NeoKaam Privacy Policy
Last updated: August 27, 2026
This policy explains what data NeoKaam holds about you, why we hold it, who else touches it, and how long we keep it. It covers the website, the web app, and the iOS and Android apps. We have tried to write it plainly and to state real numbers rather than "as long as necessary".
NeoKaam is published by Sumit Sourabh and is also distributed under the name Tickbox; the same service, the same account, and this same policy cover both, on the web and in the iOS and Android apps.
NeoKaam is built and operated by a very small team. Where a legal instrument that larger vendors offer does not exist yet, we say so on this page rather than implying otherwise.
1. Who we are
NeoKaam is a task and project management service published by Sumit Sourabh, operated from India and serving users worldwide. For anything to do with your data — questions, requests, or complaints — write to [email protected]. That address reaches the person responsible for privacy at NeoKaam. We have not appointed a formal Data Protection Officer; we are not currently required to.
For data you put into NeoKaam as part of your work — tasks, projects, comments, files — you (or your employer or school, if they set up the workspace) decide what goes in and why. We process it to run the service on your behalf.
2. What we collect
These are the actual categories of data stored in our database.
Account and identity
- Name, email address, username, and a password hash (bcrypt — never the password).
- An optional profile picture, stored on our own server and served from our domain — not uploaded to a third party.
- Your interface language (English or Hindi) and email-preference flags.
- If you sign in with Google or Apple: the identifier, name, email and profile picture those providers return, plus the OAuth tokens needed to keep the connection working.
Content you create
- Tasks, subtasks, projects, sections, labels, recurring-task templates, saved filters, comments, and direct messages to other members.
- File attachments, if your workspace has attachments enabled. They are stored in a private bucket and only ever served through short-lived signed links.
- Activity history — who changed what on a task and when — which is visible to the other members of that project.
- Support requests and in-app feedback you send us.
Security and technical records
- Login history: the time, method (password, Google, Apple, mobile app), IP address and browser user-agent of each successful sign-in. We keep this so you and we can spot account takeover.
- Security audit log: a record of security-relevant actions — adding or removing project members, issuing invite and share links, billing changes, linking WhatsApp, requesting an export or a deletion — with the time, IP address and user-agent.
- Device push tokens for the mobile apps, so we can deliver notifications.
- Server logs and error reports generated while serving your requests.
- Session cookies — see section 8.
Optional integrations, only if you turn them on
- Google Calendar: we write your task deadlines into your calendar and store the resulting event IDs. We ask Google only for the calendar-events permission (
calendar.events) — enough to create and update the events we make, not to manage your calendars or your account. You can disconnect it in the app at any time, which revokes our access. - WhatsApp task import: if you link your number, we store that phone number and the messages, photos, voice notes or small spreadsheets you forward to our bot, so we can turn them into tasks.
- AI task import: the spreadsheet, text, photo or voice note you submit is sent to an AI provider to extract a task list. See section 5.
Billing
- Subscription state, plan, source (card, Google Play, App Store), and the payment provider's customer and subscription identifiers.
- We never see or store your card number. Card details go directly to Stripe, Razorpay, Apple or Google.
- Counters recording when you hit a plan limit, used to understand which limits bite.
What we do not collect: we run no analytics, advertising, session-replay or cross-site tracking of any kind. There is no Google Analytics, no advertising pixel and no third-party tracker in the web app or the mobile apps. Web fonts are served from our own domain, not from a font CDN. We do not sell personal data, and we do not share it for behavioural advertising.
3. Why we use it, and our legal basis
If you are in the UK or EEA, the "legal basis" column is our basis under the GDPR. If you are in India, the equivalent under the DPDP Act is your consent or a legitimate use such as performing a service you asked for.
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Run your account, store and sync your tasks | It is the service you signed up for | Performance of a contract |
| Send verification, password-reset, invitation and reminder emails and push notifications | You cannot use the account without them | Performance of a contract |
| Keep login history and a security audit log, and rate-limit sensitive endpoints | Detect and stop account takeover and abuse | Legitimate interests (security) |
| Record and report application errors | Find and fix faults before they cost you data | Legitimate interests (service reliability) |
| Answer your support requests | You asked us something | Legitimate interests / contract |
| Calendar sync, WhatsApp import, AI import | Optional features you switched on | Consent (withdrawable at any time) |
| Product-announcement emails | Telling you what changed | Consent — one click to opt out, and we honour it |
| Take payment and keep subscription records | Billing and tax records | Contract and legal obligation |
4. How long we keep it
These are the retention windows actually enforced by our scheduled jobs, not aspirations.
| Data | Kept for |
|---|---|
| Your account and everything in it | For as long as your account exists. Deleting your account starts the clock below. |
| Deleted accounts | 30 days from the moment you request deletion, then permanently and irreversibly erased by an automated job — including projects you own, your tasks, comments, messages, activity history and login records. The one exception is the security audit log described below, which is kept as evidence of who did what. The 30 days exist so an accidental or coerced deletion can be reversed, and so co-workers are not cut off from a shared project without warning. |
| Login history (IP address, user-agent) | 90 days, then automatically deleted. |
| Security audit log (the action taken, IP address, user-agent) | 400 days, then automatically deleted. It is deliberately not erased when an account is deleted: a record of a deletion request that vanishes with the account proves nothing. It holds identifiers, never names, email addresses or phone numbers. |
| Plan-limit and billing event records | 180 days, then automatically deleted. |
| AI import jobs (the file, photo, voice note or message you submitted and the rows extracted from it) | A job left un-confirmed for 24 hours is treated as abandoned and its content is discarded. All import job records are purged after 30 days. |
| Attachment files | Deleted with the task they belong to. Half-finished uploads are removed after 24 hours; a reconciliation job sweeps up any orphaned object. |
| Unverified sign-ups | If you register but never verify your email, we warn you, then delete the account — after roughly 24 hours if it holds nothing, or after 7 days if you had created tasks. |
| Email verification links | 24 hours. Password reset links: 1 hour. Project invitations: 7 days. Shared invite links: 72 hours. |
| Mobile sign-in refresh tokens | 30 days, then you sign in again. |
| Orphaned profile pictures | Removed by a cleanup job once no account references them. |
| Email you send to our support address | Stored so we can answer you; we do not currently run an automatic expiry on it. Ask us and we will delete a specific thread. |
| Database backups | Backups are held on three independent rotations; the longest-lived slot is about one year. Deleting your account removes you from the live database at the end of the grace window, but a backup taken before then may still contain your data until that backup rotates out. |
Where the law requires us to keep something longer — for example financial records — we keep only that record, for only that long.
5. Who else processes your data (subprocessors)
These are the third parties that store, process or transit your data on our behalf. Each one is listed with what it actually does and what it can see. Some are only involved if you use the relevant feature or if your deployment has it enabled.
| Provider | What it does for us | What it can see | Where |
|---|---|---|---|
| Hetzner Online GmbH | Hosts our application server and database | Everything in the service — it is the machine the service runs on | Helsinki, Finland (EU) |
| Cloudflare, Inc. | DNS, TLS termination, CDN and bot protection in front of every request | Request metadata including your IP address, and traffic in transit | Global edge network |
| Cloudflare R2 | Private object storage for file attachments and for photos or voice notes sent to the WhatsApp bot | Those file contents and names | Cloudflare global (automatic region) |
| Resend | Delivers the email we send you, and receives mail sent to our support address | Your email address and the contents of those messages | United States |
| Anthropic | AI extraction for the optional task-import feature, including reading photos of task lists | Only the spreadsheet, file, message or photo you submit for import — never your account data or task history | United States |
| Hetzner AI inference | Optional alternative to Anthropic for reading photos sent to the WhatsApp bot, when configured | Only the photo you submit for import | EU |
| Speech-to-text | Transcribes voice notes sent to the WhatsApp bot, when that feature is enabled. By default this runs on our own server (a self-hosted Whisper model); a hosted OpenAI-compatible provider may be configured instead, and this list will name it before that happens | The audio of the voice note you sent, and nothing else | Our server (Finland) by default |
| Meta Platforms (WhatsApp Business Cloud API) | Carries messages to and from the optional WhatsApp import bot | Your phone number and the messages you exchange with the bot | Global |
| Google LLC | Sign in with Google; Google Calendar sync; Google Play subscription verification | Your Google account identity; the events on the calendar you connect; your Play purchase records | Global |
| Apple Inc. | Sign in with Apple; App Store subscription verification | Your Apple sign-in identifier and App Store purchase records | Global |
| Expo (Expo Application Services) | Delivers push notifications to the mobile apps | Your device push token and the text of each notification | United States |
| Stripe, Inc. | Card payments and subscriptions outside India | Your payment details and billing identifiers (we never receive the card number) | United States / global |
| Razorpay Software Pvt. Ltd. | Card and UPI payments in India | Your payment details and billing identifiers | India |
| Sentry | Application error reporting, when enabled | Error type, message and stack trace, plus an opaque internal user identifier. We deliberately never send your name or email address to Sentry. | United States / EU |
| NVIDIA (NIM inference API) | Summarises mail sent to our support address so we notice it quickly | The sender, subject and body of email you send to our support address. Nothing from your account or tasks. | United States |
| Telegram | Carries that internal support summary, and our own service-health alerts, to the operator on duty | The summary text described above; health alerts describe our servers, not your account | Global |
We will update this list before adding a new subprocessor that handles personal data. If you would like to be told when it changes, email us and we will add you to the notice list.
6. Other people who see your data
- Your teammates. Tasks, comments, attachments and activity history in a shared project are visible to every member of that project. Project owners can see who is a member and manage them. This is the point of the product, but it is worth stating: do not put something in a shared project that you would not want the whole project to read.
- Whoever set up your workspace. If your employer or school created the project you were invited to, they control it.
- Law enforcement or a court, where we are legally compelled. We will tell you unless we are legally barred from doing so.
- A buyer, if NeoKaam is ever sold or merged. You would be told before your data moved, and this policy would continue to apply until you were given a new one.
7. International transfers
Our servers are in Finland, within the EU. We are operated from India, so our own staff access data from India. Several of the subprocessors in section 5 are in the United States or operate global networks, so your data will cross borders.
For transfers out of the UK or EEA we rely on the receiving provider's Standard Contractual Clauses, which are part of the standard terms we accept with each of them. We do not currently offer a choice of data region, and we cannot keep your data inside a single country. If that is a requirement for you, tell us before you sign up.
8. Cookies
We use strictly necessary cookies only: a session cookie that keeps you signed in, a CSRF protection cookie, and a cookie remembering your chosen language. There are no analytics, advertising or tracking cookies, so there is no consent banner to click through. Blocking cookies will stop you being able to sign in.
9. Your rights
Depending on where you live these rights come from the GDPR/UK GDPR, India's Digital Personal Data Protection Act 2023, or the CCPA/CPRA. We apply them to everyone regardless of location.
- Access — ask what we hold about you.
- Export / portability — download everything we hold about you as a machine-readable JSON file from Profile → Your data → Download my data, at any time and without asking us. It covers your own profile, projects, tasks, comments, messages and account history; other members' content and email addresses are not included. Task lists can also be exported to Excel and PDF from inside the app.
- Correction — fix anything wrong. Most of it you can edit yourself in your profile.
- Deletion — delete your account from Profile → Delete account, or ask us to. See the retention table for exactly what then happens, and our deletion page for the step-by-step.
- Object or restrict — tell us to stop a particular use. Where we rely on legitimate interests, you can object and we will stop unless we have a compelling reason not to.
- Withdraw consent — disconnect Google Calendar or unlink WhatsApp in the app at any time; unsubscribe from announcement emails with the link in any of them.
- No selling, no ad targeting — under the CCPA/CPRA we do not sell or share personal information, so there is nothing to opt out of.
- No automated decision-making — nothing about you is decided by an algorithm with legal or similarly significant effect.
To exercise any of these, email [email protected] from the address on your account. We will confirm your identity and respond within 30 days. There is no charge. If you think we have got it wrong you can complain to your data protection authority — in India, the Data Protection Board; in the EU or UK, your national supervisory authority — but we would appreciate the chance to fix it first.
10. Children and students
NeoKaam is built for workplace and staff use. It is not directed at children, and you must be at least 13 (or the minimum age in your country) to hold an account. We do not knowingly create accounts for children under that age.
Some of our customers are schools, and their staff use NeoKaam to organise their own work. If you are an institution and you intend to create accounts for pupils under 18, or to store information about identifiable pupils in tasks, please contact us first. India's DPDP Act imposes additional duties for children's data — including verifiable parental consent and a prohibition on behavioural tracking and targeted advertising — and we would need to agree in writing how those duties are met before that use begins.
We do not do behavioural tracking or targeted advertising for anyone, of any age. If you believe a child has an account with us, or that a child's data has ended up in NeoKaam, email [email protected] and we will remove it.
11. How we protect your data
Everything travels over TLS, and we set HSTS with preload so browsers refuse to talk to us insecurely. Passwords are stored only as bcrypt hashes, never in a recoverable form. Sensitive endpoints — sign-in, registration, password reset — are rate-limited. Attachments live in a private bucket reachable only through short-lived signed URLs, and uploaded images are validated by inspecting the file's actual bytes rather than trusting its name. Incoming webhooks from our payment and messaging providers are signature-verified. Backups run on three independent schedules and are integrity-checked before they are kept.
We are honest about the limits. We are a small team; we have not completed a SOC 2 or ISO 27001 audit; we have not commissioned a third-party penetration test; and we do not encrypt individual database columns beyond what our hosting provides. We do run our own adversarial security reviews — the most recent was remediated in full — and we publish a vulnerability disclosure policy. No system is perfectly secure. If there is a breach affecting your personal data, we will notify you and the relevant authority without undue delay.
12. Data processing agreements
We do not yet publish a standard Data Processing Agreement. If your organisation needs one — or needs answers to a security questionnaire, or a copy of this subprocessor list under your own contract — email [email protected] and we will work through it with you. We would rather tell you what we can and cannot commit to than hand you a document we cannot honour.
13. Changes to this policy
We will update this page when what we do changes. For material changes — a new category of data, a new purpose, or a new subprocessor with access to your content — we will tell you by email or in the app at least 14 days before they take effect. The date at the top always reflects the last change.
14. Contact
NeoKaam is published by Sumit Sourabh. Questions, requests, or complaints about anything on this page: [email protected]. A real person reads it.