Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your information.
Last updated: November 18, 2025
Introduction
Taffy Tree ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-enhanced project management platform and related services (the "Service").
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
Information We Collect
Information You Provide
- Account Information: Name, email address, password, and profile information
- Project Data: Tasks, notes, documents, and other content you create or upload
- Communication Data: Messages, feedback, and support requests
- Payment Information: Billing details and payment method information (processed securely by third-party providers)
Information Automatically Collected
- Usage Data: How you interact with our Service, features used, and time spent
- Device Information: IP address, browser type, device type, and operating system
- Log Data: Server logs, error reports, and performance metrics
- Cookies and Tracking: Information collected through cookies and similar technologies
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Service
- Process transactions and manage your account
- Personalize your experience and provide AI-powered features (no data is used for training AI models.)
- Communicate with you about your account and our services
- Provide customer support and respond to inquiries
- Send marketing communications (with your consent)
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations and enforce our terms
- Conduct research and analytics to improve our services
Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Email: privacy@taffytree.com
Mail: Taffy Tree Privacy Team
Data Sharing and Disclosure
We do not share, transfer, or disclose any Google user data to third parties.
Data Protection and Security
We employ industry‑standard security measures to protect all data, including any Google user data that may be processed:
- Encryption: Data is encrypted in transit using TLS 1.2+ and at rest with AES‑256 encryption.
- Network Security: Firewalls and intrusion‑detection systems monitor traffic to and from our services.
- Access Controls: Strict role‑based access controls and multi‑factor authentication limit internal access to authorized personnel only.
- Security Reviews: Industry-standard security reviews may be conducted to remediate risks such as: regular security audits, vulnerability scans, and penetration testing.
These mechanisms safeguard both regular and sensitive data handled by the Service.
Data Retention and Deletion
We retain Google user data only for the period necessary to provide the Service. Specifically, calendar event data retrieved from Google is stored in our database solely to enable synchronization and display within the platform. This data is retained until the user disconnects their Google account or explicitly requests deletion. Upon disconnection or deletion request, all stored Google data is permanently removed from our systems.
We do not retain any other Google user data beyond what is necessary for the functionality of the Service.