TaskloreSign in

Privacy Policy

Last updated: 22 July 2026

This policy explains what Tasklore does with your data. Tasklore is operated by Sielay Ltd, a company registered in England & Wales (the "we", "us", the data controller). It is written to be read, not to hide behind jargon. If anything is unclear, email support@sielay.com.

The short version

When you summarise an issue, Tasklore reads that issue's content — its title, description, status, assignee, comments, and its activity/change history (e.g. status and assignee changes) — sends what's needed to a large language model to produce a short summary, shows you that summary, and then throws the content away. We do not store your Jira content or the summaries we generate. We keep only your account, your connected-site credentials (encrypted), and a private count of how many summaries you have used (with the Jira org it was for, for billing).

What we store

Account. Your email address and (if you use Google sign-in) your name, to authenticate you.

Connected Jira sites. For each Jira site you connect, its cloud id, name and URL, and the OAuth access/refresh tokens needed to keep the connection working. Tokens are encrypted at rest (AES-256-GCM) before they are written to our database.

Billing & usage. Your summary allowance and top-up balances, your reset date, and your Stripe customer/subscription identifiers. Our usage ledger records only counts and timestamps — never an issue key, comment, or summary.

What we never store

Jira issue descriptions, comment text, or any Jira field content; and the summaries produced from them. These exist only for the duration of the request that produces them, in memory, and are then discarded. This ephemerality is a deliberate design choice, not an afterthought.

How your Jira content is processed by AI

To generate a summary we send the issue's title, description, status, assignee, comments, and a condensed activity/change history to a large language model provider. We disclose exactly which providers and models may process it. By default we use the first provider below; a self-hosted or configured deployment may use an alternate model, but only from this list:

OpenAI, L.L.C.
Models: gpt-5.4-nano · Trains on submitted content: no · their privacy policy ↗
Default provider. Accessed via the OpenAI API; API data is not used to train their models.
DeepSeek
Models: deepseek-v4-pro · Trains on submitted content: no · their privacy policy ↗
Optional alternate model, only when configured, routed via an OpenAI-compatible gateway.
Anthropic PBC
Models: claude-haiku-4-5 · Trains on submitted content: no · their privacy policy ↗
Optional premium-quality model, only when configured, routed via an OpenAI-compatible gateway.

We select providers that, under their API terms, do not use content submitted via their API to train their models. We do not control these providers' own policies; the links above are authoritative for their processing. We send only what is needed to summarise the one issue you asked about.

Sub-processors

We rely on the following processors to run the service: Supabase (authentication and database hosting), Vercel (application hosting), Stripe (payments and tax), Atlassian (your Jira data source, accessed read-only on your authorisation), the AI providers listed above, and Glue (privacy-safe product analytics — event names and coarse counts only, never Jira content). Each processes data on our behalf under its own terms.

Legal basis & your rights (UK GDPR)

We process your account and connection data to perform our contract with you, and usage data on the basis of our legitimate interest in metering and preventing abuse. Because we do not retain Jira content or summaries, there is nothing of that kind to export or erase. For the data we do hold, you may request access, correction, export, or deletion, and you may close your account at any time — email support@sielay.com. You also have the right to complain to the UK Information Commissioner's Office (ICO).

Retention

Account, connected-site, and billing records are kept for as long as your account is open, and deleted (or anonymised for lawful financial record-keeping) after you close it. Jira content and summaries are never retained.

International transfers

Some processors above are located outside the UK/EEA. Where that is the case, transfers are covered by appropriate safeguards (such as the UK International Data Transfer Agreement or equivalent standard contractual clauses).

Changes

We will update this policy as the service evolves and change the "last updated" date above. Material changes to which AI providers can process your content will always be reflected in the table above before they take effect.

Contact

Sielay Ltd — support@sielay.com.