Security
Last updated: May 2026
Current measures
- API keys and secrets are stored server-side only. None are exposed to the client.
- All AI model calls happen server-side.
- Input is screened for sensitive content before storage or processing.
- Rate limiting is in place to prevent abuse.
Data storage
Today, your data lives in your browser's local storage. Taskmorrow does not sync to a backend server unless you explicitly enable a future integration. Your data leaves your browser only when AI features are enabled and a request is sent to an AI provider.
What is not yet certified
Taskmorrow does not currently hold SOC2, HIPAA, GDPR certification, or similar attestations. We are a small early-stage product. We take security seriously, but we do not make compliance claims we cannot back up.
Data deletion
You can clear all local data from the Settings page. If you have questions about deletion or security, email us at support@taskmorrow.com.
No integrations connected yet
Calendar, email, SMS, and cloud sync integrations are not active. When they are added, they will use industry-standard OAuth and encryption practices. We will update this page before any integration goes live.