For consultants, freelancers and small businesses

How to keep client information confidential

Client details kept on your own computer, locked when you step away, encrypted wherever they travel, and shared with an AI agent only as far as you allow.

About 20 minutesMac and WindowsNeeds Pro

To keep client information confidential, keep it on a computer you control, lock it when you step away, and encrypt every copy that leaves it. In PrimeTask a client can have a Space that never leaves your computer, a PIN locks the app, synced folders and backups take a password, and an AI agent sees only the Spaces you allow.

Updated · Checked with PrimeTask 1.0.5 · PrimeTask Team

PrimeTask

This computerWhere the client's data livesCopies that leave itEach one encryptedWho else can read itOnly what you allowPIN lockWhen you step awayClient SpaceKept on this computerFile SyncEncrypted in the folderBackupsLocked with a passwordYour AI agentOnly the Spaces you tick

How it fits together

Select a part, in the drawing or here, to see what it does and what it feeds.

What flows

Encrypted as it leaves

Client Space to File Sync

Locked with a password

Client Space to Backups

Only if you tick it

Client Space to Your AI agent

Part ofLinkedLeaves encryptedRead by
Every connection, in words
  • PIN lock is linked to Client Space.
  • Client Space is linked to File Sync.
  • Client Space is linked to Backups.
  • Client Space is linked to Your AI agent.
  • Encrypted as it leaves: Client Space to File Sync.
  • Locked with a password: Client Space to Backups.
  • Only if you tick it: Client Space to Your AI agent.

How the parts of keeping client information confidential connect, and what happens to each copy that leaves

The problem

Client information can leak in ordinary ways: a laptop left open, a backup copied to cloud storage without a password, a sync folder someone else can still open, notes pasted into an AI tool.

When the records live on your own computer, each of those is a choice you control. This guide makes each one on purpose.

What it uses

Five parts, one connected system

Each card opens its docs article in a new tab, for the detail behind the steps.

Spaces

A Space for each client, kept on this computer

Docs for Spaces (opens in a new tab)

Security

A PIN and auto-lock for when you step away

Docs for Security (opens in a new tab)

File Sync Personal

Sync through a folder you choose, encrypted with your password

Docs for File Sync Personal (opens in a new tab)

Data Management

Backups locked with a password, nightly if you like

Docs for Data Management (opens in a new tab)

Bring Your Own AI

An AI agent limited to what you allow

Docs for Bring Your Own AI (opens in a new tab)

Step 1

Give each client a Space of their own

Spaces (opens in a new tab)

Open Settings → Spaces and create a Space for a client whose work must stay apart. Leave its sync on No Sync, the default for a new Space: its data then stays on this computer only.

Everything for that client, from tasks and projects to notes and contacts, stays inside it, apart from your other work.

Step 2

Lock PrimeTask when you step away

Security settings (opens in a new tab)

Open Settings and the Security card, then set a PIN. Save the recovery codes it shows you once: they're the only way back in if you forget the PIN.

Turn on auto-lock to cover the screen after a quiet spell, and use Lock Screen on the Profile card when you walk away. A connected AI agent waits while PrimeTask is locked.

Step 3

Turn on your computer's disk encryption

PIN protection is not disk encryption (opens in a new tab)

The PIN protects the app you see, not your files on disk. Someone with the disk and the right tools could still read them.

Turn on FileVault on a Mac, or BitLocker on Windows, and use both together: disk encryption for the files, the PIN for the app.

Step 4

Encrypt a Space that syncs

File Sync Personal (opens in a new tab)

If a client's Space has to reach your other computers, choose File Sync with a folder you pick, and turn on Password Protection. The folder then holds encrypted files its provider can't read.

Keep the password somewhere you trust: without it, the Space can't be read, and there is no recovery.

Step 5

Put a password on backups

Data Management (opens in a new tab)

Open Settings → Data Management and give a backup a password whenever the file leaves your computer: uploaded to cloud storage, emailed, or handed to someone. Without one, anyone holding the file can read every task, note and contact in it.

PrimeTask doesn't keep the password, so store it in a password manager.

Step 6

Keep a confidential client's contacts in their project

Using PrimeCRM on a project (opens in a new tab)

Open the client's project, press E, turn on Enable CRM and choose Isolated. The project gets its own private contacts, companies and activities, kept out of your main CRM.

Needs Pro. PrimeCRM is part of Pro. On Standard, give the client a Space of their own instead.

Step 7

Decide what an AI agent can see

Bring Your Own AI (opens in a new tab)

In Settings → External Integrations → MCP Server, keep Write off until you trust the agent, and set Space Access to Selected only, ticking just the Spaces it may use. The Audit Log records every call.

PrimeTask sends your data nowhere, but the agent may send what it reads to its own provider. For client work, connect one you trust, or a local model in LM Studio.

The checklist

The whole list

For each client whose information must stay private:

  • A Space of their own, left on No Sync unless it must sync
  • If it syncs: File Sync with Password Protection
  • A PrimeTask PIN and auto-lock on every computer you use, since each PIN belongs to one computer
  • FileVault or BitLocker turned on
  • Backups with a password, the automatic ones included
  • On Pro: the client's project CRM set to Isolated
  • An AI agent limited to the Spaces you tick, with Write off unless it needs it

Variations

Make it yours

Three ways to change the setup to fit how you work.

Daily encrypted backups

Turn on auto-backup in Settings → Data Management and give it a password. Every day's backup is then encrypted too, at the time you choose.

Agents that work while you're away

If an agent must carry on while PrimeTask is locked, the Security card has a switch for it. It's off by default, and while it's on, anyone who can reach the agent can change your work without unlocking.

One Space for several clients

Pro
If your clients don't need to be kept apart from each other, keep them in one Space and set each client's project CRM to Isolated.

Reuse

Save it for next time

Set it up once, and start the next one from it.

A reminder for every new client

Type save:newclient Confidentiality check for the new client !high in Quick Add once. After that, /newclient fills in the line.

Questions

Common questions

No. Your Spaces are stored on your computer, and a Space on No Sync never leaves it. A Space only travels when you choose to sync it, through iCloud or a folder you pick, never through a PrimeTask server.

Not on its own. It keeps client data where you decide and gives you the locks on this page. Your professional rules decide the rest, such as who may see a file and how long you keep it.

No. A PIN locks the app you see, not the files on your disk. Turn on FileVault on a Mac or BitLocker on Windows as well.

Use a recovery code to get back past a forgotten PIN. Passwords for encrypted backups and for a password-protected Space can't be recovered by anyone, so keep them in a password manager.

Only what you allow: the Spaces you tick under Space Access, read-only unless you turn on Write, and nothing while PrimeTask is locked unless you switch that on. The audit log shows every call it made.

Set this up with your own work.

The free trial runs for 14 days and includes Pro.