillitask you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

To provide the Service, we collect:

  • Account information: name, email address, password (hashed), timezone, phone number (if you choose to verify one).
  • Content you provide: messages you send to your AI assistant, tasks and reminders you create, notes and facts you ask us to remember ("memories"), calendar events you schedule.
  • Email data (optional): if you connect email accounts for scanning, we store encrypted credentials and the content of emails received while the service is active, for the purpose of prioritization and task extraction.
  • Usage data: session logs, feature usage, AI token consumption, error logs for debugging.
  • Billing information: handled by Stripe; we do not store credit card numbers on our servers.
  • Phone number (SMS): if you opt in to SMS features, we store your verified phone number and use it only for service delivery.

3. How We Use Your Information

  • Operate the Service and provide AI assistant features.
  • Generate daily briefings, process email scanning, extract tasks and reminders.
  • Send transactional notifications you've opted into (email, SMS, in-app).
  • Process payments via Stripe and manage your subscription.
  • Verify phone ownership via one-time SMS codes.
  • Diagnose errors, prevent abuse, and improve the Service.
  • Comply with legal obligations.

4. Third-Party Services

Trillitask shares limited data with the following service providers, strictly for the purpose of providing the Service:

  • OpenAI — your messages, extracted email content, and memory queries are sent to OpenAI's API to generate responses. OpenAI's data usage policy applies. We do not use your data to train models.
  • Telnyx — phone numbers and SMS content are transmitted via Telnyx for delivery.
  • Stripe — billing information is handled entirely by Stripe.
  • Email providers (IMAP/SMTP) — if you connect email accounts, we connect directly to your provider using your stored credentials.

We do not sell, rent, or share your personal information with third parties for marketing purposes. Your phone number and SMS content are never shared with third parties for marketing.

5. SMS Messaging

If you opt in to SMS by verifying your phone number, you consent to receive text messages from Trillitask for:

  • Account verification codes
  • Task reminders, deadline alerts, and daily briefings based on your notification preferences
  • Two-way conversational messaging with your AI assistant

Message frequency varies based on your activity and preferences. Message and data rates may apply. You can opt out at any time by replying STOP to any message, or by removing your phone number from the Settings page. Reply HELP for support. We do not share your phone number with third parties for marketing purposes.

6. Data Security

We use industry-standard security practices:

  • Passwords are hashed using bcrypt.
  • Email account credentials are encrypted at rest using AES-256-CBC.
  • All web traffic uses HTTPS/TLS.
  • Tenant data is strictly isolated at the database level.
  • Sessions use secure, HTTP-only cookies.

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

7. Data Retention

We retain your account data as long as your account is active. You can delete individual memories, conversations, and tasks at any time from within the Service. When you delete your account, all personal data is removed within 30 days, except where we are required to retain it for legal or accounting purposes.

8. Your Rights

You have the right to:

  • Access and export your personal data
  • Correct inaccurate information
  • Delete your account and associated data
  • Opt out of SMS and email notifications at any time
  • Object to the processing of your personal data

To exercise these rights, email privacy@trillitask.com.

9. Children's Privacy

Trillitask is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will remove it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this policy? Email privacy@trillitask.com.