For consultants, freelancers and small businesses
How to keep client information confidential
Client details kept on your own computer, locked when you step away, encrypted wherever they travel, and shared with an AI agent only as far as you allow.
To keep client information confidential, keep it on a computer you control, lock it when you step away, and encrypt every copy that leaves it. In PrimeTask a client can have a Space that never leaves your computer, a PIN locks the app, synced folders and backups take a password, and an AI agent sees only the Spaces you allow.
Updated · Checked with PrimeTask 1.0.5 · PrimeTask Team
PrimeTask
How it fits together
Select a part, in the drawing or here, to see what it does and what it feeds.
What flows
Encrypted as it leaves
Client Space to File Sync
Locked with a password
Client Space to Backups
Only if you tick it
Client Space to Your AI agent
Every connection, in words
- PIN lock is linked to Client Space.
- Client Space is linked to File Sync.
- Client Space is linked to Backups.
- Client Space is linked to Your AI agent.
- Encrypted as it leaves: Client Space to File Sync.
- Locked with a password: Client Space to Backups.
- Only if you tick it: Client Space to Your AI agent.
How the parts of keeping client information confidential connect, and what happens to each copy that leaves
The problem
Client information can leak in ordinary ways: a laptop left open, a backup copied to cloud storage without a password, a sync folder someone else can still open, notes pasted into an AI tool.
When the records live on your own computer, each of those is a choice you control. This guide makes each one on purpose.
What it uses
Five parts, one connected system
Each card opens its docs article in a new tab, for the detail behind the steps.
File Sync Personal
Sync through a folder you choose, encrypted with your password
Docs for File Sync Personal (opens in a new tab)Data Management
Backups locked with a password, nightly if you like
Docs for Data Management (opens in a new tab)Bring Your Own AI
An AI agent limited to what you allow
Docs for Bring Your Own AI (opens in a new tab)Step 1
Give each client a Space of their own
Spaces (opens in a new tab)Open Settings → Spaces and create a Space for a client whose work must stay apart. Leave its sync on No Sync, the default for a new Space: its data then stays on this computer only.
Everything for that client, from tasks and projects to notes and contacts, stays inside it, apart from your other work.
Step 2
Lock PrimeTask when you step away
Security settings (opens in a new tab)Open Settings and the Security card, then set a PIN. Save the recovery codes it shows you once: they're the only way back in if you forget the PIN.
Turn on auto-lock to cover the screen after a quiet spell, and use Lock Screen on the Profile card when you walk away. A connected AI agent waits while PrimeTask is locked.
Step 3
Turn on your computer's disk encryption
PIN protection is not disk encryption (opens in a new tab)The PIN protects the app you see, not your files on disk. Someone with the disk and the right tools could still read them.
Turn on FileVault on a Mac, or BitLocker on Windows, and use both together: disk encryption for the files, the PIN for the app.
Step 4
Encrypt a Space that syncs
File Sync Personal (opens in a new tab)If a client's Space has to reach your other computers, choose File Sync with a folder you pick, and turn on Password Protection. The folder then holds encrypted files its provider can't read.
Keep the password somewhere you trust: without it, the Space can't be read, and there is no recovery.
Step 5
Put a password on backups
Data Management (opens in a new tab)Open Settings → Data Management and give a backup a password whenever the file leaves your computer: uploaded to cloud storage, emailed, or handed to someone. Without one, anyone holding the file can read every task, note and contact in it.
PrimeTask doesn't keep the password, so store it in a password manager.
Step 6
Keep a confidential client's contacts in their project
Using PrimeCRM on a project (opens in a new tab)Open the client's project, press E, turn on Enable CRM and choose Isolated. The project gets its own private contacts, companies and activities, kept out of your main CRM.
Needs Pro. PrimeCRM is part of Pro. On Standard, give the client a Space of their own instead.
Step 7
Decide what an AI agent can see
Bring Your Own AI (opens in a new tab)In Settings → External Integrations → MCP Server, keep Write off until you trust the agent, and set Space Access to Selected only, ticking just the Spaces it may use. The Audit Log records every call.
PrimeTask sends your data nowhere, but the agent may send what it reads to its own provider. For client work, connect one you trust, or a local model in LM Studio.
The checklist
The whole list
For each client whose information must stay private:
- A Space of their own, left on No Sync unless it must sync
- If it syncs: File Sync with Password Protection
- A PrimeTask PIN and auto-lock on every computer you use, since each PIN belongs to one computer
- FileVault or BitLocker turned on
- Backups with a password, the automatic ones included
- On Pro: the client's project CRM set to Isolated
- An AI agent limited to the Spaces you tick, with Write off unless it needs it
Variations
Make it yours
Three ways to change the setup to fit how you work.
Daily encrypted backups
Agents that work while you're away
One Space for several clients
ProReuse
Save it for next time
Set it up once, and start the next one from it.
A reminder for every new client
save:newclient Confidentiality check for the new client !high in Quick Add once. After that, /newclient fills in the line.Questions
Common questions
No. Your Spaces are stored on your computer, and a Space on No Sync never leaves it. A Space only travels when you choose to sync it, through iCloud or a folder you pick, never through a PrimeTask server.
Not on its own. It keeps client data where you decide and gives you the locks on this page. Your professional rules decide the rest, such as who may see a file and how long you keep it.
No. A PIN locks the app you see, not the files on your disk. Turn on FileVault on a Mac or BitLocker on Windows as well.
Use a recovery code to get back past a forgotten PIN. Passwords for encrypted backups and for a password-protected Space can't be recovered by anyone, so keep them in a password manager.
Only what you allow: the Spaces you tick under Space Access, read-only unless you turn on Write, and nothing while PrimeTask is locked unless you switch that on. The audit log shows every call it made.
Related
More setups like this
Other jobs, set up the same way.
How to keep track of professional contacts
Everyone you know professionally, what you last talked about, and a nudge before each connection goes quiet.
Client follow up tracker
Every promise to get back to a client, on a date, with the history of what was said.
Client project tracker
Every client, their projects and your next step, in one place.
Set this up with your own work.
The free trial runs for 14 days and includes Pro.
