Nesk legal
Privacy Policy
Last updated: 5 September 2026
Nesk is built on a simple principle: your data should be used to provide and improve Nesk, not to build a business around tracking you.
We aim to collect as little personal information as we reasonably can. We do not sell your personal data, use it for advertising profiles, or share it with advertisers or data brokers.
This policy explains what information Nesk collects, why we collect it, how it is used, and the choices you have.
On this page
1. Who is responsible for your data?
Nesk is operated by:
[LEGAL NAME / TRADING NAME] [BUSINESS OR CONTACT ADDRESS] [PRIVACY CONTACT EMAIL]
For data protection purposes, this entity is the controller of the personal information processed through Nesk.
If you have a question about your information or want to exercise a data protection right, contact us at the address above.
2. The information Nesk processes
Account information
We process the information needed to create, authenticate and maintain your account.
This currently includes your:
- email address;
- authentication identifiers;
- account status; and
- authentication-related security information.
Passwords are handled by our authentication provider. Nesk does not need or intend to store your plaintext password.
The information you put into Nesk
Nesk stores the information you choose to create while using the service, including things such as:
- tasks;
- task descriptions and details;
- projects;
- priorities;
- due dates;
- effort estimates;
- task status;
- completion information;
- deferrals and rejections;
- work-session information;
- planning information; and
- other task-management metadata you choose to provide.
This information belongs to you. Using Nesk does not transfer ownership of your content to us.
Please avoid putting sensitive personal information into Nesk unless it is genuinely necessary for your use of the service.
Service and security information
Like most online services, we may process limited technical information required to operate and secure Nesk, such as:
- timestamps;
- request and error information;
- authentication events;
- security events;
- device or browser information where technically necessary; and
- IP address information where it appears in infrastructure or security logs.
We do not use this information to create advertising profiles.
3. Product analytics
We want to understand whether Nesk works well and where it needs improving.
Nesk may therefore collect first-party usage information about how the product is used, such as:
- which product features are used;
- task completion, deferral or rejection events;
- broad patterns in task estimates and actual effort;
- navigation between Nesk views;
- errors and performance information; and
- aggregated patterns of product usage.
We design this analytics collection to minimise personal information.
Where we need event-level information before aggregation, we aim to use pseudonymous identifiers instead of directly identifying information such as email addresses.
Where reasonably possible, analytics are aggregated and anonymised so they can no longer be connected to an identifiable user.
We do not use product analytics to:
- serve targeted advertising;
- track you across unrelated websites;
- create advertising profiles;
- sell behavioural information;
- determine your eligibility for unrelated products or services; or
- provide your individual productivity information to employers or other third parties.
The purpose of Nesk analytics is to understand and improve Nesk.
4. Cookies and local storage
Nesk may use cookies or equivalent browser storage where necessary to provide the service, for example to keep you securely authenticated and maintain essential session state.
We do not use third-party advertising cookies or cross-site tracking cookies.
We intend product analytics to operate without non-essential tracking cookies wherever reasonably possible.
If we later introduce technology that requires consent under applicable cookie and electronic communications law, we will ask for that consent before using it.
5. Why we use your information
We process personal information only where we have a lawful reason to do so.
Providing Nesk
We process account information and the data you enter into Nesk because it is necessary to provide the service you have requested.
Our lawful basis is generally performance of a contract.
This includes:
- creating and authenticating your account;
- storing and displaying your tasks;
- ranking tasks;
- maintaining projects and workflow state;
- providing planning and analytics features;
- exporting your information; and
- carrying out actions you request.
Operating, securing and improving Nesk
We may process limited service, security and pseudonymised usage information where necessary for our legitimate interests in:
- maintaining the reliability of Nesk;
- identifying and fixing defects;
- preventing abuse and security incidents;
- understanding how features perform; and
- improving the product.
We aim to do this in ways that have minimal privacy impact and do not override your rights and interests.
Where the same objective can reasonably be achieved using anonymised information, we prefer that approach.
Legal obligations
We may process information where necessary to comply with a legal obligation.
6. Email
Nesk does not use your email address for unrelated marketing by default.
We may send emails necessary to operate your account or a workflow you have requested, including:
- account verification;
- authentication messages;
- password recovery;
- security notifications;
- important service communications; and
- notifications that form part of a Nesk workflow you have chosen to use.
If we ever introduce optional marketing communications, they will be clearly distinguished from service communications and will include an appropriate way to opt out.
7. Service providers
Nesk relies on carefully selected service providers to operate parts of the service.
These providers process information on our behalf and are not permitted to use Nesk user information for their own unrelated purposes simply because they provide infrastructure to us.
Current providers include:
Supabase
Nesk uses Supabase for backend and authentication services.
This means relevant account and application information may be processed through Supabase infrastructure to provide those services.
Render
Nesk uses Render to host and operate the Nesk web service and associated website infrastructure.
Information sent to Nesk may therefore pass through or be processed by Render infrastructure as necessary to provide the service.
We may change infrastructure providers as Nesk develops. When a change materially affects how your personal information is processed, we will update this policy.
We do not regard the use of these processors as selling your information.
8. International transfers
Some infrastructure providers may process or make information accessible outside the United Kingdom.
Where this constitutes a restricted international transfer under UK data protection law, we will use an applicable legal transfer mechanism, such as:
- UK adequacy regulations; or
- appropriate contractual and organisational safeguards.
We will take reasonable steps to ensure that personal information remains appropriately protected when processed internationally.
9. How long we keep information
We keep identifiable personal information only for as long as it is reasonably needed for the purposes described in this policy.
While your account is active, we retain the account and task information needed to provide Nesk.
If you delete your account, we will delete or anonymise personal information associated with the account, subject to:
- short technical periods required to complete deletion;
- secure backup-retention cycles;
- information that we are legally required to retain; and
- limited records we reasonably need to establish or defend legal claims.
Where analytics have already been genuinely anonymised and can no longer be associated with you, those statistics may be retained because they are no longer personal information.
We will define and review appropriate retention periods for operational logs, backups and pseudonymised analytics rather than retaining them indefinitely.
10. Exporting your data
We believe leaving Nesk should be straightforward.
Nesk provides, or will provide as part of the supported account-management workflow, a simple way to export your data in a commonly usable machine-readable format such as CSV.
You should not have to remain a Nesk customer merely to retain access to information you created.
You may also have a legal right to data portability in circumstances covered by UK GDPR.
11. Deleting your account
You can request deletion of your Nesk account and associated personal information through the account-management process.
We intend account deletion to be clear and easy to execute.
We will not deliberately make account deletion harder than account creation in order to retain users.
After deletion, some information may remain temporarily in secure backups or where retention is required by law, but it will not continue to be used as an active Nesk account.
12. Your data protection rights
Depending on the circumstances, UK data protection law may give you rights including:
- the right to be informed about how we use your information;
- the right to access your personal information;
- the right to correct inaccurate information;
- the right to request deletion of your information;
- the right to restrict certain processing;
- the right to data portability;
- the right to object to certain processing; and
- rights relating to certain forms of automated decision-making.
Where processing is based on consent, you may withdraw that consent.
Where we rely on legitimate interests, you have the right to object to that processing in applicable circumstances.
You can exercise these rights by contacting [PRIVACY CONTACT EMAIL].
You also have the right to complain to the UK Information Commissioner's Office if you believe your personal information has been handled unlawfully.
13. Automated ranking
Nesk uses software to rank tasks and recommend what you might work on next.
This ranking uses information associated with your tasks and workflow, such as priority, urgency, effort and other task-management signals.
The recommendation is intended to help you organise your own work.
It does not make legal, employment, financial, credit or similarly significant decisions about you.
You remain free to ignore, defer or override a recommendation.
14. Security
We use reasonable technical and organisational measures designed to protect Nesk data against unauthorised access, alteration, loss or disclosure.
No online service can guarantee absolute security, but security and privacy are design requirements for Nesk rather than optional additions.
If we become aware of a personal-data breach, we will assess and handle it in accordance with applicable data protection law.
15. Changes to this policy
Nesk will evolve, and this policy may change with it.
If we make a material change to how we use personal information, we will make the updated policy available and provide additional notice where required.
We will not quietly reinterpret this policy to use existing user information for materially unrelated purposes.
The current version and its effective date will always be published here.
16. Our privacy commitment
Our aim is simple:
Your data exists to make Nesk work for you. It is not the product.
We want Nesk to succeed because people find it valuable enough to use and, where applicable, pay for—not because their behaviour can be sold to somebody else.