Last updated: June 3, 2026 · Vulnerability Disclosure Policy v1.0
Found a security issue? We welcome coordinated disclosure from security researchers. Read the policy below, then report it.
Report a vulnerabilityEmail content is processed in-memory only for AI scoring and draft generation, then discarded. For tasks created from emails, we persist the sender, subject, date, a short preview snippet of the body, and any reply you've drafted — but never the full email body or attachments.
All data travels through secure encrypted channels, both in transit and at rest. Connection tokens are stored with additional encryption using separate key management.
Emails flagged as revenue risk (invoices, payment requests, deal-critical) can NEVER be auto-sent. This rule is enforced at the service layer — it cannot be overridden by users, admins, or API calls.
Credits are deducted before an AI action runs. If the action fails for any reason, credits are automatically refunded. You never pay for failed operations.
Version 1.0 · Effective 2026-06-03 · Operated by Navya Gourmet Private Limited
DailyTaskProAI is dedicated to preserving data security by preventing unauthorized disclosure of information. This policy gives security researchers instructions for conducting vulnerability discovery activities, explains which systems and types of activity are in scope, how to send vulnerability reports, and how long we ask you to wait before publicly reporting vulnerabilities you have identified.
We request that you:
Security research carried out in conformity with this policy is deemed permissible. We will work with you to swiftly understand and fix the problem, and DailyTaskProAI will not suggest or pursue legal action in connection with your research.
This policy applies to the following systems operated by DailyTaskProAI:
Any service not explicitly listed above — including related and third-party services — is out of scope and may not be tested. Vulnerabilities in third-party solutions DailyTaskProAI interacts with (Google APIs, Razorpay, Stripe, Hostinger) should be reported directly to the relevant vendor under their disclosure policy. Email security@dailytaskproai.com if you are unsure whether a target is in scope.
The following test types are not authorized:
To report any security flaws, email security@dailytaskproai.com. We will acknowledge receipt of your report by the next business day and keep you updated on our progress. Reports may be submitted anonymously.
To process and respond to a vulnerability report effectively, please include:
If possible, please provide your report in English.
If you choose to give your contact information, we will communicate with you transparently and in a timely manner. We will acknowledge receipt of your report within three business days, keep you informed on vulnerability confirmation and remedy to the best of our ability, and welcome a dialogue on the technical concerns you raise.
For vulnerabilities affecting Google user data accessed via DailyTaskProAI's OAuth integration (Gmail and Google Calendar restricted scopes), DailyTaskProAI commits to additional reporting to Google Security in line with the Google API Services User Data Policy and the Limited Use requirements.
Critical Google-data vulnerabilities will be:
This reporting is in addition to — not in place of — any user notification and regulator filings required by applicable law.
A machine-readable contact entry is also available at /.well-known/security.txt per RFC 9116.