Simple. Powerful. Just works.

Task management
that works for you

No complexity. No learning curve. Just simple lists and notes that sync in real-time.
Perfect for individuals and teams.

No credit card required
Setup in 30 seconds
Your data is private
CoTask Dashboard Preview

Everything you need,
nothing you don't

Designed for simplicity. Built for collaboration.

Real-time Sync

See changes instantly as your team collaborates. No refresh needed.

Lists & Notes

Create todo lists or rich text notes with embedded tasks.

Easy Sharing

Share with anyone. Control who can view or edit.

Fast

Optimized for speed.

Built on the principle of simplicity

No overwhelming menus. No complex workflows. No steep learning curve.

Cotask gets out of your way so you can focus on what matters: getting things done.

CoTask Simple Interface

Ready to simplify your workflow?

Join others who've already made the switch to effortless task management

About Cotask

Cotask was built with one core principle: simplicity above all else. We're not trying to be an enterprise project management tool or a complex workflow system. We're here to make everyday task management effortless.

Whether you're an individual organizing your personal life, coordinating with friends and family on household tasks, or collaborating with a small team on straightforward projects, Cotask is designed for you. We believe that most tasks don't need complicated features—they just need to get done.

Perfect for:

  • Individuals: managing personal tasks and goals
  • Friends & Family: coordinating household chores, events, and shopping lists
  • Small Teams: working on simple projects without unnecessary complexity

With real-time synchronization, intuitive sharing controls, and a clean interface that stays out of your way, Cotask helps you focus on what matters most: getting things done without the overhead.

No bloat. No confusion. Just tasks and notes that work the way you expect them to.

Privacy Policy

A privacy-focused task and note management application

Last Updated: December 11, 2025

Cotask is a student project developed in Norway. We take your privacy seriously and comply with Norwegian privacy laws and GDPR.

Our Core Principles

Your data is yours. We never sell or share it with third parties.

We collect only what's necessary to provide the service.

You have full control over your data at all times.

We're transparent about our data practices.

Your content remains private by default.

We implement appropriate security measures for a student project.

1

Data Controller

The data controller for Cotask is a student developer based in Norway. For all privacy-related matters, you can reach us at:

2

Information We Collect

Account Information

When you create an account, we collect:

  • Email address (for account creation and login)
  • Username (chosen by you)
  • Name (optional, for display purposes)
  • Password (stored encrypted, we cannot see your actual password)
  • Profile picture (optional, if you upload one)

Content Data

We store the content you create:

  • Task lists and individual tasks
  • Notes and their content
  • Sharing permissions you set
  • Timestamps (when items were created or modified)

Technical Data

Minimal technical information:

  • IP address (logged by our hosting provider for security)
  • Browser type and version (for compatibility)
  • Device information (for responsive design)

What We DON'T Collect

  • We don't use tracking pixels or analytics cookies
  • We don't collect browsing history or behavior outside Cotask
  • We don't use advertising cookies or third-party analytics
3

Legal Basis for Processing (GDPR Article 6)

Under GDPR, we process your data based on:

Contract Performance (Article 6(1)(b))

Processing your account and content data is necessary to provide the Cotask service you signed up for.

Legitimate Interests (Article 6(1)(f))

We process technical data to ensure security, prevent abuse, and improve the service.

Consent (Article 6(1)(a))

For optional features like profile pictures, we obtain your explicit consent.

4

How We Use Your Information

We use your information exclusively to:

  • Provide and maintain the Cotask service
  • Enable collaboration features like sharing lists and notes
  • Sync your data across your devices in real-time
  • Send you essential service communications (e.g., password resets)
  • Identify and fix technical issues
  • Ensure the security of your account and prevent abuse

What We DON'T Do

Cotask does NOT:

  • Sell or share your data with third parties for any purpose
  • Use your data for advertising or marketing
  • Analyze your content for commercial purposes
  • Send promotional emails (we only send essential service emails)
  • Share your data with advertisers or data brokers
5

Data Sharing and Third Parties

User-Initiated Sharing Only

When you choose to share a list or note with another Cotask user, they will be able to see:

  • The shared content (list or note)
  • Your username and name
  • Your profile picture (if you've uploaded one)

You control exactly what is shared and can revoke access at any time.

Service Providers

We use the following third-party services:

  • Supabase: Backend database and authentication service. Your data is stored on Supabase's servers. Supabase is GDPR-compliant and their data centers are located in various regions (you can check their documentation for specific locations).
  • VPS Hosting Provider: The Cotask application is hosted on a Virtual Private Server. Only encrypted connections (HTTPS) are used.

These service providers have access to your data only to perform services on our behalf and are obligated not to disclose or use it for any other purpose.

Legal Requirements

We may disclose your information if:

  • Required by Norwegian law or valid legal process
  • Necessary to protect the rights, property, or safety of users
  • Needed to prevent or investigate potential fraud or security issues

No Selling or Commercial Sharing

We will NEVER sell your personal data to third parties or share it for commercial purposes. This is a student project focused on providing a useful service, not monetizing user data.

6

Data Security

We implement security measures appropriate for a student project:

HTTPS Encryption

All data transmitted between your device and our servers is encrypted

Password Hashing

Passwords are hashed using bcrypt - we never see your actual password

Database Security

Row-level security policies protect your data in the database

Secure Authentication

JWT tokens with expiration for session management

Regular Updates

We keep software dependencies updated for security patches

Access Control

Only you and users you explicitly share with can access your content

Important Security Notice

While we implement appropriate security measures for a student project, Cotask is not designed for storing highly sensitive, confidential, or critical information. Please do not store:

  • Financial information (credit cards, bank accounts)
  • Medical records or health information
  • Government ID numbers or social security numbers
  • Passwords or security credentials
  • Confidential business information
7

Your Rights Under GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights:

Right to Access (Article 15)

You can view all your data within the application at any time. For a complete data export, contact us.

How to exercise: Available in-app or email us

Right to Rectification (Article 16)

You can correct any inaccurate personal data through your profile settings.

How to exercise: Edit in Profile page

Right to Erasure / 'Right to be Forgotten' (Article 17)

You can delete your account and all associated data at any time.

How to exercise: Delete Account button in Profile settings

Right to Restrict Processing (Article 18)

You can request we limit how we use your data.

How to exercise: Email huberthilla0420@gmail.com

Right to Data Portability (Article 20)

You can request a copy of your data in a machine-readable format.

How to exercise: Email us for manual export

Right to Object (Article 21)

You can object to our processing of your data for legitimate interests.

How to exercise: Email huberthilla0420@gmail.com

Right to Withdraw Consent

For consent-based processing (like profile pictures), you can withdraw consent anytime.

How to exercise: Remove in Profile settings or email us

Exercising Your Rights

Most rights can be exercised directly in the app. For requests requiring manual processing (like data export), email us at huberthilla0420@gmail.com. We will respond within 30 days as required by GDPR, though we typically respond much faster.

Right to Complain

If you believe we are not handling your data appropriately, you have the right to file a complaint with the Norwegian Data Protection Authority (Datatilsynet) at www.datatilsynet.no

8

Data Retention

📂

Active Accounts

We retain your data for as long as your account is active.

🗑️

Account Deletion

When you delete your account, we immediately delete your personal information and content from our active database.

💾

Backups

Database backups are retained for up to 30 days for disaster recovery. After this period, your data is permanently deleted from backups as well.

👥

Shared Content

If you've shared content with other users, they will retain access to that content until they delete it, even if you delete your account.

⏱️

Inactive Accounts

Accounts inactive for more than 2 years may be deleted after email notification.

Project Timeline Notice

Cotask is a student project with an expected active development period until approximately June 2025. After the project conclusion:

  • You will be notified via email at least 60 days in advance
  • You will have time to export your data
  • All user data will be permanently deleted from our systems
  • We may continue running the service if there's sufficient interest, but make no guarantees
9

Cookies and Similar Technologies

Cotask uses minimal cookies necessary for the service to function. We use "strictly necessary" cookies that are exempt from consent requirements under GDPR.

Cookies We Use:

Authentication Cookie (Session)

  • Purpose: Keeps you logged in and authenticates your requests
  • Duration: Until you log out or token expires (typically 7 days)
  • Type: Strictly necessary - cannot be disabled
  • Data stored: Encrypted authentication token (JWT)

Theme Preference (Local Storage)

  • Purpose: Remembers your dark/light mode preference
  • Duration: Permanent until cleared
  • Type: Functionality - enhances user experience
  • Data stored: Theme preference ("dark" or "light")

What We DON'T Use:

  • Third-party tracking cookies
  • Advertising cookies
  • Analytics cookies (like Google Analytics)
  • Social media cookies
  • Marketing cookies

Managing Cookies

You can control and delete cookies through your browser settings. However, disabling the authentication cookie will prevent you from logging into Cotask. Most browsers allow you to:

  • View what cookies are stored
  • Delete individual cookies
  • Block third-party cookies
  • Clear all cookies
10

International Data Transfers

Cotask is developed and operated from Norway, which is part of the European Economic Area (EEA) and subject to GDPR.

Data Storage Location

Your data is stored with Supabase. Supabase offers multiple regions for data storage. While we cannot guarantee the specific region your data resides in without checking our Supabase configuration, Supabase is GDPR-compliant and offers EU hosting options.

If data is transferred outside the EEA, Supabase uses Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection.

For the most current information about Supabase's data locations and GDPR compliance, visit: Supabase GDPR Documentation

11

Children's Privacy

Cotask is not intended for children under the age of 16 (the minimum age for processing personal data under GDPR without parental consent). We do not knowingly collect personal information from children under 16.

If you are under 16:

Please do not use this service or provide any personal information. If you are a parent or guardian and believe your child under 16 has provided us with personal information, please contact us immediately at huberthilla0420@gmail.com and we will delete it.

12

Changes to This Privacy Policy

We may update this Privacy Policy as the project evolves. When we make changes, we will:

  • Update the "Last Updated" date at the top of this page
  • For significant changes: Display a prominent notice in the Cotask application
  • For significant changes: Send an email notification to your registered email address

What Constitutes a Significant Change?

  • Changes to what data we collect
  • Changes to how we use your data
  • Changes to who we share data with
  • Changes to your rights
  • Changes to data retention periods

Your Continued Use: Continued use of Cotask after changes constitutes your acceptance of the updated policy. If you do not agree with changes, you should stop using the service and delete your account.

Contact Us About Privacy

If you have any questions about this Privacy Policy, wish to exercise your GDPR rights, or have concerns about how your data is being handled, please contact:

Email (Primary Contact)

huberthilla0420@gmail.com

Use this email for all privacy-related inquiries, GDPR requests, and general questions.

Response Time

We aim to respond to all privacy inquiries within 7 days, though GDPR allows up to 30 days. Response times may be longer during exam periods.

Supervisory Authority

Norwegian Data Protection Authority (Datatilsynet)
Website: www.datatilsynet.no
You have the right to file a complaint with them if you believe we're not handling your data properly.

Student Project Disclaimer: Cotask is developed by a student as part of an academic project. While we are committed to handling your data responsibly and in compliance with GDPR, please be aware of the limitations inherent in a student project. We appreciate your understanding and patience.

Thank you for using Cotask. We take your privacy seriously and are committed to protecting your personal data in accordance with Norwegian and EU law.

Last reviewed and updated: December 11, 2025

Cookie Notice

We use strictly necessary cookies to keep you logged in and ensure the security of your account. We do not use tracking, analytics, or advertising cookies. By using Cotask, you agree to our use of essential cookies. Learn more