Task Pilot

Privacy Policy

Last updated August 25, 2026

Task Pilot is a task and calendar assistant operated by Elora Medical LLC. This policy explains what it stores, why, and how to get it deleted. It applies to the application at commandcenter.ceo.

What we store

Account data. Your name, email address, a hash of your password (never the password itself), and the workspace you belong to.

Work data you create. Tasks, subtasks, notes, files you attach, time-clock entries, invoices, contacts and messages you enter into the app.

Data from Google, when you connect an account. Calendar events, Gmail messages, and the email address of the connected account. Connecting is optional and can be undone at any time in Settings.

Operational records. Sign-in timestamps, an audit trail of administrative changes, and short-lived rate-limit counters.

Google user data, specifically

Task Pilot requests these scopes, and uses them only as described:

  • calendar and calendar.readonly — read your events so the planner schedules around them, and write the time blocks it plans back to your calendar.
  • gmail.readonly and gmail.modify — read messages so the app can surface them in its inbox and propose tasks from them, and mark them read/archived when you act on them in the app.
  • gmail.send — send only the messages you explicitly compose or approve.
  • userinfo.email — identify which Google account is connected.

Task Pilot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never sold, never used for advertising, and never used to train generalized AI or machine-learning models. It is not transferred to anyone except as needed to provide the features above, or where you direct it, or as required by law.

AI processing. When you use the features that draft replies or extract tasks from a message, the text of that message is sent to the AI provider configured for your workspace (Anthropic or OpenAI) to produce the draft. Those providers act as processors for that request and, under their API terms, do not use it to train their models. You can leave those features switched off.

Where it lives

Application data is stored in a Neon PostgreSQL database in the United States; uploaded files are stored in Cloudflare R2. The application runs on Cloudflare Workers. Access credentials are held as encrypted secrets and are not readable from the application interface.

How long we keep it

Your data is kept for as long as your workspace exists. Delete a record in the app and it is removed from the database. Disconnect a Google account in Settings and its stored tokens and synced events are deleted. Location coordinates recorded by the time clock are purged on a retention schedule your workspace owner sets (90 days by default).

Deleting your data

Email andrew@eloramedical.net from the address on the account and ask for deletion; the workspace and everything in it is removed. You can also revoke Task Pilot's access to your Google account at any time at myaccount.google.com/permissions, which stops all further access immediately.

Sharing

We do not sell data. Other members of your workspace see what their permissions allow, and nothing outside it. The service providers named above (Neon, Cloudflare, Google, Anthropic, OpenAI, Telnyx for SMS, Resend for transactional email) process data on our behalf to deliver the features you use.

Children

Task Pilot is a business tool and is not directed to anyone under 16.

Changes

If this policy changes materially, the date above changes and the notice appears in the app.

Contact

Elora Medical LLC — andrew@eloramedical.net