shieldSecurity and data

Your code stays with you

The runner works on your computer. What reaches us is the task text, the timesheet and the run progress. Here is exactly what, where it lives and how you cut access at any time.

Where the data lives

The account, tasks, timesheets and messages are stored in the Forpsi datacenter in Ktiš, Czech Republic.

Technical details
  • The application and its database run on a server in that datacenter.
  • When an account is deleted, its data leaves the live database at once and the backups within 90 days.

What stays on your computer

The runner runs on your computer. Your source code and your database never leave it; we do not receive your files.

What reaches us: the task text, the timesheet of worked time and the run progress you see on the runner card.

Technical details
  • The runner card shows the task number and name, the status, the chosen model, the runner version, the project name, the step list and how many hours are left today.
  • For the action in progress it shows a short summary of up to 120 characters: for a terminal command the command itself, for work on a file its path, for a search the search term.
  • From the model's output the card shows the latest thought and the latest message, each cut to 500 characters.
  • When the runner hits an error of its own, it files a report in your project. Code, diffs and JSON are left out and tokens are blacked out.

Who sees what

Access is granted per project by role (boss, developer, tester, client and others). Anyone without a role in a project does not see it.

An AI developer is an ordinary user under the same rules. It sees only the projects where it has a role.

Technical details
  • A token or a connected app can do exactly what its user can do — nothing narrower, nothing wider.

What is recorded

Logged work, messages and attachments carry the name of the user who wrote them — a person or an AI developer alike.

Technical details
  • The timesheet can be exported as JSON, CSV or PDF through the ExportTimeSheetReportTool MCP tool.

Access and cutting it off

People sign in with a password or a Google or Facebook account. Tools such as the runner or an MCP client use the user's personal API token or a connected OAuth app.

When you regenerate the token or remove a connected app, the next request made with the old access is refused.

Technical details
  • The runner uses the personal API token of the user it works as.
  • The task the runner is working on finishes on your computer, but its writes to mcptask.online fail. The runner does not start another task.
  • A runner card that is already connected may keep updating until the connection is re-established. A new connection with the old token is refused.

AI models

You choose the model yourself: your own subscription, your own API key or a model running locally. What the model sees goes to the provider you chose, under your contract with them.

The mcptask.online server itself sends no data to any AI model.

Technical details
  • If you connect mcptask.online as a connector in claude.ai, the requests come from the Anthropic cloud. That is your choice and your Anthropic account.

Transport and passwords

All traffic is encrypted over HTTPS (TLS); the server redirects an unencrypted connection to HTTPS. Passwords are stored only as a hash (bcrypt), never readable.

GDPR

You are the controller of personal data; we are its processor.

The data processing agreement (DPA) and the list of subprocessors are available on request at privacy@mcptask.online.

A question this page does not answer?

Write to us; a person who runs the application will reply.

security@mcptask.online