Privacy Policy

Last updated 31 July 2026

monotask is a coworking task bot for Twitch and Discord, operated by FlowCo. This policy describes exactly what it stores, why, where it lives, and how to get it removed. It describes the software as actually built — not a template.

What we store

Account identifiers. Your Twitch user ID and username, and/or your Discord user ID and username. These are how the bot recognises you across messages. We never receive or store your password for either platform.

Content you create. The text of tasks you add, whether they are complete, and their order. Task text is whatever you type — please don’t put sensitive personal information in it.

Activity. Check-ins, streaks, task completions, achievements, and which community they belong to. Voice-channel session times where a Discord server has that feature enabled.

Preferences. Your timezone, and whether your aggregate profile and results appear publicly. Overlay participation is controlled separately by each check-in.

If you are a streamer. Your channel and server identifiers, overlay theme settings, and — if you authorise stream events — an access token for your Twitch account. That token is encrypted at rest and used only to subscribe to your stream’s online/offline and raid events.

What we don’t store

Passwords. Payment details (monotask is free and takes no payments). Message content from chat other than the commands you address to the bot. Email addresses, unless you sign in to the web dashboard, where they are held by our authentication provider rather than by us.

Why we store it

To provide the service you asked for: keeping your task list, counting your streaks, and displaying a check-in on a streamer’s overlay when you explicitly ask us to. Under UK/EU data protection law our lawful basis is legitimate interest in operating a service you have chosen to use, and consent where you have explicitly authorised sharing, linking accounts, or granting stream-event access.

Private by default — and what check-in shares

Your personal task list is private. Your aggregate public profile and public leaderboard participation are also hidden until you opt in with !show in Twitch chat or the show action in Discord’s /privacy command. !hide opts out again without deleting your private tasks.

A separate, explicit !checkin or /checkin lets that community’s current overlay show your username, streak, and current open task text. An offline check-in waits for a stream for no more than two hours. A live check-in ends when that stream session ends, you use !checkout (or Discord’s checkout action), you hide, or its safety expiry is reached. Checking in never opts you into a public profile or leaderboards.

You have one global task list, so tasks added in one Twitch or Discord community follow you into another. They are not shown there unless you explicitly check in there too.

Where it lives

In a PostgreSQL database hosted by DigitalOcean in Amsterdam, Netherlands (EU), encrypted in transit. Deliberately chosen: most of our users are in Europe, and keeping data on EU soil keeps this simple.

Who else sees it

We do not sell your data, and we do not share it with advertisers. Twitch and Discord have their own policies covering the platforms themselves.

How long we keep it

Task and activity data is kept while your account exists, because streaks and history are the feature. Offline check-ins expire from public display after two hours; live check-ins disappear when the session ends and retain a 24-hour hard expiry only for long-stream and restart recovery. Checkout or hide removes a current check-in immediately. One-time linking rows are removed after their original short expiry, whether used or unused. Delete your data at any time — see below.

Your rights

If your Twitch or Discord identity is linked to your web account, the dashboard provides a JSON export and destructive-confirmation deletion. You can also request a copy, correction, or deletion by emailing hello@monotask.bot from an address we can tie to your account. Twitch/Discord-only guests must contact us from the provider account in question so we can verify ownership without relying on a public bearer link. We aim to respond within 30 days.

Monotask deletion removes product data but does not delete your shared FlowCo/Clerk sign-in. It retains only keyed, non-public markers needed to prevent silent account recreation and keep an active moderation block enforceable; no task content or raw provider identifier is kept in those markers. Self-service deletion refuses community owners; support must verify a transfer or permanent disconnect first so one person cannot erase a community's data. Deleted data may remain in managed backups until the provider’s verified rotation window ends.

Children

monotask is not directed at children under 13, and we don’t knowingly collect their data. Twitch and Discord both require users to be 13 or older.

Changes

If this policy changes materially we will update the date above and announce it in the communities using the bot.


monotask is operated by FlowCo. Questions or requests: hello@monotask.bot