Taskerise

Privacy policy

Last updated 29 Sept 2026.

Taskerise is a marketplace where advertisers fund campaigns and taskers do the work and are paid for it. Running that safely means holding a certain amount of information about both sides. This page says exactly what, why, and for how long.

It describes the service at taskerise.com, operated by [[LEGAL ENTITY NAME, registered address]].

The short version

We collect what the product needs to work and to be fair: who you are, how to reach you, the handles you say are yours, the work you did, and the money that moved. We do not sell any of it, and we do not run advertising trackers on this site.

What we collect

Your account. Usually an email address, and either a password (stored only as a hash, never as text) or a Google or Microsoft sign-in; an account made in Telegram may have none of these, only its Telegram sign-in (see below). A username, which is public. Optionally a display name, a name to show taskers, a country, a gender, a birth date, a short bio, a phone number and a profile photo, and whether that photo appears on your tasks. Your language and theme, if you set them in Account → Preferences. If you joined through someone's invite link, who invited you. A photo is re-encoded when you upload it — cropped to a square, with the location and camera details taken out — and only that copy is kept.

Verification. Whether your email is confirmed, and when. A phone number and its confirmation, if you use phone sign-in. If you switch on two-factor authentication, the secret behind it — encrypted at rest, not stored in readable form.

The handles you add. The account names you give us for each network. These are the whole point of the platform: a task is matched against them, and a reviewer compares your proof to them.

Work. Campaigns you create, including the target link and the brief. Tasks you claim, what you submitted, and the screenshots you uploaded as proof. Whether it passed, and why if it did not.

Money. Every movement through your wallet as a ledger entry. For deposits: the payment address or gateway reference and what the gateway told us about it. For withdrawals: the destination you gave — a wallet address, or an IBAN/Sheba with the account holder's name — and who reviewed it.

Support. Dispute threads and support tickets.

Notifications in Telegram. If you connect Telegram in your notification settings, the id of that chat and its Telegram username, so your notifications can be sent there.

Signing in with Telegram. If you use Taskerise inside Telegram (the Mini App opened from our bot) and choose to sign in with it, your Telegram user id and username, so opening it again signs you in. Telegram tells us these when you open the app. Your phone number reaches us only if you agree when Telegram asks to share it; it is then saved as your account's verified number. Other users never see any of these.

Notifications on your devices. If you turn them on for a phone or computer, the address your browser's push service gave it, the keys that encrypt messages to it, which browser it is, and which sign-in it belongs to.

Technical. Your browser's user-agent string, and when you were last seen. Your IP address is stored with each signed-in session (see Account → Sessions) and in the security audit log against actions that matter — signing in, changing security settings, moving money, opening a task's link — and is used in memory for rate limiting. When you sign in, we also note a random identifier for your browser, so we can tell when several accounts are used from the same one. We do not keep a general log of every page you visit.

Why we hold it

To run your account and keep it yours. To match tasks to the right people and let the other side check the work. To move money, and to be able to show where it went. To settle a dispute, where the record is the evidence. To detect fraud — faked proof, undone work, one person running several accounts. And where the law requires us to keep financial records.

Who else can see it

Other people on the platform. Your public profile, which anyone can open without signing in, shows your username, display name, profile photo, level, rating, public counts, when you joined and when you were last seen, and it also carries the country on your profile. An advertiser sees the username, photo and social handle of whoever sends work to their campaign, and a rounded version of their track record: roughly how many of their tasks people reviewed, the share that passed, and whether they are a trusted tasker. A tasker is not told who is behind a task: before taking it they see what it asks and a rounded version of the advertiser's record; once they take it, the name you chose for taskers, if you set one; and while they hold it, the link it leads to. Your profile photo appears on your tasks only if you turn that on in your account. Never your username, email address or phone number. Emails and phone numbers are refused in task text, rejection reasons and dispute messages. In a dispute, both sides see the whole thread, deliberately: there is no private channel to the administrator. If someone joined through your invite link, you see their username, when they joined, and the fee and your share on each of their paid tasks, but not which task it was; and anyone who opens your invite link sees your username.

Administrators. Staff can see your account, including your email address, your phone number and how you sign in, and its transactions: to handle tickets and disputes, review payouts and keep accounts safe. They cannot see your password — nobody can, it is only a hash — and nobody from Taskerise will ever ask you for it or for a two-factor code. Staff who look after accounts are told when a new one is made: its username, how it signed up and whether it came through an invitation or a promo code. They see this in the app, and by email, in their own Telegram chat or on their own devices if they turned those on for themselves.

Services we depend on. We send them only what the job needs:

  • Google — if you sign in with Google.
  • Microsoft — if you sign in with Microsoft.
  • Cloudflare Turnstile — the anti-bot check on sign-up and sign-in.
  • Telegram — to confirm a Telegram handle or a channel membership; if you connect it for notifications, to deliver them (each notification's text is sent to your chat); and if you use Taskerise inside Telegram, to say which Telegram account opened it.
  • Your browser's push service (Google for Chrome and most Android browsers, Apple for Safari, Mozilla for Firefox, Microsoft for Edge on Windows) — if you turn on notifications on a device, to deliver them there. Each one is encrypted for that one browser, so the push service carries it without being able to read it.
  • NOWPayments — crypto deposits.
  • ZarinPal — card deposits for accounts paying in Iranian rial.
  • Nobitex — an exchange-rate feed. No personal data is sent.
  • An AI provider (Google Gemini, or a fallback) — for writing suggestions and a check of proof screenshots. See below.
  • Our email provider — to deliver verification and notification mail.

We do not sell personal data, and we do not share it for advertising.

AI writing suggestions

When you ask for a suggestion on a writing task, we send an AI provider what the task says: the network and the action, the link it points to, its title, description and brief (with any email or phone number taken out), the language and the character limit. Your identity is not sent, and no account details go with it. We keep the prompt and the answer so a suggestion can be audited if a submission is disputed, and delete them after 30 days by default.

AI check of proof screenshots

When a task asks for screenshots, we send them to the same AI provider when you submit, made smaller, with the network, the action and the link the task points to (for a custom task, the advertiser's proof instructions, with any email or phone number taken out). It describes what the screenshots show: which app, whether the task is shown done, and the account names and comment it can read. We compare that with the task ourselves. Your handle and the text you sent are not sent with them, but a screenshot shows whatever was on your screen, so crop out anything you would rather not share.

If the screenshots plainly are not the task — from another app or not from an app at all, the task not shown done, or a comment other than the one you entered — we send them back and store nothing, so you can add the right ones; the task stays yours. If you are sure they are right, send them again: after two send-backs they go to the advertiser as they are, marked as sent back, and are never paid at once. This is never done for custom tasks. Otherwise the result is shown to the advertiser beside your screenshots, as a hint: it never passes or rejects your work, and the advertiser decides. If the AI cannot be reached, your work goes through and may be looked at later.

We keep what it found, and how many times your screenshots were sent back, with the task. The provider handles the images under its own terms.

How long we keep things

  • Your account and its history — while the account exists.
  • Financial records — retained after account closure where the law requires it. Ledger entries are append-only; a deleted account does not erase the record that money moved.
  • Your profile photo — until you replace or remove it, when the file is deleted.
  • AI suggestions — 30 days by default.
  • What the AI found in your screenshots, and any send-backs — as long as the task record is kept.
  • Sessions — 30 days by default, or until you end them from Account → Sessions.
  • A connected Telegram chat — until you disconnect it, send /stop to the bot, or block it.
  • Telegram sign-in — until you turn it off in Account → Security, or the account is closed.
  • A device with notifications on — until you turn them off or remove it, or its sign-in ends; one its push service says is gone, or that stops accepting them, is forgotten.
  • Backups — 14 days by default, after which they are overwritten.

Security

Passwords are hashed. Two-factor secrets are encrypted at rest. The site is served over HTTPS only, with a content security policy and strict transport security. Withdrawals require two-factor authentication. Account → Sessions lists every device signed in and lets you end any of them.

No system is perfect, and we would rather say so than claim otherwise.

Your choices

You can change or correct your profile, handles and preferences from Account at any time, remove your photo, and choose which notifications you receive. You can end any session. You can ask us for a copy of your data, or to delete your account — write to [[privacy@taskerise.com]]. Deletion removes your profile and personal details; it cannot remove financial records we are required to keep, or the content of a dispute the other party is also part of.

Depending on where you live you may have further rights — access, correction, erasure, portability, objection — and you can exercise them at the same address.

Cookies

Two cookies: one for your session, so you stay signed in, and one that recognises this browser when someone signs in, so we can tell when several accounts are used from the same one. It holds a random value and nothing about you. Your browser also keeps your theme and language, and an invite code for 30 days if you arrived through an invite link. If you change your language or theme in Account → Preferences, we save it on your account, so emails reach you in your language. There are no advertising or analytics cookies on this site.

Children

Taskerise is not for anyone under 18.

Changes

We will change this page when the product changes. The date at the top is the last time it did. If a change is significant, we will tell you in the app rather than quietly editing the page.

Contact

[[privacy@taskerise.com]] for anything on this page. Support tickets are the faster route for anything else.