Privacy Policy
Last updated: 1 January 2026
Template text — have your own counsel review before relying on it.
This policy explains what CazoTask does with your information. CazoTask runs automations on your behalf, which means we necessarily touch the content inside your connected accounts — emails, calendar entries, documents, messages. We have tried to write this in plain English rather than the usual fog, because you should be able to tell exactly what happens before you connect anything.
Who we are
CazoTask is the controller of the personal data described here. We operate in the United Kingdom and the United States and process data under the UK GDPR, the EU GDPR where it applies, and applicable US state privacy laws including the CCPA/CPRA. You can reach our privacy team at privacy@cazotask.com.
What we collect
- Account data. Your email address, authentication identifiers, plan and billing status. Card details are handled by Stripe; we never see or store a full card number.
- Connection data. When you connect Gmail, Slack, Notion, HubSpot or any other tool, we store OAuth access and refresh tokens plus the scopes you granted and the account identifier the provider gives us.
- Content processed by automations. The material an automation needs to do its job — the body of an email it is triaging, the transcript it is summarising, the invoice line items it is chasing — along with the output it produced.
- Run logs. Timestamps, which automation ran, whether it succeeded, what action it took, and any errors. Logs include short excerpts of content so you can audit what happened.
- Product and device data. IP address, browser and device type, pages viewed and features used, for security and to work out what to build next.
How we use it
We use your data to run the automations you switch on, to show you what happened and how much time it saved, to keep your account secure, to bill you, and to provide support. We also use aggregated, de-identified statistics — how many runs the platform handled, which automations are popular — to improve the product. We do not sell personal data, and we do not share it with advertising networks.
Connected accounts and tokens
Every connection uses OAuth, so you authorise us at the provider and can withdraw that authorisation at any time from their settings or ours. We request the narrowest scopes the automation you selected actually needs, and we show you each scope in plain English before you approve it. Access and refresh tokens are encrypted at rest using envelope encryption with keys held in a managed key service, separate from the application database. Tokens are decrypted only in memory, only for the duration of a run.
AI processing
Automations that draft, classify or summarise send the relevant content to a third-party AI provider over an encrypted connection. We use those providers under enterprise or API terms that prohibit training on data submitted through the API and require deletion after a short retention window used only for abuse monitoring. Your content is never used to train our models or any public model, and we do not use one customer's data to improve another customer's results. We send the minimum content the step requires rather than the whole mailbox.
Legal bases
Where the UK or EU GDPR applies, we rely on: performance of a contract, to deliver the service you signed up for; legitimate interests, for security, fraud prevention and product improvement; consent, for optional marketing email and for the specific scopes you grant at connection time; and legal obligation, for tax and accounting records.
Who we share with
We use a small set of processors: a cloud hosting and database provider, an AI model provider, Stripe for payments, an email delivery service, and error and analytics tooling. Each is bound by a data processing agreement and standard contractual clauses where data moves internationally. We will disclose data if legally compelled, and we will tell you unless we are prohibited from doing so.
How long we keep it
Account data is kept while your account is open. Run logs and processed content are retained for 90 days by default so you can audit what an automation did, then deleted automatically; paid plans can shorten this. Backups roll off within 35 days. Invoices and tax records are kept for six years because we are required to.
Deleting your data
You are in control of this and you do not need to email anyone to exercise it.
- Disconnect a tool. Open Settings → Connections and revoke it. The stored tokens are destroyed immediately and any automation depending on that tool is paused.
- Delete run history. From the same screen you can clear logs and processed content for a single automation or for everything, at any time.
- Delete your account. Settings → Account → Delete account removes your profile, connections, automations, logs and processed content from live systems within 24 hours, and from encrypted backups within 35 days. This is a real deletion, not a hidden flag, and it cannot be undone.
You can also export everything as JSON before you go. If you would rather we did it for you, email privacy@cazotask.com from your account address and we will action it within 30 days.
Your rights
Depending on where you live, you have the right to access, correct, delete, port and restrict processing of your data, to object to processing based on legitimate interests, and to withdraw consent. US state residents may also opt out of sale or sharing — we do neither, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights. If you are unhappy with our response, UK residents may complain to the Information Commissioner's Office.
Children
CazoTask is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children, and we delete it if we discover we have.
Changes
If we make a material change we will email you at least 30 days before it takes effect. The date at the top of this page always reflects the current version.