1. What is TaskiAI
TaskiAI is an optional AI assistant integrated into Taski, available in two distinct modes:
- Inline mode (
@TaskiAI): explicitly invokable in 1-1 chats with other people (disabled in groups). Replies are visible to both chat participants. Covered by sections 2-15 of this document. - Dedicated chat mode: a private 1-1 chat between the user and the assistant, accessible from the chat list (entry "Taski AI"). No third party is involved: messages and replies are visible only to the user. Covered by section 16.
In both modes the service is provided by Anthropic via the Claude Sonnet 5, Claude Opus 4.7 and Claude Haiku 4.5 models (see section 6), and by OpenAI (gpt-image-2.5-flare) for image generation and retouching when explicitly requested by the user.
Many of the usage limits described in this document (messages, images, web searches, voice calls) vary depending on the account's plan: Free or Taski Plus (paid subscription). Where applicable, this document states both values.
2. Exception to the E2EE model
Important. TaskiAI is the only feature that, when activated, makes an exception to the end-to-end E2EE model. To answer the user's question, an external AI service must be able to read the conversation context. All other activity in Taski (messages, calls, media) remains end-to-end encrypted and unreadable to us and third parties.
3. What is shared with Anthropic
The following data is transmitted to the AI provider only upon explicit invocation of @TaskiAI:
- Last 20 messages of the current conversation, decrypted only in transit. If these include locations, the model also receives the related coordinates: for live location, only the starting point and duration stated in the start message, never subsequent updates; for the "Trusted contact" feature, the location requests and the point sent in reply by the phone of the person who received them (with accuracy, time of the reading and battery level).
- Maximum 3 recent photos from the context, compressed to 768px and described in text by Claude Haiku 4.5. Generated captions are cached for 14 days per conversation to avoid expensive re-processing.
- The user's display name to correctly attribute the request.
- The explicit question written after
@TaskiAI.
The "Explain" and "Suggest" long-press actions send the selected message and, as context, the same last 20 messages, locations included.
4. What we do NOT do
- ❌ The server never archives the plaintext of context messages or photos at rest. It only sees them in transit, like a proxy. (The exceptions are AI replies and AI-generated or retouched images, see sections 11 and 14.)
- ❌ Anthropic does not use user data to train its models (Anthropic contractual policy).
- ❌ TaskiAI is never automatically invoked: only when the user writes
@TaskiAIor uses the "Ask TaskiAI" actions from long-press on a message. - ❌ No photo is sent if there are none in the 20 recent messages.
- ❌ In groups TaskiAI is disabled by design: the decision to share context must be unanimous, and maintaining bilateral consent is too fragile in a group.
5. Per-chat memory
TaskiAI can remember relevant facts that emerge in the conversation (e.g. "Stefano is celiac") to make subsequent answers more useful.
- Per-chat scope: facts from one conversation are never visible in others. Memory is isolated by (user, chat).
- Local storage + encrypted sync: facts are saved on the user's device (SwiftData on iOS, IndexedDB on Web, local file on Android) and synced across the user's devices via Cloudflare KV in end-to-end encrypted AES-256-GCM form. The key is derived from the user's private key via HKDF (salt = SHA256(convId), info = "taski-ai-memory:v1"). The server only stores encrypted data it cannot read.
- Automatic extraction: Claude Haiku 4.5 extracts facts from the context after each response. Cap: 50 facts / 2KB per chat with deterministic score-based compaction.
- Explicit commands: "remember that..." adds a fact with userStated flag (excluded from auto-compaction). "forget..." removes a fact.
- Full control: the user can disable memory, view and delete individual facts from the chat Profile → TaskiAI Memory.
- Lifetime of the synced copy: the encrypted copy on Cloudflare KV expires after 90 days without updates.
6. Models used
- Claude Sonnet 5 (Anthropic): conversational responses, inline commands, "Explain" action, translation with AI Rewrite, decision to invoke the image generation and retouching tools.
- Claude Opus 4.7 (Anthropic): advanced reasoning, used only when explicitly requested by the user (e.g. "think harder", "use a more powerful model") and within the dedicated daily quota (see section 13).
- Claude Haiku 4.5 (Anthropic): short or simple replies in the dedicated chat, Translate/Correct/Suggest quick actions, AI Rewrite (except translation), fact extraction for memory, context photo description, moderation double-check, post-voice-call memory extraction (see section 16.5).
- gpt-image-2.5-flare (OpenAI, with gpt-image-2 as fallback): image generation and retouching when explicitly requested by the user (see section 14).
- gpt-image-2.5-flare and gpt-image-1 (OpenAI): AI stickers (see section 18).
- gpt-realtime-2.1 + gpt-4o-mini-transcribe (OpenAI Realtime API): full-duplex voice call with the dedicated chatbot (see section 16.5).
- Tavily: web search during the voice call with the dedicated chatbot (see section 16.5).
The actual model may vary over time to improve quality or reduce costs, always within the providers listed above (Anthropic for language models, OpenAI for images and realtime voice, Tavily for voice web search).
7. Opt-out
TaskiAI can be disabled completely in:
- iOS: Settings → Privacy → TaskiAI
- Android: Settings → Privacy → TaskiAI
- Web/Desktop: Settings → Privacy → TaskiAI
When even just one of the participants of a 1-1 chat has opt-out enabled, @TaskiAI mentions in that chat are rejected by the server.
8. Mandatory pre-invocation disclosure
The first time TaskiAI is invoked in a chat, the app shows a disclosure screen explaining what is about to be shared (including the update of the 20 messages and 3 photos). The user must confirm to proceed. The confirmation is stored locally; if we update the sharing terms (e.g. the number of messages or photos changes), the disclosure is shown again.
9. UX: skip push of the user message
When the user sends @TaskiAI ..., the other participant does not receive the push notification of that message (so they are not spammed). They only receive the push of the AI response, with TaskiAI's dedicated avatar. This reduces noise in the shared chat.
10. Contact list context in the prompt
To allow TaskiAI to refer correctly to participants, the 20 context messages are passed to the model with names from the device's address book (resolved locally on the user's device before sending) instead of numeric userIds. This improves the quality of the answers but means that Anthropic sees the names as they appear in the user's contact list.
11. Data retention
- Context messages: not persisted by the Taski server. To reduce latency and costs, Anthropic may temporarily keep them in cache (prompt caching) for a maximum of 1 hour, after which they are discarded; they are not used for training.
- Photos: not persisted. Only the generated captions (text) are cached for 14 days per chat in Cloudflare KV.
- AI responses: persisted normally in the chat messages (visible to both participants, with "✨ TaskiAI" label). They are not E2EE encrypted because the server generated them; they are protected by TLS in transit and encryption at rest.
- Memory: on the user's device (see section 5). KV ciphertext-only sync if active.
12. AI Sub-processors
AI data is processed by three distinct sub-processors, each for a specific task:
- Anthropic (Claude Sonnet 5 / Opus / Haiku 4.5): conversational responses, memory extraction, context photo description, moderation double-check, decision to invoke the image generation tool.
- Privacy Policy: anthropic.com/legal/privacy
- Acceptable Use Policy: anthropic.com/legal/aup
- Commercial Terms: anthropic.com/legal/commercial-terms
- OpenAI: several distinct uses.
- gpt-image-2.5-flare (fallback gpt-image-2) — image generation when the user explicitly requests it. Receives only the text prompt constructed by Claude (in English, max 1000 characters), not the original chat messages or photos.
- gpt-image-2.5-flare (fallback gpt-image-2) — photo retouching on explicit request. Receives the photo to be edited and the editing instructions (see section 14.1).
- gpt-image-2.5-flare / gpt-image-1 — AI stickers, including the source photo in "photo → sticker" mode (see section 18).
- gpt-realtime-2.1 + gpt-4o-mini-transcribe (Realtime API) — full-duplex voice call with the dedicated chatbot. Receives streaming PCM16 audio, the transcripts generated for turn-detection, any photos the user sends during the call (max 768px, JPEG) and an initial system prompt with user name, current date/time and the chatbot's local memory. When the call is started from the dedicated chat, the system prompt also includes the last 5 text messages from that chat as passive reference context (the AI knows them but won't bring them up unless the user explicitly references them). Details in section 16.5.
- Privacy Policy: openai.com/policies/privacy-policy
- Business Terms: openai.com/policies/business-terms
- Tavily: web search during the voice call with the dedicated chatbot. Receives only the search query formulated by the AI (max 400 characters) and the country inferred from the language, without user identifiers.
- Privacy Policy: tavily.com/privacy
The non-Anthropic/OpenAI providers used for moderation and fallback (Cloudflare Workers AI: Llama Guard 3, Flux Schnell) also operate only in the cases described in the Privacy policy and in the Acceptable use policy.
13. Limitations and liability
- Probabilistic: TaskiAI can be wrong. Answers do not replace professional medical, legal, or financial advice.
- No persistent training: Anthropic states that it does not train models on data transmitted via the API for service purposes. However, in case of security or legal requests, transient data may be analyzed to identify abuse.
- No warranty: the service is in beta and provided "as is".
Rate limits (inline mode)
@TaskiAImessages: Free 5 per day · Plus 30 per day per user (server-side cap, rolling 24h window).- "Ask TaskiAI" long-press actions (Explain, Translate, Correct, Suggest): Free 5 per day · Plus 30 per day per user.
- AI Rewrite (draft rewriting, see section 18): Free 5 per day · Plus 30 per day per user.
- Advanced reasoning (Claude Opus): Free 1 per day · Plus 5 per day per user. Cap shared with the dedicated chat mode (section 16.8).
14. Image generation
When the user invokes TaskiAI with an explicit request to generate an image (e.g. "@TaskiAI draw me a sunset"), Claude Sonnet 5 may call an internal generate_image tool that produces the image through a second AI provider.
What is shared with OpenAI (generation)
- Only the text prompt, constructed by Claude in English (max 1000 characters), enriched with relevant details from the chat context (subject, style, mood).
- Never sent to OpenAI: original chat messages, photos, user identities, conversationId, userId.
- Style + aspect ratio chosen by Claude from a predefined set.
Where the generated image is stored
- The image is saved in the Cloudflare R2 bucket at path
ai-generated/{conversationId}/{messageId}.jpgin plaintext (not end-to-end encrypted). - Served to participants via signed URL HMAC-SHA256 valid for 7 days and not renewable.
- Visible to both participants of the 1-1 chat, exactly as for AI text responses (section 11).
Retention and deletion
- 7 days from generation, as for other content that is not end-to-end encrypted. Automatic cleanup via daily cron at 2 AM UTC.
- The user can manually save the image to their device gallery before expiry by tapping the image in chat.
- Once expired on R2, the image is no longer retrievable from the server, but remains visible locally on devices that have cached it.
Usage limits
- Free: 2 images per day · Plus: 10 per day per user (global server-side cap, shared between inline mode and dedicated chat and between generation and retouching — see 14.1 and 16.4). The counter resets every day at midnight UTC.
- If the limit is reached, a locally generated informational bubble notifies the user. No request is sent to OpenAI.
E2EE exception
Generated images are not end-to-end encrypted because the server produces them. They are nonetheless protected by TLS in transit and encryption at rest (Cloudflare R2 server-side encryption). This is an unavoidable consequence of the AI feature, analogous to section 2 (Exception to the E2EE model).
14.1 Photo retouching
The user can ask TaskiAI to edit a photo (e.g. "@TaskiAI remove the background from this photo"). In this case Claude may call the internal edit_image tool, which modifies the pixels of the actual photo via OpenAI.
- Which photo: in inline mode, the most recent photo in the chat context is used, which may also have been sent by the other participant. In the dedicated chat, the photo attached by the user is used.
- What OpenAI receives: the photo (decrypted on the device and sent in cleartext to the Taski server, protected by TLS in transit, and from there to OpenAI) and the editing instructions. It does not receive chat messages, user identities, conversationId or userId.
- Result: the edited photo is saved in cleartext (not end-to-end encrypted) on Cloudflare R2 and shown in the chat like generated images: in inline mode it is visible to both participants for 7 days, in the dedicated chat for 24 hours.
- Quota: each retouch uses one generation from the image quota (Free 2 · Plus 10 per day).
- Responsibility: the user must have the right to edit the photo and must respect the image and dignity of the people depicted (see Acceptable use policy).
15. Web search
When the user asks a question that requires fresh or recent information (weather, opening hours, current prices, today's news, recent events), Claude Sonnet 5 may autonomously decide to invoke a web search tool provided by Anthropic to retrieve information from the public web.
What is sent
- The search query formulated by the model based on the user's question, typically in English to optimize the search engine's result quality (e.g. "weather forecast May 5 2026"). The query is generated by the model, not written by the user, and does not include the user's precise location: only the country (IT) and timezone (Europe/Rome) are passed to the tool as localization parameters.
- The model receives up to 5 results per query (title, URL, preview snippet, page content).
- Results are included as input in the next Claude turn to produce the final reply, which cites the consulted sources.
Provider and localization
Web search is executed server-side by Anthropic via their web_search tool (Brave Search engine). Requests are localized to Italy by default (country: IT, timezone: Europe/Rome).
Limits and caps
- Maximum 2 searches per question turn (server-side cap enforced on the model).
- Free: not available (0 searches/day) · Plus: 15 searches per day per user (server-side cap, rolling 24h window). On Free accounts the tool is never exposed to the model; on Plus, once the daily cap is reached, Claude will reply from its training knowledge without searching until reset.
- The iOS client mirrors the cap for pre-empt UX: queries that look like web-search requests (keywords "search", "today", "tomorrow", "weather", "how much") are blocked locally when the cap is exhausted, avoiding wasted server calls.
Retention and privacy
- Search queries and results follow the same zero-retention agreement with Anthropic as section 11: no training, no logs beyond what is needed for the response.
- Taski does not log search queries, only an aggregate counter to enforce rate limit (KV key
ai-websearch:userIdwith 24h TTL, holds only a number). - Citations in the final reply (URLs and titles of consulted sites) are visible to both the user invoking
@TaskiAIand the other participant of the 1-1 chat (same as the AI reply text).
16. Dedicated chat with TaskiAI (chatbot)
In addition to the inline @TaskiAI invocation described above, a private 1-1 chat with the assistant is available, reachable from the chat list under "Taski AI". It is a conversation between the user and the model, separate from any other chat: no third party sees or receives it.
16.1 What is shared with Anthropic
The following data is transmitted to the AI provider only during the active conversation:
- The text history of the dedicated chat (the user's messages and the assistant's replies).
- Photos and PDF documents the user explicitly uploads in the chat (via the attachments button). Photos (resized) and PDFs are sent as files to the response model, which reads them directly.
- The dedicated chat's persistent memory (see 16.3), included in the system prompt as context.
- The user's display name, current date and time to personalize responses.
Messages from the user's other chats (1-1 with other people, groups, etc.) are never transmitted to the chatbot. The dedicated chat is isolated from all other Taski activity.
16.2 Exception to the E2EE model
As with the inline mode (section 2), the dedicated chat is not end-to-end encrypted: the server must forward content to the AI provider to generate replies. Messages in the dedicated chat (the user's questions and the AI's replies) are kept on the server in cleartext for up to 7 days, to provide the model with the conversation context; attachments are not retained. The chat is protected by TLS in transit and at-rest encryption. All other Taski activity (chats with other people, calls, media) remains E2EE.
16.3 Local persistent memory
- Local storage, E2EE-encrypted sync: the dedicated chat's memory is stored locally on the user's device. Where it is synced across the user's devices, this happens exclusively in end-to-end encrypted form (AES-256, key derived from the user's private key): the server only stores encrypted data it cannot read. The dedicated chat and its memory are available on iPhone, Android, Web and Desktop; Apple Watch has no access to it.
- Capacity: a limited number of facts per chat, with deduplication and automatic space management.
- Automatic extraction: Claude Haiku 4.5 extracts relevant facts after each assistant reply (skipped when attachments are present, for latency).
- Explicit commands: "remember that…" forces an addition, "forget…" removes a specific fact.
- Full control: from the dedicated chat screen the user can open "TaskiAI Memory", view the full list, delete individual facts or clear everything.
- Transmission to server: at invocation the memory is sent to the server as part of the prompt (needed by the AI model to respond) and is not stored in cleartext at rest by the Taski server (Anthropic may keep it in cache for max 1 hour, see section 11); any multi-device synchronization happens only in end-to-end encrypted form (see above).
16.4 Image generation
When the user explicitly requests an image (e.g. "draw me…"), the chatbot can call the same generate_image tool described in section 14, with these differences:
- Usage limit: Free 2 images per day · Plus 10 per day — same shared counter as the inline mode (section 14): this is not an additional limit, it is the same daily cap per user regardless of where the image is generated.
- Storage: images are saved in the Cloudflare R2 bucket at
ai-chatbot/{userId}/{messageId}.jpg, in clear (not end-to-end encrypted), with a 24-hour TTL. - Local cache: after generation, the app downloads and keeps a local copy of the image on the device, which is preserved even after the R2 expiration. The user can save the image to the camera roll, share it or copy it via long-press.
- What OpenAI receives: identical to section 14 — only the text prompt built by Claude (max 1000 characters, in English), not the chat history or other photos. For retouching an attached photo, section 14.1 applies.
16.5 Voice call with the chatbot
From the dedicated chat screen, the user can start a full-duplex voice call with TaskiAI by tapping the phone icon in the header. The conversation runs in real time over the OpenAI Realtime API; the Taski server acts as a WebSocket proxy between the user's device and OpenAI, without storing the audio.
What is shared with OpenAI during the call
- Microphone audio in PCM16 mono 24 kHz format, streamed continuously for the duration of the call.
- Transcripts generated by
gpt-4o-mini-transcribe(user input) and by thegpt-realtime-2.1model (AI response) to allow natural interruptions and turn-detection (Server VAD). - Photos sent by the user during the call: from the app, via the camera button, the user can take a photo or pick one from the gallery and send it to the AI while the call is ongoing. The photo is resized to max 768px (longest edge), JPEG-compressed and sent to OpenAI as
input_imageon the Realtime channel with low detail. The AI can see and comment on it by voice. The client allows one photo at a time (a second send is blocked until the receipt of the previous one is acknowledged); there is no numeric per-call cap. No photo is sent automatically: every send requires an explicit user action. - Initial system prompt: contains the user's name, current date/time, the reduced capabilities active during the call and the local persistent memory of the chatbot (section 16.3) as context.
- Last 5 messages from the text chat (only if the call is started from the dedicated chat): to enable conversational continuity between text and voice modes, when the user starts the voice call by tapping the phone icon in the dedicated chat header, the device sends to the server the last 5 text messages of that chat (role + text, max 1900 characters per message). The server embeds them in the session
instructionsas a "RECENT TEXT CHAT CONTEXT (PASSIVE BACKGROUND REFERENCE ONLY)" block with explicit rules for the model: do not bring up these topics on its own, do not summarize them in the greeting, wait for the user to speak first, use them only if the user explicitly references them. If the user starts the call from a different entry point (iOS Recents, widget, etc.) no context message is sent. The 5 messages do not become turns of the voice conversation and do not flow into the transcripts passed to Claude Haiku 4.5 for post-call memory extraction.
Assistant voice
The AI speaks with OpenAI's "marin" voice (multi-language auto-match). The selection is fixed server-side and not user-configurable.
Reduced capabilities during the call
In voice mode TaskiAI cannot generate images or produce PDFs/documents: for those the user is redirected to the text chat after the call ends. It can: receive photos from the user during the call (see above) and comment on them by voice; create memos and schedule messages via dedicated tools; search the web (see below). The persistent memory is shared between the two modes.
Web search during the call
When up-to-date information is needed (news, weather, opening hours, prices), the AI can run a web search via Tavily, announcing it by voice. Only the query formulated by the AI (max 400 characters) and the country inferred from the language are sent to Tavily, without user identifiers. Maximum 3 searches per call. Taski does not retain the queries.
Post-call memory extraction
At the end of the call, the accumulated transcripts (cap 8000 characters) are sent once to Claude Haiku 4.5 (Anthropic) to extract any relevant facts to add to the user's local persistent memory (section 16.3). Facts are applied on the device via WebSocket. Transcripts are not persisted at rest by the Taski server.
Data retention
- Audio: never persisted — only in transit through the Taski → OpenAI WebSocket proxy.
- Photos sent during the call: never persisted on the Taski server. Transmitted to OpenAI inside the Realtime message and then discarded. On the user's device they remain in the local player cache only if the user took them from the in-app camera.
- Transcripts: kept in the Durable Object's memory during the session (cap 8000 characters, FIFO). At the end they are (a) sent to Claude Haiku 4.5 for memory extraction and (b) aggregated into a single TaskiAI message formatted as
*You:* ... *TaskiAI:* ...inserted in the dedicated chat and shown to the user as a normal message. Like the other messages in the dedicated chat, this message remains on the server for up to 7 days (see 16.9). - OpenAI may transiently retain audio and transcripts as per its own policy. OpenAI states that it does not train models on API data for service purposes.
- "Call ended" bubble: at the end of the session a system message (duration, outcome) is inserted into the chat, analogous to user-to-user voice calls. Persisted normally in the local dedicated chat history.
Usage limit
- Free: 2 minutes / 24 hours · Plus: 30 minutes / 24 hours per user (separate from the message/image/document limits). The counter is persisted in Cloudflare KV (
ai-voice-mins:{userId}, 24h TTL) and resets automatically. - At least 30 seconds of remaining quota are required to start a call.
- When the quota is exhausted the server forces the session to close and the user sees an informational bubble.
E2EE exception
The call audio is not end-to-end encrypted: it must be processable by OpenAI to generate the response. It is protected by TLS in transit (both client → Taski and Taski → OpenAI) and is not persisted at rest. All other Taski calls (1-1 and group) remain end-to-end encrypted via SRTP/AES-GCM.
Availability
The voice call with the chatbot is available on iPhone and Android, exclusively in the dedicated chat. Web, Desktop and Apple Watch have no access to this feature.
16.6 Generated documents (PDF)
When the user explicitly requests it, the chatbot can produce a PDF document (e.g. a recipe, list, summary). The PDF is generated locally on the device by the app from the text returned by the model, and cached in the Documents/AIChatPDFs/ folder. It is never sent to OpenAI or any other provider: generation is entirely client-side. Tap the bubble → Quick Look preview with system buttons for sharing and saving.
16.7 Photos and documents uploaded by the user
- Photos: resized and sent as an image to Anthropic's response model. Photos are cached locally on the device for later viewing. If the user asks to edit them, the photo is also sent to OpenAI (section 14.1).
- PDF documents: sent as files to Anthropic's response model, which reads their content.
- Neither photos nor documents uploaded by the user are persisted by the Taski server at rest (only the caption written by the user or an indication of the attachment type remains in the history).
16.8 Rate limits
- Messages: Free 3 per day · Plus 15 per day per user (server-side and client-side rate limit, rolling 24h window). When reached, a banner notifies the user and temporarily blocks sending.
- Uploaded documents: 5 documents per day per user.
- Generated images: Free 2 per day · Plus 10 per day — same shared counter as the inline mode (see 16.4).
- Voice call: Free 2 minutes · Plus 30 minutes, every 24 hours, per user (see 16.5). Server-side cap persisted in Cloudflare KV.
- Advanced reasoning (Claude Opus): Free 1 per day · Plus 5 per day per user — cap shared with the inline mode (section 13).
These limits are independent of each other and are enforced server-side; the app keeps a local copy of them only to warn the user in advance.
16.9 Data retention
- Dedicated chat history: on the user's device (the app's local database) until logout, account deletion or manual clearing of the chat. On the server, messages (text of questions and replies, without attachments) remain in cleartext for up to 7 days, after which they are automatically deleted; they are deleted immediately if the account is deleted.
- Memory: local file, with an optional E2EE-encrypted synced copy that expires after 90 days without updates (see 16.3 and 5).
- Generated images (R2): 24 hours, then automatic cleanup via daily cron.
- Generated PDFs: local app cache until logout or manual deletion.
- Voice-call audio: never persisted (see 16.5).
- Transient transmission: Anthropic and OpenAI may transiently retain data as per their respective policies (see section 12). Anthropic and OpenAI state that they do not train models on API data.
16.10 Multi-platform availability
The dedicated chat (messages, attachments and memory) is available on iPhone, Android, Web and Desktop. The voice call with the chatbot is only available on iPhone and Android. Apple Watch has no access to the dedicated chatbot.
16.11 Opt-out
The global TaskiAI opt-out from section 7 (Settings → Privacy → TaskiAI) disables both the inline mode and the dedicated chat (text and voice). Alternatively, the user may simply never open the dedicated chat or start the voice call: no request is sent to the AI providers until the user explicitly interacts.
17. Voice-scheduled messages
During a voice call with TaskiAI, the user may ask the assistant to schedule a future message to one of their contacts: e.g. "send Marco tomorrow at 10 the message: hi how are you". For full transparency, the complete step-by-step flow is described below.
17.1 What passes through OpenAI in cleartext
- The user's voice is transcribed in real time by the OpenAI Realtime API on OpenAI's servers, in cleartext, with contractually zero retention (see section 12).
- The AI extracts the three required parameters: recipient name, message text, future date/time.
- In this step the message text passes through OpenAI in cleartext — this is unavoidable, because the AI needs to understand what to write in order to structure it correctly.
17.2 What happens on the device
- The user's device receives the extracted parameters.
- It identifies the matching Taski contact in the local address book (case-insensitive textual matching against contacts with whom a 1-1 chat already exists).
- It prepares the message in cleartext locally.
17.3 E2EE encryption before delivery to the Taski server
- Before sending to the server, the message is end-to-end encrypted with AES-256-GCM and a symmetric key shared via X25519, exactly like a regular message.
- The Taski server receives only the encrypted version, stored in the
scheduled_messagestable. - At the scheduled time, a server cron job delivers the encrypted message to the recipient via WebSocket or push.
- The recipient decrypts the message on their own device: the Taski server never has access to the plaintext.
17.4 Confidentiality summary
OpenAI temporarily sees the message text (because it transcribes the user's voice and processes it to extract the parameters), but the final message reaches the recipient E2EE like any other Taski message. The Taski server never sees the plaintext. The AI provider (OpenAI) sees it only in transit for the time strictly necessary for processing, under a zero-retention contract (see section 12).
17.5 Usage limits (MVP)
- Works only with contacts the user already has a 1-1 chat open with.
- Name matching is textual (case-insensitive contains): if the user has multiple contacts with the same name, the AI will ask to specify more precisely.
- Text only: photos, voice messages, videos and documents cannot currently be scheduled by voice.
- The date/time must be in the future. The AI computes relative dates ("tomorrow at 10", "tonight at 8") in the device's local timezone.
17.6 100% E2EE alternative without AI provider
A user who prefers not to let the message text transit through OpenAI even temporarily may always schedule messages manually from the chat interface, via the clock icon in the input bar. Manual scheduling is 100% E2EE end-to-end and does not involve any AI provider: the message is encrypted on the device before leaving, like any other Taski message.
17.7 Opt-out
The global TaskiAI opt-out described in section 7 also disables the ability to schedule messages by voice (the voice call with TaskiAI is no longer available). Manual scheduling from the chat interface remains available at all times and is not affected by the AI opt-out.
18. AI stickers and message rewriting
18.1 AI stickers
- The user can create stickers from text or from a photo. Stickers are generated by OpenAI (gpt-image-2.5-flare or gpt-image-1, depending on the style).
- In "photo → sticker" mode, the source photo is sent in cleartext to the Taski server (protected by TLS) and from there to OpenAI; the server does not retain it. The resulting sticker is then sent in the chat end-to-end encrypted like other media.
- Only for text-based stickers, if OpenAI is unavailable, a fallback is used: Claude Haiku 4.5 (Anthropic) prepares the prompt and Flux Schnell (Cloudflare Workers AI) generates the image. Photos are never sent to the fallback providers.
- Limits: Free 1 sticker · Plus 5 stickers every 24 hours per user. If generation fails, the quota is refunded.
18.2 AI Rewrite (draft rewriting)
- Before sending a message, the user can ask to rewrite the draft: correct it, improve it, make it more formal, more casual, shorter or funnier, or translate it.
- Only the draft text (max 2000 characters) and the chosen tone are sent to Anthropic: Claude Sonnet 5 for translation, Claude Haiku 4.5 for the other tones. The rewritten draft returns to the device; the message, if sent, then travels end-to-end encrypted like any other.
- The Taski server retains neither the original nor the rewritten text.
- Limits: Free 5 · Plus 30 rewrites per day per user.
19. Contact
Questions about TaskiAI: [email protected]