1. Introduction
Taski is primarily a native app (iOS, Android, Apple Watch). Cookies and similar technologies specifically concern the Web client (web.taski.chat) and this legal site (legal.taski.chat). The Desktop client (Tauri) uses local storage instead of HTTP cookies.
2. Technologies used
2.1 Strictly necessary cookies
On the Web client we use only strictly necessary cookies for the operation of the service. We do not have marketing, profiling, or third-party analytics cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| __cf_bm (Cloudflare) | Bot management and DDoS protection | 30 minutes |
| cf_clearance (Cloudflare) | Confirmation of passed anti-bot challenge | Session |
These cookies are automatically set by Cloudflare (our edge networking provider) and are necessary for the security of the service. They are exempt from prior consent under art. 122 of the Italian Privacy Code and art. 5(3) of the ePrivacy Directive.
2.2 Browser LocalStorage
The Web client uses the browser's localStorage for:
Keys (prefix taski_) | Content | Purpose |
|---|---|---|
| taski_token, taski_linked_session_id | Session token and linked session ID | Maintain login after refresh and identify the session in the "Linked devices" panel |
| taski_web_sync_*, taski_own_key_version, taski_key_rotation_*, taski_kt_last_sth | Synchronization cursors and technical state of keys and Key Transparency | Synchronize messages and verify key integrity |
| taski_messages | Cache of recent messages | Show conversations immediately on opening |
| taski_theme_preference, taski_webpush_*, taski_notify_when_focused, taski_read_receipts, taski_ai_optout, taski_recent_emojis, taski_sticker_recents, taski_stories_expanded | Preferences | Theme, notifications, privacy, TaskiAI, recent emoji and stickers, interface |
| taski_lock_failed_attempts, taski_browser_has_passkey, taski_last_direct_auth_method | App lock and sign-in state | Security of sign-in and of the passcode lock |
All this data remains on the user's browser and is not shared with third parties. It is deleted on voluntary logout (Settings → Log out) or when the site's data is cleared.
2.3 IndexedDB
For messages and media the Web client uses IndexedDB (browser-side database) to:
- Store the Web client's private encryption keys (
taski-keysdatabase), protected by the app lock if enabled - Store decrypted messages for fast access
- Keep a media cache (photos, videos) to avoid re-downloading them (
taski-media-cachedatabase, up to 500 MB; beyond this limit the oldest media are removed). Media are stored in encrypted form; the cache is separate for each account - Cache contact avatars and saved stickers
IndexedDB also remains on the user's browser, local to the web.taski.chat domain. On voluntary logout (Settings → Log out), keys, app lock and media cache are deleted. If instead the session is closed externally (revocation from the phone, session expiry), media stored in sealed form remain in the browser so that they can be reopened at the next sign-in with the same account; if a different account signs in on the same browser, they are deleted.
2.4 Service Worker
The Web client registers a Service Worker for:
- Push notifications (Web Push API + VAPID)
- Static resource caching (PWA-like, partial offline access)
- Bridge for local resolution of contact list names in notifications
2.5 Cloudflare Pages cookies (this site)
The site legal.taski.chat is hosted on Cloudflare Pages. Cloudflare may set technical cookies for security (__cf_bm) and DDoS prevention. We do not use analytics or tracking pixels on this site.
3. Third-party cookies
We do not use third-party cookies for analytics, profiling, retargeting or advertising (e.g. Google Analytics, Facebook Pixel, etc.).
4. How to manage cookies and storage
- Block cookies: browser settings (Chrome, Safari, Firefox, Edge). Blocking strictly necessary cookies may make the Web client unusable.
- Clear storage: Browser settings → Privacy → Clear browsing data → Select cookies + site data. Causes logout from the web session.
- In-app logout: from the Web client, Settings → Log out. Deletes token, private keys, app lock and media cache from the browser.
- Remote disconnection: from the phone, Settings → Linked devices → Revoke. Terminates the web session and invalidates the token server-side. Sealed media may remain in the browser cache (see 2.3): to remove them, use "Log out" in the browser or clear the site's data.
5. International transfers
Cloudflare technical cookies may involve data transfer to the global Cloudflare infrastructure, certified under the EU-U.S. Data Privacy Framework.
6. Changes
We may update this page if we add or remove storage technologies. The "Last updated" date will be updated.
7. Contact
Questions about cookies: [email protected]