Privacy Policy

Effective date: 18 July 2026.

1. Introduction

TaskGoblin Limited ("TaskGoblin", "we") operates an AI coding-agent platform that reviews merge/pull requests and autonomously writes code in connected repositories. This policy covers the marketing site (taskgoblin.ai), the application (cave.taskgoblin.ai), and the services, and applies to visitors, account users, and individuals whose information appears in customer content. For customer content — the code, issues, and messages a customer organisation routes to us — we act as a processor on that organisation's instructions; for account and billing data we are the controller.

2. Information We Collect

Information you provide. Name, email address, and avatar; an optional password (stored hashed); two-factor-authentication and passkey credentials (stored encrypted); organisation details; and your communications with support.

From connected accounts, at your direction. When you connect GitLab, GitHub, Linear, or Slack, we receive your profile information on that platform (provider ID, name, username, email, avatar) and OAuth tokens. All tokens are encrypted at rest.

Customer content processed to run the Agent. Repository contents — cloned in full into an isolated sandbox: the Agent reads the whole working tree, not only the diff under review — plus issues, comments, merge/pull-request discussions, and Slack messages. Agent conversation history, execution traces, and per-organisation token-usage metrics are stored so the Agent keeps context across turns.

Review findings we retain. For each inline review comment the Agent posts, we store the finding's title, body, suggested replacement code, file path and line, category, severity, and fix status. This means excerpts of your code are stored in our database, not merely passed through.

Run records. For each Agent run we persist the assembled system prompt, the user prompt, the raw webhook payload we received from the provider (which can include the triggering user's platform profile and comment text), the Agent's final response, and its execution trace.

Collected automatically. Session IP address and browser user-agent; your timezone, auto-detected from your browser to display dates correctly; server logs and application-health metrics.

Payment data. Payments are processed by Stripe. We store only Stripe customer and subscription identifiers and your plan state — never card numbers.

3. What We Don't Do

We use no analytics or advertising trackers, no third-party tracking cookies, no pixels, and no session recording. We do not sell or rent personal data, and we show no ads. The marketing site sets no cookies at all. There is nothing to opt out of — we honour "Do Not Track" by default.

4. Cookies

The application uses only strictly functional cookies: the session cookie, the CSRF token (XSRF-TOKEN), the "remember me" token, locale (language preference), and appearance (theme). That list is exhaustive.

5. How We Use Information

We use information to provide and operate the services (review merge/pull requests, run the Agent, open merge/pull requests, sync integrations, apply requested fixes); authenticate and secure accounts; manage billing and subscriptions; provide support; monitor capacity and enforce usage limits; improve the services using aggregated, de-identified usage data; comply with law; and protect against fraud and abuse. We do not use your code or content to train AI models.

Where the GDPR applies, we process personal data to perform our contract with you, for our legitimate interests (security, service improvement, fraud prevention), with your consent where applicable, and to comply with legal obligations.

7. How We Share Information

We do not sell personal data. We share it only with:

  • Stripe — payments and subscription management.
  • Amazon Web Services (Laravel Vapor) — hosting and storage, in the United States.
  • Cloudflare — CDN and security in front of the marketing site.
  • LLM providers (Anthropic, OpenAI, Google) — receive the code and context needed for a run, at your direction, to power the Agent.
  • Sandbox infrastructure — isolated execution environments operated by or for TaskGoblin.
  • Your connected platforms (GitLab, GitHub, Linear, Slack) — the Agent writes back to them at your direction (commits, merge/pull requests, inline review comments, description summaries, comments, and messages) under its own bot identity.
  • Our email delivery provider — transactional email.

We may also share information with professional advisors, in a corporate transaction (with notice), or when legally required (with notice where lawful).

Data the Agent writes into GitLab, GitHub, Linear, or Slack is governed by those platforms' own policies and your settings there. We are not responsible for third-party sites we link to.

9. Data Retention

Account and profile data are kept for the life of the account. OAuth and integration tokens are kept until you disconnect the integration or delete the organisation, then deleted. Repository code in sandboxes: a sandbox is persisted and reused across a conversation thread's runs — it is not destroyed after each run — and is removed when the organisation is deleted. Review findings (including stored code suggestions), agent conversation history, run prompts, raw webhook payloads, execution traces, and usage metrics are kept for the life of the organisation. Billing records are kept as required by tax and accounting law. Data is deleted on account or organisation deletion, or on a verified request.

10. Security

We use encryption in transit (TLS) and at rest for all secrets (OAuth tokens, API keys, two-factor secrets); strict per-organisation data isolation; agent runs execute in isolated sandboxes with scoped credentials; and access controls and audit logging protect sensitive records. No system is perfectly secure; we will notify you of breaches as required by applicable law.

11. Your Rights and Choices

You can access and update your account data in settings. For deletion, portability, correction, restriction, or objection, contact [email protected]. If you are in the EEA or UK, you have GDPR rights, including the right to complain to a supervisory authority; California residents have CCPA/CPRA rights (to know, delete, correct, and to non-discrimination — and we do not sell or share personal information). If your information appears in a customer's repository or workspace, please direct requests to that customer; we will assist them as a processor.

12. International Transfers

Our servers are in the United States. If you use the services from elsewhere, your information is transferred to and processed in the United States, with appropriate safeguards for EEA/UK transfers.

13. Children

The services are not directed at children under 16, and we do not knowingly collect their data. Contact us for removal.

14. Changes to This Policy

We will post updates with a revised effective date and notify you of material changes by email or in-product.

15. Contact

Questions and requests: [email protected] — TaskGoblin Limited