PipeTask
Privacy Policy
Effective July 29, 2026
PipeTask synchronizes collaborative Google Chat Space tasks to a Supabase-backed workspace and provides an AI-assisted interface for managing those tasks. This policy explains the data handled by the PipeTask browser extension and its supporting services.
Data PipeTask handles
- Google account information: your name, email address, profile identifiers, and the authentication information required to connect Google and PipeTask.
- Task and workspace information: Google Tasks list metadata and Google Chat Space task titles, descriptions, identifiers, assignees, completion status, due dates, update dates, Space names, and Space identifiers.
- Current Space context:the extension locally checks whether the active tab is a supported Google Chat Space and sends only that Space's name and identifier when you sync it or ask the Agent about this Space. The full tab URL is not stored or sent to PipeTask's services. PipeTask does not collect your general browsing history or Google Chat messages.
- Agent information: your signed-in Google name and email, prompts you send to the PipeTask Agent, relevant task records retrieved for your request, generated responses, and task actions proposed by the Agent.
- Service information: limited request, error, security, and reliability metadata generated when the extension communicates with its supporting services.
How the data is used
PipeTask uses this information only to authenticate you, discover and synchronize Google Chat Space tasks, maintain your PipeTask workspace, answer task-management questions, and carry out task actions you explicitly confirm. PipeTask does not read Google Chat messages, serve personalized advertising, or sell user data.
Creating, editing, assigning, completing, or permanently deleting a Google Chat Space task requires confirmation in the extension before PipeTask sends the action.
Where data is processed
- Google: Google OAuth, Google Tasks, Google Chat task surfaces, and Google Gemini process the information necessary to authenticate, read or update tasks, and produce Agent responses.
- Supabase: Supabase provides authentication, database storage, Row Level Security, and the Edge Function that connects the extension to Google Gemini.
- Your browser: the extension stores session information, consent status, recent synchronization status, workspace preferences, and up to 20 recent Agent messages in extension-local storage.
Data may be processed in countries where these providers operate. Their handling of data is also governed by their applicable terms and privacy policies.
Workspace access
PipeTask uses Supabase Row Level Security as its data-access boundary. Workspace administrators can access tasks in their organization. Members can access tasks assigned to them and unassigned tasks, together with the workspace information needed to use PipeTask.
Retention and deletion
Local session data remains until you disconnect PipeTask, remove the extension, or clear extension data. Local Agent history remains until you clear the conversation or disconnect. Synced workspace records remain until they are reconciled with Google Chat, deleted by an authorized workspace user or administrator, or removed following a verified deletion request.
Disconnecting removes PipeTask's locally stored authentication tokens, Agent history, consent record, and workspace preferences. It does not automatically delete task records already synchronized to the shared workspace.
Security
PipeTask transmits data over HTTPS. Google access tokens are used only with Google services. Supabase session tokens are used only with the configured PipeTask Supabase project. The extension package does not contain Supabase service-role credentials or AI-provider API keys.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used and transferred only as necessary to provide or improve PipeTask's disclosed task-synchronization and task-management purpose, maintain security, comply with law, or complete a transaction to which the user has given prior consent.
PipeTask does not use or transfer user data for personalized advertising, creditworthiness, lending, sale to data brokers, or other unrelated purposes. Humans do not read user task data except with the user's specific consent, when necessary for security, when required by law, or when data has been aggregated and anonymized for permitted internal operations.
Your choices
You can decline the in-extension disclosure and avoid connecting PipeTask. After connecting, you can clear Agent history or disconnect at any time. To request access, correction, workspace deletion, or other privacy assistance, email contact@arboraistudio.com with "PipeTask Privacy Request" in the subject line.
Changes and contact
We may update this policy when PipeTask's data practices or legal obligations change. Material changes will be disclosed before newly affected data is handled.
