Scope: the AltNerva Tasks internal test build operated by 北京寰衍科技有限公司, including its Windows desktop app, website, accounts, optional cloud sync, Founder invitations and related services.
Who we are
AltNerva Tasks is provided by 北京寰衍科技有限公司. This policy applies only to the Tasks Windows desktop app and its website, accounts, optional cloud sync, online updates, character/DIY features, product metrics and diagnostics. It does not apply to any input method or other separate product that AltNerva may offer in the future. Before publicly enabling accounts and cloud sync, we will prominently provide the operator information, personal information protection contact details and applicable filing information required by law on the website.
Our principles
We follow the principles of lawfulness, legitimacy, necessity, good faith, openness, transparency and data minimization. When first starting the client, you must read this policy and the Terms of Service. Before consent, the client does not open the local task database, request cloud sync, retrieve product metrics or enable optional data capabilities. Anonymous local mode does not create a cloud guest account. The client requests the relevant online services only when you actively register, sign in, use Founder benefits or enable cloud sync. Except as needed for Tasks functionality, account security, cloud sync, customer support and legal obligations, we do not collect personal information unrelated to the service. We do not sell personal information.
Information we collect and use
- Account registration and sign-in: email address, login credential requests, password hashes, account ID, login sessions, device sign-in status, request times, IP address and necessary security logs are used to create accounts, verify identity, maintain sessions and protect account security. Passwords are submitted over an encrypted connection; the server does not store plaintext passwords.
- Founder invitations: phone number or email, preferred name, invitation number, Founder number, submission time and benefit status are used to generate invitations, notify eligibility, remove duplicate applications and grant benefits.
- Tasks and cards: in local-only mode, task content is stored in an encrypted database on your device. After you sign in and enable cloud sync, card titles, body text and other synchronized content are encrypted on the device using AES-256-GCM before being uploaded as encrypted change records. The cloud stores ciphertext and sync-key packages encrypted with a password or recovery code. It does not store plaintext card titles, body text or sync keys.
- Sync metadata: account ID, device ID, record types and identifiers, operation types, version numbers, timestamps, sync status, content checksums, IP address and necessary security logs are used for event routing, conflict resolution, rate limiting, troubleshooting and security audits. This necessary metadata is separate from encrypted card content and may be processed directly by the server.
- Characters, DIY and personalization: character colors, card styles, benefit-related assets and preferences are used to restore your personalized settings.
- Online updates: app version, system platform, update request times, IP address and download logs are used to provide official Windows EXE and App Installer updates and security audits.
- Diagnostics and metrics: error codes, API status, error times, device and app environment, and aggregate usage metrics are used for troubleshooting, stability improvements and product operations metrics. Card body text is not recorded by default. Where the internal test build has not integrated a separate third-party diagnostics service, it does not send data to such a service for that purpose.
- AI assistance: the current Tasks internal test build does not provide a publicly available AI feature that processes card body text. If task organization, summaries, completion or intelligent suggestions are added in the future, we will separately explain the processing scope before enabling them and provide independent controls and any necessary consent.
Sensitive personal information
Passwords, precise device identifiers, minors’ personal information and task content that may reveal personal habits or private matters may constitute sensitive personal information or highly sensitive context. We process such information only for a specific purpose and where sufficiently necessary, using measures such as local database encryption, on-device encryption of sync content, encryption in transit, access controls, rate limiting and security audits. No security measure can guarantee absolute security. If a security incident is discovered, we will take remedial and notification measures as required by law.
Processors and third-party sharing
We may engage cloud computing, managed database, email, object storage, CDN, error diagnostics or customer support providers to process the data necessary for the current functionality. The actual providers’ names, contact details or privacy policy links, processing purposes and methods, and categories of personal information are specified in the Third-party sharing and SDK list. Providers whose actual information has not been disclosed in that list must not be used for public account and cloud-sync services. Unless otherwise provided by law, we will not provide your personal information to independent third parties without your separate consent.
Retention
We retain personal information only for the shortest period necessary to fulfill the processing purpose. Account information is retained while the account exists. Encrypted cloud-sync data is retained while the account exists and you have not separately requested deletion. Logs and security-audit data are retained for the periods necessary for security, auditing and legal requirements, then deleted or anonymized. Turning off cloud sync stops new synchronization only; it does not automatically delete data already uploaded to the cloud.
Your rights
Subject to applicable law, you may request access, copies, correction, supplementation, deletion, restriction of processing, withdrawal of consent, account closure and an explanation of personal information processing rules. Turning off sync, withdrawing applicable cross-border or overseas processing consent, exporting data, deleting cloud data and closing an account are different actions. Turning off sync or withdrawing consent does not automatically export or delete existing cloud data; exporting does not automatically delete it either. See Account closure and data rights for the effects and available paths. We will handle requests within a reasonable period; as a general rule, we will provide the outcome of app-related personal information rights requests within 15 working days.
Minors
AltNerva Tasks does not provide a dedicated service for children under the age of fourteen. If we discover that children’s personal information has been processed without guardian consent, we will delete it or take necessary protective measures as soon as possible. See the Children’s privacy rules.
Global cloud processing and regions
Accounts, optional cloud sync, email notifications and related security capabilities may use global cloud infrastructure. When you actively use these online capabilities, your email, account and device information, login and sync metadata, IP address, necessary security logs, and card change records encrypted on the device may be processed or stored outside your country or region.
Before publicly enabling these capabilities, the client will ask you to actively select or confirm your country or region to display the applicable notices and available services. We will not silently determine or change your region solely from your IP address. Region confirmation determines applicable notices and service entry points; it is not a promise that data will be stored in that region. Changing the language, system region or a later region selection will not automatically migrate existing accounts or cloud data. If cross-region migration is offered in the future, we will separately explain the original and destination locations, effects and rights, and require you to initiate or confirm it.
Users in mainland China
If personal information collected in mainland China is provided outside the People’s Republic of China through global cloud infrastructure, we will present a separate notice before first sending account or sync data, identifying the overseas recipient, purposes and methods of processing, information categories and ways to exercise rights, and obtain separate consent or complete other applicable procedures as required by law. Refusal will not affect local-only task functionality. Public notices may use “overseas” as a general description of infrastructure locations, but actual overseas recipients must be accurately identified in the Third-party sharing and SDK list.
Users in other countries or regions
Your personal information may be processed or stored outside your country or region through global cloud infrastructure. According to the laws applicable to you, we will explain the recipients, processing purposes, information categories, safeguards and ways to exercise rights, and obtain consent or use another lawful basis where required.
Policy updates
We may update this policy as functionality, laws, regulations or service delivery change. We will draw significant changes to your attention through the website, client notices or other prominent means.