Privacy

TaskDock is a stateless MCP connector. It processes only the content you pass to its tools in order to compute a response for that same request.

What it stores

Write tools (task_create, task_update, task_complete) store tasks under a namespace you choose (workspace_id). Storage is owner-gated: tasks in a protected workspace (one with a secret key) are kept in a durable private store (Vercel Blob, private at rest) and are bound to the key holder; tasks in an unprotected namespace are ephemeral — never written to durable storage, lost on cold start. Read tools return those tasks.

Access model: public endpoint, per-workspace secret key

The MCP endpoint is public (no login, no OAuth). Access control is per-workspace by a secret key (a capability token): an unprotected workspace_id is a namespace, not an access boundary. Protect a workspace with workspace_create or workspace_protect; afterwards every read and write requires that secret key. The key is shown once, stored only as a SHA-256 hash, and never recoverable. Real multi-user authentication is the pre-publish gate; this pilot is private/draft.

What it never does

No accounts, no tracking, no advertising, no sale of data, no calls to third-party services. No reminders or notifications.

Deletion

Completing a task keeps it (status=done); nothing is hard-deleted, so an original is always recoverable. To have stored tasks removed, contact support.


Support: infodev@mmcco.co