DATA & TRUST

How Aitaskora stores and moves your data.

The owner workspace is local-first. Online services are used only for approval records you publish and approval emails you send.

1 · YOUR BROWSER

Owner workspace

Project briefs, scope baselines, client requests, commercial profiles, work logs, costs, backup dates, and private approval owner keys are stored in browser local storage.

Risk:

Clearing browser storage may remove this information. Export backups regularly.

2 · CLOUDFLARE D1

Published approval record

When you explicitly create an approval, the selected scope or change record is stored online with its expiry, view count, client decision, comment, and decision time.

Not uploaded automatically:

Your full local workspace and unrelated project records.

3 · RESEND

Transactional email

When direct delivery is used, the recipient, subject, note, approval summary, and secure page link are sent to the configured email provider.

Fallback:

Without direct email configuration, Aitaskora opens your device email application.

Optional account and encrypted multi-device sync

An account is optional. Sign-in uses an eight-digit code and a Secure, HttpOnly session cookie.

The browser encrypts the workspace with AES-GCM. The key is derived from the private passphrase with PBKDF2 and a random salt. The passphrase and key are never uploaded. The server stores ciphertext, revision, salt, IV, integrity hash, device label, update time, and aggregate counts.

When both local and cloud states changed, Aitaskora refuses automatic overwrite. A forgotten passphrase makes the encrypted copy unrecoverable.

Recovery Center and automatic snapshots

Aitaskora keeps up to six recent, distinct workspace snapshots inside the current browser. A snapshot is created automatically after workspace changes and immediately before project deletion, backup restoration, integrity repair, or factory reset. Recovery snapshots are local and may disappear if the browser’s site data is cleared.

Backup and moving devices

Use Settings → Export backup to create a JSON file containing your projects, change records, work logs, commercial profiles, and private owner references. Restore that file in another browser to move the workspace. The restore process now displays a content preview and saves the current workspace into Recovery Center before replacement.

Deleting one project

Project deletion removes the project and its linked local requests, profile, work logs, and local approval-owner references. Aitaskora first attempts to revoke known active approval links. If revocation fails and you continue, the remote record may remain reachable while the local owner key is lost.

Factory reset

Factory reset removes all Aitaskora local-storage records from the current browser. It requires typing RESET and attempts to revoke known active approval links first. Export a backup before using it.

Approval evidence and follow-up

For each published approval, the owner can retrieve an evidence record containing the exact published content, a SHA-256 content fingerprint, page views, client decision details, and the complete transactional email-attempt history stored for that approval. Evidence can be printed or exported as JSON.

Follow-up dates, reminder counts, and reminder timing are stored locally in the owner workspace. Sending a reminder uses the same locked project recipient and the same pending approval page.

Client decision review and receipt

Before submitting, the client sees a final review of the selected decision, identity details, comment, and commercial impact. Rejection and requested changes require a written reason. The submitted email must match the email stored on the approval record when one is available.

After the decision, Aitaskora creates a deterministic receipt ID and SHA-256 content fingerprint. The client may print the receipt, save it as PDF, or download a JSON copy. When transactional email is configured, a confirmation receipt is also sent automatically to the client.

Pilot feedback and safe diagnostics

Feedback is submitted only when the user opens and sends the feedback form. Aitaskora stores the feedback type, rating, role, use intent, written message, optional reply email, source, app version, and optional safe diagnostics.

Safe diagnostics include record counts and device context but exclude project names, client names, client emails, request text, scope content, approval links, and encryption passphrases. Rate limiting uses a daily hashed request fingerprint; raw IP addresses are not stored in the feedback record.

What Aitaskora does not guarantee

Aitaskora documents commercial decisions but does not guarantee legal enforceability, identity verification, electronic-signature compliance, inbox delivery, or the correctness of estimates and classifications.