Task AIby phthos.ai
Sign inOpen app
Trust centerPrivacyTermsDPASubprocessors

Privacy Policy

Last updated: 2026-07-16

This Privacy Policy describes how phthos.ai (“Phthos”, “we”, “us”) handles information when you use Task AI and related services.

1. Who we are

Task AI is a product of Phthos. We provide AI task automation, connector integrations, knowledge bases (Brain), and team workspaces. For privacy questions, contact hello@phthos.ai.

2. Information we collect

  • Account information — name, email, workspace membership, authentication details (including OAuth profile data from providers you choose).
  • Billing information — plan, subscription status, invoices, and payment metadata processed by Stripe. We do not store full payment card numbers.
  • Task and configuration data — tasks, agent flows, connector settings, API keys (encrypted), secrets, Brain sources, schedules, and team invitations.
  • Usage data — AI run metadata, credit consumption, chat history, tool calls, and operational logs needed for metering, debugging, and security.
  • Connector content — when you connect Google Drive, Notion, Slack, or similar apps, we process content you authorize for indexing and task execution.
  • Technical data — IP address, browser type, device information, and cookies for session management and security.

3. How we use information

  • Provide, secure, and maintain Task AI and related APIs.
  • Authenticate users, enforce workspace roles, and prevent abuse.
  • Meter credits, process subscriptions, and send transactional email.
  • Run scheduled tasks, sync Brain sources, and execute agent workflows you configure.
  • Improve reliability, debug incidents, and develop features.
  • Comply with law and respond to lawful requests.

We do not sell your personal information.

4. AI content and customer data

Prompts, files, and connector content are processed to fulfill your requests, including forwarding to LLM and embedding providers configured for your workspace. Those providers handle data under their own terms. You are responsible for ensuring you have rights to submit content and for configuring retention appropriately.

5. How we share information

  • Service providers — see our Subprocessor list.
  • Model and app providers — when you route traffic or connect integrations, content is sent to providers you select.
  • Team members — other users in your workspace who have been granted access.
  • Legal and safety — when required by law or to protect rights and safety.

6. International transfers

We may process data in the European Union and in other countries where our service providers operate. Where required, we use appropriate safeguards for cross-border transfers.

7. Retention

We retain account, billing, and configuration data while your account is active and as needed for legal obligations. Run history, chat events, and Brain indexes are retained according to plan limits and operational settings; older data may be deleted or aggregated.

8. Security

We use encryption for secrets, access controls, rate limiting, and network isolation for production infrastructure. No method of transmission or storage is completely secure — protect your credentials and API keys.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export personal data. Email hello@phthos.ai to exercise these rights. Enterprise customers may use the terms in our DPA.

10. Changes

We may update this policy by posting a revised version and updating the “Last updated” date. Material changes may be communicated through the app or email where appropriate.

Contact

Email: hello@phthos.ai

Website: https://phthos.ai

PrivacyTermsDPASubprocessorsContact

© 2026 phthos.ai