Skip to content

NeoKaam Privacy Policy

Last updated: August 27, 2026

This policy explains what data NeoKaam holds about you, why we hold it, who else touches it, and how long we keep it. It covers the website, the web app, and the iOS and Android apps. We have tried to write it plainly and to state real numbers rather than "as long as necessary".

NeoKaam is published by Sumit Sourabh and is also distributed under the name Tickbox; the same service, the same account, and this same policy cover both, on the web and in the iOS and Android apps.

NeoKaam is built and operated by a very small team. Where a legal instrument that larger vendors offer does not exist yet, we say so on this page rather than implying otherwise.

1. Who we are

NeoKaam is a task and project management service published by Sumit Sourabh, operated from India and serving users worldwide. For anything to do with your data — questions, requests, or complaints — write to [email protected]. That address reaches the person responsible for privacy at NeoKaam. We have not appointed a formal Data Protection Officer; we are not currently required to.

For data you put into NeoKaam as part of your work — tasks, projects, comments, files — you (or your employer or school, if they set up the workspace) decide what goes in and why. We process it to run the service on your behalf.

2. What we collect

These are the actual categories of data stored in our database.

Account and identity

  • Name, email address, username, and a password hash (bcrypt — never the password).
  • An optional profile picture, stored on our own server and served from our domain — not uploaded to a third party.
  • Your interface language (English or Hindi) and email-preference flags.
  • If you sign in with Google or Apple: the identifier, name, email and profile picture those providers return, plus the OAuth tokens needed to keep the connection working.

Content you create

  • Tasks, subtasks, projects, sections, labels, recurring-task templates, saved filters, comments, and direct messages to other members.
  • File attachments, if your workspace has attachments enabled. They are stored in a private bucket and only ever served through short-lived signed links.
  • Activity history — who changed what on a task and when — which is visible to the other members of that project.
  • Support requests and in-app feedback you send us.

Security and technical records

  • Login history: the time, method (password, Google, Apple, mobile app), IP address and browser user-agent of each successful sign-in. We keep this so you and we can spot account takeover.
  • Security audit log: a record of security-relevant actions — adding or removing project members, issuing invite and share links, billing changes, linking WhatsApp, requesting an export or a deletion — with the time, IP address and user-agent.
  • Device push tokens for the mobile apps, so we can deliver notifications.
  • Server logs and error reports generated while serving your requests.
  • Session cookies — see section 8.

Optional integrations, only if you turn them on

  • Google Calendar: we write your task deadlines into your calendar and store the resulting event IDs. We ask Google only for the calendar-events permission (calendar.events) — enough to create and update the events we make, not to manage your calendars or your account. You can disconnect it in the app at any time, which revokes our access.
  • WhatsApp task import: if you link your number, we store that phone number and the messages, photos, voice notes or small spreadsheets you forward to our bot, so we can turn them into tasks.
  • AI task import: the spreadsheet, text, photo or voice note you submit is sent to an AI provider to extract a task list. See section 5.

Billing

  • Subscription state, plan, source (card, Google Play, App Store), and the payment provider's customer and subscription identifiers.
  • We never see or store your card number. Card details go directly to Stripe, Razorpay, Apple or Google.
  • Counters recording when you hit a plan limit, used to understand which limits bite.

What we do not collect: we run no analytics, advertising, session-replay or cross-site tracking of any kind. There is no Google Analytics, no advertising pixel and no third-party tracker in the web app or the mobile apps. Web fonts are served from our own domain, not from a font CDN. We do not sell personal data, and we do not share it for behavioural advertising.

3. Why we use it, and our legal basis

If you are in the UK or EEA, the "legal basis" column is our basis under the GDPR. If you are in India, the equivalent under the DPDP Act is your consent or a legitimate use such as performing a service you asked for.

What we doWhyLegal basis (GDPR)
Run your account, store and sync your tasksIt is the service you signed up forPerformance of a contract
Send verification, password-reset, invitation and reminder emails and push notificationsYou cannot use the account without themPerformance of a contract
Keep login history and a security audit log, and rate-limit sensitive endpointsDetect and stop account takeover and abuseLegitimate interests (security)
Record and report application errorsFind and fix faults before they cost you dataLegitimate interests (service reliability)
Answer your support requestsYou asked us somethingLegitimate interests / contract
Calendar sync, WhatsApp import, AI importOptional features you switched onConsent (withdrawable at any time)
Product-announcement emailsTelling you what changedConsent — one click to opt out, and we honour it
Take payment and keep subscription recordsBilling and tax recordsContract and legal obligation

4. How long we keep it

These are the retention windows actually enforced by our scheduled jobs, not aspirations.

DataKept for
Your account and everything in itFor as long as your account exists. Deleting your account starts the clock below.
Deleted accounts30 days from the moment you request deletion, then permanently and irreversibly erased by an automated job — including projects you own, your tasks, comments, messages, activity history and login records. The one exception is the security audit log described below, which is kept as evidence of who did what. The 30 days exist so an accidental or coerced deletion can be reversed, and so co-workers are not cut off from a shared project without warning.
Login history (IP address, user-agent)90 days, then automatically deleted.
Security audit log (the action taken, IP address, user-agent)400 days, then automatically deleted. It is deliberately not erased when an account is deleted: a record of a deletion request that vanishes with the account proves nothing. It holds identifiers, never names, email addresses or phone numbers.
Plan-limit and billing event records180 days, then automatically deleted.
AI import jobs (the file, photo, voice note or message you submitted and the rows extracted from it)A job left un-confirmed for 24 hours is treated as abandoned and its content is discarded. All import job records are purged after 30 days.
Attachment filesDeleted with the task they belong to. Half-finished uploads are removed after 24 hours; a reconciliation job sweeps up any orphaned object.
Unverified sign-upsIf you register but never verify your email, we warn you, then delete the account — after roughly 24 hours if it holds nothing, or after 7 days if you had created tasks.
Email verification links24 hours. Password reset links: 1 hour. Project invitations: 7 days. Shared invite links: 72 hours.
Mobile sign-in refresh tokens30 days, then you sign in again.
Orphaned profile picturesRemoved by a cleanup job once no account references them.
Email you send to our support addressStored so we can answer you; we do not currently run an automatic expiry on it. Ask us and we will delete a specific thread.
Database backupsBackups are held on three independent rotations; the longest-lived slot is about one year. Deleting your account removes you from the live database at the end of the grace window, but a backup taken before then may still contain your data until that backup rotates out.

Where the law requires us to keep something longer — for example financial records — we keep only that record, for only that long.

5. Who else processes your data (subprocessors)

These are the third parties that store, process or transit your data on our behalf. Each one is listed with what it actually does and what it can see. Some are only involved if you use the relevant feature or if your deployment has it enabled.

ProviderWhat it does for usWhat it can seeWhere
Hetzner Online GmbHHosts our application server and databaseEverything in the service — it is the machine the service runs onHelsinki, Finland (EU)
Cloudflare, Inc.DNS, TLS termination, CDN and bot protection in front of every requestRequest metadata including your IP address, and traffic in transitGlobal edge network
Cloudflare R2Private object storage for file attachments and for photos or voice notes sent to the WhatsApp botThose file contents and namesCloudflare global (automatic region)
ResendDelivers the email we send you, and receives mail sent to our support addressYour email address and the contents of those messagesUnited States
AnthropicAI extraction for the optional task-import feature, including reading photos of task listsOnly the spreadsheet, file, message or photo you submit for import — never your account data or task historyUnited States
Hetzner AI inferenceOptional alternative to Anthropic for reading photos sent to the WhatsApp bot, when configuredOnly the photo you submit for importEU
Speech-to-textTranscribes voice notes sent to the WhatsApp bot, when that feature is enabled. By default this runs on our own server (a self-hosted Whisper model); a hosted OpenAI-compatible provider may be configured instead, and this list will name it before that happensThe audio of the voice note you sent, and nothing elseOur server (Finland) by default
Meta Platforms (WhatsApp Business Cloud API)Carries messages to and from the optional WhatsApp import botYour phone number and the messages you exchange with the botGlobal
Google LLCSign in with Google; Google Calendar sync; Google Play subscription verificationYour Google account identity; the events on the calendar you connect; your Play purchase recordsGlobal
Apple Inc.Sign in with Apple; App Store subscription verificationYour Apple sign-in identifier and App Store purchase recordsGlobal
Expo (Expo Application Services)Delivers push notifications to the mobile appsYour device push token and the text of each notificationUnited States
Stripe, Inc.Card payments and subscriptions outside IndiaYour payment details and billing identifiers (we never receive the card number)United States / global
Razorpay Software Pvt. Ltd.Card and UPI payments in IndiaYour payment details and billing identifiersIndia
SentryApplication error reporting, when enabledError type, message and stack trace, plus an opaque internal user identifier. We deliberately never send your name or email address to Sentry.United States / EU
NVIDIA (NIM inference API)Summarises mail sent to our support address so we notice it quicklyThe sender, subject and body of email you send to our support address. Nothing from your account or tasks.United States
TelegramCarries that internal support summary, and our own service-health alerts, to the operator on dutyThe summary text described above; health alerts describe our servers, not your accountGlobal

We will update this list before adding a new subprocessor that handles personal data. If you would like to be told when it changes, email us and we will add you to the notice list.

6. Other people who see your data

  • Your teammates. Tasks, comments, attachments and activity history in a shared project are visible to every member of that project. Project owners can see who is a member and manage them. This is the point of the product, but it is worth stating: do not put something in a shared project that you would not want the whole project to read.
  • Whoever set up your workspace. If your employer or school created the project you were invited to, they control it.
  • Law enforcement or a court, where we are legally compelled. We will tell you unless we are legally barred from doing so.
  • A buyer, if NeoKaam is ever sold or merged. You would be told before your data moved, and this policy would continue to apply until you were given a new one.

7. International transfers

Our servers are in Finland, within the EU. We are operated from India, so our own staff access data from India. Several of the subprocessors in section 5 are in the United States or operate global networks, so your data will cross borders.

For transfers out of the UK or EEA we rely on the receiving provider's Standard Contractual Clauses, which are part of the standard terms we accept with each of them. We do not currently offer a choice of data region, and we cannot keep your data inside a single country. If that is a requirement for you, tell us before you sign up.

8. Cookies

We use strictly necessary cookies only: a session cookie that keeps you signed in, a CSRF protection cookie, and a cookie remembering your chosen language. There are no analytics, advertising or tracking cookies, so there is no consent banner to click through. Blocking cookies will stop you being able to sign in.

9. Your rights

Depending on where you live these rights come from the GDPR/UK GDPR, India's Digital Personal Data Protection Act 2023, or the CCPA/CPRA. We apply them to everyone regardless of location.

  • Access — ask what we hold about you.
  • Export / portability — download everything we hold about you as a machine-readable JSON file from Profile → Your data → Download my data, at any time and without asking us. It covers your own profile, projects, tasks, comments, messages and account history; other members' content and email addresses are not included. Task lists can also be exported to Excel and PDF from inside the app.
  • Correction — fix anything wrong. Most of it you can edit yourself in your profile.
  • Deletion — delete your account from Profile → Delete account, or ask us to. See the retention table for exactly what then happens, and our deletion page for the step-by-step.
  • Object or restrict — tell us to stop a particular use. Where we rely on legitimate interests, you can object and we will stop unless we have a compelling reason not to.
  • Withdraw consent — disconnect Google Calendar or unlink WhatsApp in the app at any time; unsubscribe from announcement emails with the link in any of them.
  • No selling, no ad targeting — under the CCPA/CPRA we do not sell or share personal information, so there is nothing to opt out of.
  • No automated decision-making — nothing about you is decided by an algorithm with legal or similarly significant effect.

To exercise any of these, email [email protected] from the address on your account. We will confirm your identity and respond within 30 days. There is no charge. If you think we have got it wrong you can complain to your data protection authority — in India, the Data Protection Board; in the EU or UK, your national supervisory authority — but we would appreciate the chance to fix it first.

10. Children and students

NeoKaam is built for workplace and staff use. It is not directed at children, and you must be at least 13 (or the minimum age in your country) to hold an account. We do not knowingly create accounts for children under that age.

Some of our customers are schools, and their staff use NeoKaam to organise their own work. If you are an institution and you intend to create accounts for pupils under 18, or to store information about identifiable pupils in tasks, please contact us first. India's DPDP Act imposes additional duties for children's data — including verifiable parental consent and a prohibition on behavioural tracking and targeted advertising — and we would need to agree in writing how those duties are met before that use begins.

We do not do behavioural tracking or targeted advertising for anyone, of any age. If you believe a child has an account with us, or that a child's data has ended up in NeoKaam, email [email protected] and we will remove it.

11. How we protect your data

Everything travels over TLS, and we set HSTS with preload so browsers refuse to talk to us insecurely. Passwords are stored only as bcrypt hashes, never in a recoverable form. Sensitive endpoints — sign-in, registration, password reset — are rate-limited. Attachments live in a private bucket reachable only through short-lived signed URLs, and uploaded images are validated by inspecting the file's actual bytes rather than trusting its name. Incoming webhooks from our payment and messaging providers are signature-verified. Backups run on three independent schedules and are integrity-checked before they are kept.

We are honest about the limits. We are a small team; we have not completed a SOC 2 or ISO 27001 audit; we have not commissioned a third-party penetration test; and we do not encrypt individual database columns beyond what our hosting provides. We do run our own adversarial security reviews — the most recent was remediated in full — and we publish a vulnerability disclosure policy. No system is perfectly secure. If there is a breach affecting your personal data, we will notify you and the relevant authority without undue delay.

12. Data processing agreements

We do not yet publish a standard Data Processing Agreement. If your organisation needs one — or needs answers to a security questionnaire, or a copy of this subprocessor list under your own contract — email [email protected] and we will work through it with you. We would rather tell you what we can and cannot commit to than hand you a document we cannot honour.

13. Changes to this policy

We will update this page when what we do changes. For material changes — a new category of data, a new purpose, or a new subprocessor with access to your content — we will tell you by email or in the app at least 14 days before they take effect. The date at the top always reflects the last change.

14. Contact

NeoKaam is published by Sumit Sourabh. Questions, requests, or complaints about anything on this page: [email protected]. A real person reads it.