Back to TaskGlaze

Privacy Policy

Effective date: July 20, 2026·Last updated: July 20, 2026

BLUELINKS GROUP LTD (company no. 16277222), registered office: 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency.

Your trust matters to us. This Privacy Policy explains exactly what data TaskGlaze collects, why, who we share it with (including the principal third-party providers we use, by name), precisely how long we keep it, and the rights you have over your own data. A summary table of contents is on the right — click any item to jump straight to it.

1.Introduction

This Privacy Policy explains how BLUELINKS GROUP LTD, a company registered in England and Wales under company number 16277222, whose registered office is at 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency and operating TaskGlaze ("Company", "we", "us", "our") collects, uses, discloses, and protects information when you visit taskglaze.com, use app.taskglaze.com, or otherwise interact with TaskGlaze (the "Service"). It should be read together with our Terms of Service and, if you are a business customer, our Data Processing Agreement. If you do not agree with this Policy, please do not use the Service.

2.Who we are

The data controller responsible for your personal data under this Policy is BLUELINKS GROUP LTD, a company registered in England and Wales under company number 16277222, trading as Bluelinks Agency and as TaskGlaze.

Registered office: 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF. This is also our correspondence address for data-protection matters. Our dedicated privacy contact is support@taskglaze.com.

3.When we are controller vs. processor

We act in two different roles depending on the data, and the responsibilities attached to each role are different:

  • We are the controller for your own Account data — your name, email, billing details, security logs, support correspondence, and how you use the Service — and for our own marketing. This Privacy Policy describes that processing directly, and we decide why and how it happens.
  • We are the processor — and you are the controller— for personal data you upload, import, or generate through the Outreach CRM or a connected mailbox about your own prospects, clients, or other contacts (see "Information about customer contacts and prospects" below), or personal data incidentally found while auditing a website you submit. We process that data only on your documented instructions, as set out in our Data Processing Agreement— you, not us, decide why and how it's used, and you're responsible for having a lawful basis to process it.

4.Information we collect

Account information. Name, email address, and password (stored as a bcrypt hash — we never store your password in plain text), or your Google account email/name if you sign in via Google. Optional profile fields such as company name and job title.

Billing information. Your billing name/email and subscription plan/status. Your payment card details are collected and stored directly by Stripe, our payment processor — we do not receive or store your full card number.

Service content. The websites, keywords, and domains you submit for audits, research, and backlink analysis; your Outreach CRM records (prospect contacts, notes, deal data); AI content workflow prompts and generated output; and any files or text you otherwise submit to the Service.

Connected email account credentials.If you connect a mailbox to the Outreach CRM, we store the SMTP/IMAP host, username, and password (or app-specific password, for providers like Gmail that require one when 2FA is enabled) you provide, encrypted at rest with AES-256-GCM. This feature uses direct SMTP/IMAP credentials, not an OAuth token — if your provider supports and requires an app-specific password instead of your primary account password, use that. We use these credentials only to send and retrieve mail at your explicit instruction, as described in "Connected email accounts" below.

Usage & device data. Log data such as IP address, browser/device type, pages visited, and actions taken in the Service, collected automatically for security, debugging, and abuse-prevention purposes.

Communications. Any information you provide when you contact support or otherwise correspond with us.

5.How we collect information

  • Directly from you — when you register, subscribe, submit content, connect a mailbox, or contact support.
  • Automatically — through cookies, session identifiers, and server logs as you use the Service (see "Cookies" below).
  • From third parties — for example, Google provides your name/email when you sign in with "Continue with Google", and Stripe provides billing/subscription status back to us after checkout.

6.How we use your information

  • To create and administer your Account, authenticate you, and provide the features of your Plan;
  • To process payments, manage subscriptions, and send billing-related communications;
  • To run the audits, research, AI generations, and outreach sends you request, and to store the resulting data in your Account;
  • To monitor, secure, debug, and improve the Service, including detecting and preventing fraud, abuse, and security incidents;
  • To respond to support requests and communicate with you about the Service;
  • To comply with legal obligations.

7.Types of communications we send

We separate what we send you into two categories, because they have different rules:

  • Essential/transactional — email verification, password reset, security alerts, billing/subscription notices (payment succeeded/failed, renewal reminders), and critical service updates. These are necessary to operate your Account and do not depend on marketing consent— you can't opt out of them while keeping an active Account, the same way a bank can't stop telling you about a failed payment.
  • Product announcements & promotional marketing — new-feature announcements, tips, and similar optional communications. These are sent on a legitimate-interest or consent basis as applicable in your jurisdiction, and every such email includes an unsubscribe link — opting out never affects your access to the Service itself.

9.Cookies & similar technologies

We use the following cookies and browser-storage technologies. This table is exhaustive for our own domain — nothing else sets a cookie on taskglaze.com or app.taskglaze.com:

NameSet byPurposeCategoryExpiry
__Secure-authjs.session-tokenTaskGlaze (Auth.js)Keeps you signed inAuthentication7 days
__Host-authjs.csrf-tokenTaskGlaze (Auth.js)Cross-site request forgery protection on sign-inAuthenticationSession
__Secure-authjs.callback-urlTaskGlaze (Auth.js)Remembers where to send you after signing inAuthenticationSession
tg_consentTaskGlazeRemembers your cookie-notice choice so we don't ask again on this browserPreferences1 year
theme (browser local storage, not a cookie)TaskGlazeRemembers your light/dark display preferencePreferencesUntil cleared
Turnstile challenge cookiesCloudflareConfirms you're not a bot on sign-up/login/password-reset formsSecurity & fraud preventionShort-lived (set only on those specific forms)
Stripe checkout cookiesStripePayment processing during checkoutFeatures & servicesSet only on Stripe's own checkout.stripe.com page, after you're redirected there — never on our domain

Everything above except the theme preference (functional) is strictly necessary— required for sign-in, security, or a choice you explicitly made — and none of it depends on the cookie-consent banner's outcome; the banner itself governs only whether we'd be allowed to add anything beyond this list in the future. We do not currently run any third-party analytics or advertising trackers on the Service. If we introduce any, this table and our cookie banner will be updated first, and — where legally required — the new cookie will only load after you affirmatively consent. Turnstile and Stripe cookies are set only on the specific pages that need them (sign-up/login/password-reset, and Stripe's own hosted checkout page respectively) — never loaded site-wide.

You can control cookies through your browser settings; blocking strictly-necessary cookies will prevent you from being able to sign in. This same table is also maintained as its own page at Cookie Policy.

10.How we share your information

We do not sell your personal information.This Policy identifies the principal third-party providers ("Subprocessors") that may process personal data to operate the Service, and only to the extent needed for the purpose described:

ProviderPurposeWhat they seeLocation
StripePayment processing & subscription billingBilling name/email, payment method (tokenized by Stripe — we never see your full card number)United States
ResendTransactional email delivery (verification, password reset, notifications)Your email address and the content of the transactional emailUnited States
DataForSEOKeyword, backlink, and SERP data that powers audits, keyword research, and backlink analysisThe domains/keywords you research — not your personal account dataUnited States
OpenRouter (and the underlying AI model providers it routes to, e.g. Anthropic and other model vendors)Generating AI Output for the AI content workflow and AI-drafted outreach emailsThe prompt/content you submit for that specific generation requestUnited States (routes to multiple underlying providers)
Google (OAuth, and Google Ads API where enabled)"Continue with Google" sign-in, and Google Ads keyword-volume data for keyword researchYour Google account email/name (OAuth) or the keywords you research (Ads API)United States
CloudflareBot / abuse protection (Turnstile) on sign-up, login, and password-reset formsBrowser/device signals used to verify you are not a bot — no personal profile is builtUnited States (global network)
HetznerCloud server hosting for the application and databaseAll data described in the Privacy Policy, as stored on our serversGermany (EU)
Google DriveOff-site storage of encrypted, full-system backups (including a database backup) for disaster recoveryEncrypted backup archives only — not readable by Google, or by anyone without our separately-held encryption keyUnited States

Subprocessor changes.If we add a new Subprocessor or replace an existing one in a way that materially changes how your data is handled, we will update this table and the "Last updated" date above; business customers are additionally entitled, under our Data Processing Agreement, to advance notice and a 14-day window to raise a reasonable data-protection objection. Copies of the safeguards referenced in "International data transfers" below are available on request at support@taskglaze.com.

We may also disclose information where required by law, to enforce our Terms of Service, to protect the rights, property, or safety of the Company, our users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case we will require the successor to honor this Policy for previously collected data).

11.Connected email accounts

The Outreach CRM lets you optionally connect your own mailbox to send and receive outreach correspondence. This is a sensitive integration, so we handle it deliberately:

  • Your mailbox password/credentials are encrypted at rest (AES-256-GCM) and are never displayed back to you or any other user in plain text after you save them.
  • We connect to your mailbox only to perform actions you explicitly trigger — sending a message you composed or scheduled, or checking for new replies.
  • Reply-checking opens your inbox using the IMAP EXAMINE command (read-only mode) — under this mode the mail server itself will not allow any flag or state change for the duration of the connection, so a message is never silently marked read, moved, or altered. We never issue an IMAP move, copy, flag, or delete command against your mailbox at all — this is a hard guarantee in how the feature is built, not just a policy promise.
  • Email content sent or received through a Connected Account is stored in your Account so it can be shown to you in the Service's inbox and reporting views; it is not used for any purpose beyond providing the Service to you.
  • You can disconnect a mailbox at any time from your account settings. The stored password is deleted immediatelyon disconnection — it is not retained "just in case". The disconnected account record itself (email address, which messages were sent through it) is kept, without the credential, so your Sent-mail history stays intact; it is deleted for good if you delete your Account. A copy of the credential may exist briefly in an already-taken encrypted backup until that backup ages out of our rolling backup-retention schedule (see "Data retention").

12.Information about customer contacts and prospects

Our customers use the Outreach CRM to store and contact business prospects, clients, and other contacts — individuals who have never created a TaskGlaze account and, in most cases, have never interacted with us directly. Depending on what a customer chooses to store, this can include a contact's name, work email, job title, employer, website, outreach history, email replies, notes, and deal status.

As explained in "When we are controller vs. processor" above, our customer is the data controller for this data, and we act only as their processor— we store and transmit it on that customer's instruction, and it is the customer, not us, who determines why and how that information is used.

Where applicable law requires notifying an individual that their data is held when it wasn't collected directly from them (for example, Article 14 GDPR's transparency requirement, which generally must be satisfied within a reasonable period and no later than one month, unless an exemption applies), that obligation belongs to our customer as controller, not to us. Our Data Processing Agreementsets out this allocation of responsibility in full, along with our own security and sub-processing obligations as processor. If you are a contact who was added to a TaskGlaze customer's Outreach CRM and have a question about your data, please contact that business directly; if you're unsure who that is, contact us at support@taskglaze.comand we will do our reasonable best to help identify the right customer, or to honor a suppression/opt-out request directly — see "Outreach CRM & connected email accounts" in the Terms of Service for how opt-outs are enforced platform-wide.

13.AI processing disclosure

When you use an AI-assisted feature (content briefs, drafts, meta tags, idea generation, or AI-drafted outreach emails), the relevant prompt and supporting content is sent to our AI infrastructure provider, OpenRouter, which routes the request to a third-party AI model provider to generate the response. Depending on the feature, this may include models from more than one provider; you do not currently choose the specific model — we select it per feature based on suitability and cost. The prompt/content is transmitted for the sole purpose of generating your requested output and, on our side, is not logged or retained beyond what's needed to return the response and to maintain your own generation history within your Account.

Do OpenRouter or the underlying model providers retain or train on your prompts? We do not use your Content to train any TaskGlaze-owned model — we don't operate our own model at all. Whether OpenRouter or a specific underlying model provider temporarily logs, retains, or uses your prompt to improve their own models depends on that provider's own policy and our commercial terms with them, which can differ by provider and may change over time. We select providers and configure our account to request the strongest available no-retention / no-training terms where a provider offers them, but we cannot guarantee a uniform practice across every provider our AI features may route to.

Do not submit special-category or otherwise sensitive data.You must not submit special category personal data (e.g. health, biometric, or similar sensitive personal data), financial account numbers or payment credentials, authentication secrets (passwords, API keys, tokens), or other confidential/restricted information into any AI prompt, unless expressly authorized by us in writing. AI Output should always be reviewed before use — see the Terms of Service's "AI-generated content" section.

14.International data transfers

Our application and database servers are hosted with Hetzner in Germany (EU). Some of our Subprocessors (for example, Stripe, Google, and certain AI model providers accessed through OpenRouter) are based in, or process data in, the United States or other countries outside the EEA/UK. Where that happens, we rely on one of the following safeguards, as applicable to the specific provider and transfer: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; the EU Standard Contractual Clauses on their own (for EU-originating transfers); the provider's certification under the EU–US Data Privacy Framework and, where applicable, the UK Extension to the EU–US Data Privacy Framework; or applicable UK adequacy regulations for the destination country. A copy of the specific mechanism used for a given Subprocessor is available on request at support@taskglaze.com.

15.Data retention

We keep personal data only for as long as needed for the purposes described in this Policy. The table below states the actual retention period or purge mechanism for each category — these match our real systems, not general placeholders:

DataRetention period
Active Account & Service dataDuration of your Account
Cancelled/locked Account data (trial expired or subscription ended)Retained, fully exportable, until you request deletion — see "Account data export & deletion"
Soft-deleted Outreach CRM / Mail records (prospects, conversations)30-day recovery window, then automatically and permanently purged
Mailbox credentials (Connected Accounts)Deleted immediately on disconnection; otherwise retained only while the mailbox stays connected
Outreach email content (sent/received through a Connected Account)Until you delete the record or delete your Account
Account deletion (on verified request)Completed within 30 days of your request
Suppression / unsubscribe recordsRetained indefinitely, independent of the underlying record or Account, to honor opt-outs and prevent re-contact
Encrypted server backupsWeekly backups: ~5 weeks rolling. Monthly backups: 12 months rolling
Security logs (login/auth/abuse events)14 days
Billing & invoice records6 years, to comply with UK tax/accounting record-keeping law
Support correspondenceUp to 2 years

Backups are encrypted, used solely for disaster recovery, and are not indexed or searchable outside of a genuine restore event.

16.Account data export & deletion

To request an export or deletion of your Account data, email support@taskglaze.com. There is currently no self-service "export"/"delete my account" button in the Service — both are handled as a verified request to this address, and we aim to complete either within 30 days.

Export includes your Account/profile data, project and audit history, Outreach CRM records (including prospect/contact data, subject to your own obligations to those individuals as controller), and email history sent/received through a Connected Account, provided as structured data (e.g. CSV/JSON) covering the categories you request.

Deletionremoves your Account and the data categories above, except: suppression/opt-out records (kept indefinitely, see "Data retention"), billing records we're legally required to retain (6 years), and any copy still present in an already-taken encrypted backup until it ages out of our rolling backup-retention schedule (weekly: ~5 weeks, monthly: 12 months) — we cannot selectively edit a completed backup archive, only let it expire on schedule.

17.Data security

We apply industry-standard technical and organizational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS) for all traffic to the Service;
  • Passwords hashed with bcrypt — never stored or logged in plain text;
  • Sensitive secrets (two-factor authentication seeds, connected-mailbox credentials) encrypted at rest with AES-256-GCM;
  • Optional two-factor authentication (TOTP) available on every Account at no extra cost;
  • Account-lockout and rate-limiting protections against automated login/password-guessing attempts;
  • Administrative access to customer data is restricted to designated staff accounts, gated by an admin-only flag and mandatory two-factor authentication on that access.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify affected users and relevant authorities as required by applicable law.

18.Automated decision-making

We do not carry out decision-making based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR / UK GDPR. Some account-administration actions are automated (for example, a trial automatically moving to a locked, read-only state at the end of its 14-day period) — these are routine contract-administration steps applied uniformly by Plan rules, not profiling or a decision made about you individually, and you can always contact support@taskglaze.com about any account-status question.

19.Your privacy rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure — request deletion of your data (see "Account data export & deletion");
  • Restriction of, or objection to, certain processing — including an unconditional right to object to processing for direct marketing at any time;
  • Portability — receive a structured, commonly-used copy of data you provided to us, where our processing is based on your consent or on performance of a contract and is carried out by automated means (this right does not apply to every category of data we hold — for example, it doesn't extend to data processed under a legitimate-interest basis);
  • Withdraw consent at any time, where processing is based on consent (for example, non-essential cookies or promotional marketing) — this does not affect the lawfulness of processing carried out before you withdrew it.

You can access and update most Account information directly from your account settings, or exercise any of the above rights by emailing support@taskglaze.com — this is also our dedicated contact for data-protection requests. We will respond within the timeframe required by applicable law (generally within 30 days). We may need to verify your identity before actioning a request.

Consent record for signed-in accounts. Creating an Account requires agreeing to this Policy and our Terms of Service; that acceptance is recorded once, permanently, on your Account at signup (not just as a browser cookie), so it carries across every device you use to sign in — see the cookie banner shown to signed-out visitors for the pre-Account equivalent.

If you are in the EEA or UK and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office, ico.org.uk).

20.California privacy rights (CCPA/CPRA)

Where the CCPA/CPRA applies to us, California residents may have the right to request disclosure of the categories and specific pieces of personal information we have collected about you, to request deletion of your personal information, and to be free from discrimination for exercising these rights. We do not sell or "share" personal informationas those terms are defined under the CCPA/CPRA. We may also choose to honor a similar request voluntarily, where reasonably practicable, even if the statute's applicability thresholds are not met. Our full CCPA/CPRA-specific notice — including a complete data-category table and the exact process to exercise these rights — is at Privacy Notice for California Residents. To exercise your rights, contact support@taskglaze.com.

21.Other US state privacy rights

Beyond California, a number of other US states have their own comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others that have since enacted similar legislation). Where one of these laws applies to you as a resident of that state, you generally have rights similar to those described in our California notice above: to know/access what personal information we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of the sale of personal information or its use for targeted advertising or certain profiling — none of which we do in any case, as described throughout this Policy.

Global Privacy Control (GPC). Where required by applicable state law, we honor the Global Privacy Control browser signal as a valid request to opt out of the sale or sharing of personal information from the browser sending it. Since we do not sell or share personal information in the first place, honoring this signal does not change how we process your data — but we recognize it as a valid opt-out signal regardless, rather than ignoring it.

To exercise any state-specific privacy right, contact us at support@taskglaze.com; we will respond within the timeframe required by the applicable state law. If we decline to act on a request, you may appeal by replying to our decision, and if your appeal is unsuccessful, you may generally contact your state Attorney General.

22.Children's privacy

The Service is intended for business and professional use by adults and is not directed at individuals under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.

23.Do Not Track

Some browsers offer a "Do Not Track" signal. Because there is no accepted industry standard for how to respond to it, we do not currently respond differently to browsers that send this signal. As noted above, we do not currently run third-party analytics or advertising trackers on the Service.

24.Changes to this Policy

We may update this Privacy Policy from time to time. For material changes, we will provide reasonable advance notice (for example, by email or an in-app notice) before the changes take effect, and will update the "Last updated" date above. Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of it.

25.Contact us

For any question about this Privacy Policy or to exercise a privacy right, contact BLUELINKS GROUP LTD, trading as Bluelinks Agency (operating TaskGlaze), at support@taskglaze.com.

Questions about this document?

Contact us at support@taskglaze.com and we'll get back to you within a few business days.

BLUELINKS GROUP LTD (company no. 16277222), 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF.