Effective date: July 20, 2026·Last updated: July 20, 2026
BLUELINKS GROUP LTD (company no. 16277222), registered office: 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency.
Your trust matters to us. This Privacy Policy explains exactly what data TaskGlaze collects, why, who we share it with (including the principal third-party providers we use, by name), precisely how long we keep it, and the rights you have over your own data. A summary table of contents is on the right — click any item to jump straight to it.
On this page
This Privacy Policy explains how BLUELINKS GROUP LTD, a company registered in England and Wales under company number 16277222, whose registered office is at 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency and operating TaskGlaze ("Company", "we", "us", "our") collects, uses, discloses, and protects information when you visit taskglaze.com, use app.taskglaze.com, or otherwise interact with TaskGlaze (the "Service"). It should be read together with our Terms of Service and, if you are a business customer, our Data Processing Agreement. If you do not agree with this Policy, please do not use the Service.
The data controller responsible for your personal data under this Policy is BLUELINKS GROUP LTD, a company registered in England and Wales under company number 16277222, trading as Bluelinks Agency and as TaskGlaze.
Registered office: 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF. This is also our correspondence address for data-protection matters. Our dedicated privacy contact is support@taskglaze.com.
We act in two different roles depending on the data, and the responsibilities attached to each role are different:
Account information. Name, email address, and password (stored as a bcrypt hash — we never store your password in plain text), or your Google account email/name if you sign in via Google. Optional profile fields such as company name and job title.
Billing information. Your billing name/email and subscription plan/status. Your payment card details are collected and stored directly by Stripe, our payment processor — we do not receive or store your full card number.
Service content. The websites, keywords, and domains you submit for audits, research, and backlink analysis; your Outreach CRM records (prospect contacts, notes, deal data); AI content workflow prompts and generated output; and any files or text you otherwise submit to the Service.
Connected email account credentials.If you connect a mailbox to the Outreach CRM, we store the SMTP/IMAP host, username, and password (or app-specific password, for providers like Gmail that require one when 2FA is enabled) you provide, encrypted at rest with AES-256-GCM. This feature uses direct SMTP/IMAP credentials, not an OAuth token — if your provider supports and requires an app-specific password instead of your primary account password, use that. We use these credentials only to send and retrieve mail at your explicit instruction, as described in "Connected email accounts" below.
Usage & device data. Log data such as IP address, browser/device type, pages visited, and actions taken in the Service, collected automatically for security, debugging, and abuse-prevention purposes.
Communications. Any information you provide when you contact support or otherwise correspond with us.
We separate what we send you into two categories, because they have different rules:
If you are located in the EEA, UK, or another jurisdiction with similar requirements, we rely on the following legal bases under GDPR / UK GDPR:
The Outreach CRM lets you optionally connect your own mailbox to send and receive outreach correspondence. This is a sensitive integration, so we handle it deliberately:
EXAMINE command (read-only mode) — under this mode the mail server itself will not allow any flag or state change for the duration of the connection, so a message is never silently marked read, moved, or altered. We never issue an IMAP move, copy, flag, or delete command against your mailbox at all — this is a hard guarantee in how the feature is built, not just a policy promise.Our customers use the Outreach CRM to store and contact business prospects, clients, and other contacts — individuals who have never created a TaskGlaze account and, in most cases, have never interacted with us directly. Depending on what a customer chooses to store, this can include a contact's name, work email, job title, employer, website, outreach history, email replies, notes, and deal status.
As explained in "When we are controller vs. processor" above, our customer is the data controller for this data, and we act only as their processor— we store and transmit it on that customer's instruction, and it is the customer, not us, who determines why and how that information is used.
Where applicable law requires notifying an individual that their data is held when it wasn't collected directly from them (for example, Article 14 GDPR's transparency requirement, which generally must be satisfied within a reasonable period and no later than one month, unless an exemption applies), that obligation belongs to our customer as controller, not to us. Our Data Processing Agreementsets out this allocation of responsibility in full, along with our own security and sub-processing obligations as processor. If you are a contact who was added to a TaskGlaze customer's Outreach CRM and have a question about your data, please contact that business directly; if you're unsure who that is, contact us at support@taskglaze.comand we will do our reasonable best to help identify the right customer, or to honor a suppression/opt-out request directly — see "Outreach CRM & connected email accounts" in the Terms of Service for how opt-outs are enforced platform-wide.
When you use an AI-assisted feature (content briefs, drafts, meta tags, idea generation, or AI-drafted outreach emails), the relevant prompt and supporting content is sent to our AI infrastructure provider, OpenRouter, which routes the request to a third-party AI model provider to generate the response. Depending on the feature, this may include models from more than one provider; you do not currently choose the specific model — we select it per feature based on suitability and cost. The prompt/content is transmitted for the sole purpose of generating your requested output and, on our side, is not logged or retained beyond what's needed to return the response and to maintain your own generation history within your Account.
Do OpenRouter or the underlying model providers retain or train on your prompts? We do not use your Content to train any TaskGlaze-owned model — we don't operate our own model at all. Whether OpenRouter or a specific underlying model provider temporarily logs, retains, or uses your prompt to improve their own models depends on that provider's own policy and our commercial terms with them, which can differ by provider and may change over time. We select providers and configure our account to request the strongest available no-retention / no-training terms where a provider offers them, but we cannot guarantee a uniform practice across every provider our AI features may route to.
Do not submit special-category or otherwise sensitive data.You must not submit special category personal data (e.g. health, biometric, or similar sensitive personal data), financial account numbers or payment credentials, authentication secrets (passwords, API keys, tokens), or other confidential/restricted information into any AI prompt, unless expressly authorized by us in writing. AI Output should always be reviewed before use — see the Terms of Service's "AI-generated content" section.
Our application and database servers are hosted with Hetzner in Germany (EU). Some of our Subprocessors (for example, Stripe, Google, and certain AI model providers accessed through OpenRouter) are based in, or process data in, the United States or other countries outside the EEA/UK. Where that happens, we rely on one of the following safeguards, as applicable to the specific provider and transfer: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; the EU Standard Contractual Clauses on their own (for EU-originating transfers); the provider's certification under the EU–US Data Privacy Framework and, where applicable, the UK Extension to the EU–US Data Privacy Framework; or applicable UK adequacy regulations for the destination country. A copy of the specific mechanism used for a given Subprocessor is available on request at support@taskglaze.com.
We keep personal data only for as long as needed for the purposes described in this Policy. The table below states the actual retention period or purge mechanism for each category — these match our real systems, not general placeholders:
| Data | Retention period |
|---|---|
| Active Account & Service data | Duration of your Account |
| Cancelled/locked Account data (trial expired or subscription ended) | Retained, fully exportable, until you request deletion — see "Account data export & deletion" |
| Soft-deleted Outreach CRM / Mail records (prospects, conversations) | 30-day recovery window, then automatically and permanently purged |
| Mailbox credentials (Connected Accounts) | Deleted immediately on disconnection; otherwise retained only while the mailbox stays connected |
| Outreach email content (sent/received through a Connected Account) | Until you delete the record or delete your Account |
| Account deletion (on verified request) | Completed within 30 days of your request |
| Suppression / unsubscribe records | Retained indefinitely, independent of the underlying record or Account, to honor opt-outs and prevent re-contact |
| Encrypted server backups | Weekly backups: ~5 weeks rolling. Monthly backups: 12 months rolling |
| Security logs (login/auth/abuse events) | 14 days |
| Billing & invoice records | 6 years, to comply with UK tax/accounting record-keeping law |
| Support correspondence | Up to 2 years |
Backups are encrypted, used solely for disaster recovery, and are not indexed or searchable outside of a genuine restore event.
To request an export or deletion of your Account data, email support@taskglaze.com. There is currently no self-service "export"/"delete my account" button in the Service — both are handled as a verified request to this address, and we aim to complete either within 30 days.
Export includes your Account/profile data, project and audit history, Outreach CRM records (including prospect/contact data, subject to your own obligations to those individuals as controller), and email history sent/received through a Connected Account, provided as structured data (e.g. CSV/JSON) covering the categories you request.
Deletionremoves your Account and the data categories above, except: suppression/opt-out records (kept indefinitely, see "Data retention"), billing records we're legally required to retain (6 years), and any copy still present in an already-taken encrypted backup until it ages out of our rolling backup-retention schedule (weekly: ~5 weeks, monthly: 12 months) — we cannot selectively edit a completed backup archive, only let it expire on schedule.
We apply industry-standard technical and organizational measures to protect your data, including:
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify affected users and relevant authorities as required by applicable law.
We do not carry out decision-making based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR / UK GDPR. Some account-administration actions are automated (for example, a trial automatically moving to a locked, read-only state at the end of its 14-day period) — these are routine contract-administration steps applied uniformly by Plan rules, not profiling or a decision made about you individually, and you can always contact support@taskglaze.com about any account-status question.
Depending on your location, you may have the right to:
You can access and update most Account information directly from your account settings, or exercise any of the above rights by emailing support@taskglaze.com — this is also our dedicated contact for data-protection requests. We will respond within the timeframe required by applicable law (generally within 30 days). We may need to verify your identity before actioning a request.
Consent record for signed-in accounts. Creating an Account requires agreeing to this Policy and our Terms of Service; that acceptance is recorded once, permanently, on your Account at signup (not just as a browser cookie), so it carries across every device you use to sign in — see the cookie banner shown to signed-out visitors for the pre-Account equivalent.
If you are in the EEA or UK and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office, ico.org.uk).
Where the CCPA/CPRA applies to us, California residents may have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, to request deletion of your personal information, and to be free from discrimination for exercising these rights. We do not sell or "share" personal informationas those terms are defined under the CCPA/CPRA. We may also choose to honor a similar request voluntarily, where reasonably practicable, even if the statute's applicability thresholds are not met. Our full CCPA/CPRA-specific notice — including a complete data-category table and the exact process to exercise these rights — is at Privacy Notice for California Residents. To exercise your rights, contact support@taskglaze.com.
Beyond California, a number of other US states have their own comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others that have since enacted similar legislation). Where one of these laws applies to you as a resident of that state, you generally have rights similar to those described in our California notice above: to know/access what personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of the sale of personal information or its use for targeted advertising or certain profiling — none of which we do in any case, as described throughout this Policy.
Global Privacy Control (GPC). Where required by applicable state law, we honor the Global Privacy Control browser signal as a valid request to opt out of the sale or sharing of personal information from the browser sending it. Since we do not sell or share personal information in the first place, honoring this signal does not change how we process your data — but we recognize it as a valid opt-out signal regardless, rather than ignoring it.
To exercise any state-specific privacy right, contact us at support@taskglaze.com; we will respond within the timeframe required by the applicable state law. If we decline to act on a request, you may appeal by replying to our decision, and if your appeal is unsuccessful, you may generally contact your state Attorney General.
The Service is intended for business and professional use by adults and is not directed at individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.
Some browsers offer a "Do Not Track" signal. Because there is no accepted industry standard for how to respond to it, we do not currently respond differently to browsers that send this signal. As noted above, we do not currently run third-party analytics or advertising trackers on the Service.
We may update this Privacy Policy from time to time. For material changes, we will provide reasonable advance notice (for example, by email or an in-app notice) before the changes take effect, and will update the "Last updated" date above. Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of it.
For any question about this Privacy Policy or to exercise a privacy right, contact BLUELINKS GROUP LTD, trading as Bluelinks Agency (operating TaskGlaze), at support@taskglaze.com.
Questions about this document?
Contact us at support@taskglaze.com and we'll get back to you within a few business days.
BLUELINKS GROUP LTD (company no. 16277222), 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF.