Privacy Policy

Effective Date: August 22, 2026

Introduction: The Enterprise Security Ethos

Grace Technology operates Task Force AI (taskforceai.net) as a secure platform for strategic analysis. We serve professionals who require absolute confidentiality for their mission briefs, strategic debates, and operational reports. To fulfill this mandate, our Privacy Policy is not a marketing document; it is a direct reflection of our codebase's physical architecture. We prioritize Data Sovereignty, Zero Data Retention (ZDR) for model training, and atomic data destruction.

1. Data We Collect (And Data We Refuse)

We collect only the absolute minimum data required to facilitate your access to the platform:

  • Account Data: Your email address, Google profile picture URL, and secure authentication tokens (JWT) provided via Google OAuth.
  • Billing Data: Processed securely via our PCI-compliant payment gateway (Stripe). We store only session identifiers and unit balances; we do not store full credit card numbers on our servers.
  • Voluntary Input: The mission briefs, strategic prompts, and documents you explicitly upload for AI Task Force processing, as well as the resulting debate transcripts and reports.

What We Refuse to Collect: We do not collect behavioral biometrics, device fingerprints for marketing, or shadow profiles. We do not monetize your data.

2. The Zero-Tracker Guarantee

Task Force AI utilizes zero third-party marketing trackers. There is no Google Analytics, no Meta Pixel, and no advertising telemetry injected into our frontend interface. Your strategic planning on our platform is entirely dark to the advertising industry.

Note on Security Processing: We use Cloudflare Turnstile strictly on our sign-in page for bot detection to protect your account. Turnstile may process client-side signals such as IP address, TLS fingerprint, and browser User-Agent solely for bot detection. Cloudflare does not use these security signals to identify individuals for advertising. For details, see Cloudflare's Turnstile Privacy Addendum.

3. Sub-Processors & Stateless Processing

Task Force AI operates under a strict Zero Data Retention (ZDR) architecture for model training. We do not use intermediary consumer routers. We transmit data statelessly via direct B2B Enterprise API endpoints to our sub-processors: Anthropic, OpenAI, Google, xAI, and Mistral. Under our binding Data Processing Agreements (DPAs), these sub-processors are contractually and legally prohibited from logging, retaining, or utilizing your mission briefs, transcripts, or prompts to train their models. Your data remains your exclusive intellectual property.

External Tools: If a Task Force utilizes Live Web Search, LLM-extracted search keywords (scrubbed of PII) are routed through our search sub-processor, Tavily. If you upload files or documents, they are securely housed in Google Cloud Storage (GCS) solely for the duration of your session.

4. The Pre-Transmission PII Shield

To guarantee Enterprise-Grade confidentiality, Task Force AI employs a Default-ON PII Shield. Before your mission briefs or extracted document text leaves our servers for LLM processing, our engine automatically redacts sensitive identifiers, including SSNs, phone numbers, emails, credit cards, and API keys.

Limitation of Technology: The PII Shield operates on text strings, not pixel data. It cannot redact sensitive information embedded in raw image uploads (JPG, PNG). Users must not upload unredacted photographs of sensitive physical documents.

5. Data Destruction (The Right to be Forgotten)

We do not utilize "soft deletes" or hidden retention logs. When you delete a Task Force session or your account, our backend executes an atomic Hard Delete. All conversational database records, debate transcripts, and reports are immediately wiped. Concurrently, our storage engine issues a physical destruction command to our Google Cloud Storage buckets, permanently eradicating all associated files. Your deleted data leaves zero behavioral fingerprints on our servers.

This architecture natively fulfills GDPR Article 17 (Right to Erasure) and CCPA deletion requirements.

6. Security & Encryption

All data transmitted between your browser, our servers, and our sub-processors is encrypted in transit using TLS 1.3. All persistent data (account records, session histories pending deletion, and active storage buckets) is encrypted at rest using AES-256 encryption.

7. Compliance & User Responsibility

While Task Force AI provides elite architectural safeguards to protect confidential strategic data, the User retains ultimate responsibility for data sovereignty. Users must not bypass the PII Shield when handling sensitive client or corporate data, and must adhere to their respective industry compliance frameworks regarding the transmission of raw proprietary information.

8. Contact Information

For privacy inquiries, data export requests, or compliance audits, please contact our Data Protection Officer:

Company
Grace Technology
Data Protection Officer
tracy@gracetechnology.org

See also our Terms of Service.