Privacy Policy
Last updated: July 27, 2026
TaskAlarm ("the add-on," "we," "us") is a Google Workspace add-on that sends you email reminders for your Google Tasks at times you choose. This policy explains what data the add-on accesses, why, how it is handled, how it is protected, and the choices you have. We built TaskAlarm to do one job well and to touch as little of your data as possible.
1Information we access
TaskAlarm accesses the following, only to provide the reminder feature:
- Your Google Tasks (read-only). The add-on reads your task lists and tasks so it can show them in the sidebar and know which have upcoming reminders. It does not create, edit, or delete your tasks.
- Your email address. Used to send reminder emails to you and to identify your account for plan management.
- Alert times you set. When you choose a reminder time for a task, that time is stored so the add-on can send the reminder.
2How we use it
Your data is used solely to operate TaskAlarm's reminder feature:
- To display your tasks in the add-on sidebar.
- To send you an email reminder at the time you set for a task.
- To determine whether your account is on the free plan or the Pro plan.
We do not use your data for advertising, we do not sell or rent it, and we do not share it with third parties except the service providers described below that are required for the add-on to function.
3Where data is stored
- Alert times and reminder state are stored using Google's own Properties Service, tied to your Google account.
- Plan status (whether you are a free or Pro user, matched by your email address) is stored in our database provider, Supabase, to verify your plan when the add-on runs.
- Payment information for Pro subscriptions is handled entirely by Stripe. TaskAlarm never sees or stores your card details.
4Service providers
TaskAlarm relies on a small number of providers to function. Each processes only the limited data needed for its role:
- Google Workspace / Google Tasks API — the platform the add-on runs on and the source of your tasks.
- Supabase — stores plan status keyed to your email address.
- Stripe — processes Pro subscription payments.
5How we protect your data
We apply the following technical and organizational safeguards to all data TaskAlarm accesses, including sensitive data obtained from Google APIs:
- Encryption in transit. All communication between the add-on, the Google Tasks API, Supabase, and Stripe takes place over HTTPS secured with TLS. TaskAlarm makes no unencrypted network requests.
- Encryption at rest. Alert times and reminder state are held in Google's Properties Service and encrypted at rest by Google's infrastructure. Plan status held in Supabase is encrypted at rest by that provider.
- Authentication and credentials. Access to your Google Tasks is authorized through Google OAuth 2.0. Access tokens are issued, scoped, and managed by Google. TaskAlarm never sees, requests, or stores your Google password.
- Least privilege. The add-on requests read-only access to your tasks and is technically incapable of creating, editing, or deleting them. We request the minimum set of OAuth scopes required for reminders to function, and nothing beyond that.
- Data minimization. Task titles and task content are processed within Google's infrastructure to build your reminder email and are never copied to our database or transmitted to any third party. The only data stored outside Google is your email address and your plan status.
- No human review. Your tasks and reminder emails are processed automatically. No member of our team reads, browses, or has any interface to view your task content.
- Access controls. Service credentials and API keys are stored as encrypted secrets within the hosting platform, never in source code or public repositories. Administrative access to the plan-status database is limited to the single developer account that operates TaskAlarm and is protected by two-factor authentication.
- Payment isolation. Card details are collected and processed directly by Stripe, a PCI DSS Level 1 certified provider. Payment card data never passes through, and is never stored by, TaskAlarm.
- Incident response. If we become aware of a security incident affecting your data, we will notify affected users at the email address associated with their account, and notify Google where Google user data is involved, without undue delay.
6Data retention and deletion
Alert times and reminder state persist while you use the add-on and are removed when you uninstall TaskAlarm or delete the associated tasks. Plan status is retained while your account exists so the add-on can verify your plan. You may request deletion of your plan record at any time by emailing support@taskalarm.app; we will delete it within 30 days of a verified request. Uninstalling the add-on or revoking its access immediately ends all further access to your Google Tasks data.
7Limited Use disclosure
TaskAlarm's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We only use Google user data to provide and improve the reminder feature, and we do not transfer it except as needed to run the service.
8Your choices
- You can remove any reminder by clearing its alert time in the sidebar.
- You can uninstall TaskAlarm at any time, which stops all access and removes stored reminder state.
- You can revoke the add-on's access to your Google account at myaccount.google.com/permissions.
- You can contact us to request deletion of your plan record.
9Children
TaskAlarm is not directed to children under 13 and does not knowingly collect data from them.
10Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated within the add-on.
11Contact
Questions about this policy or your data? Email support@taskalarm.app.