LEGAL
Privacy Policy
This policy explains what information the service processes, why it is needed, how it is protected, and the controls available to you.
Effective August 3, 2026
Information we process
We process your authenticated email address and optional display name, workspace and board configuration, membership and sharing records, schedules, run history, and the reports or snapshots produced from sources you choose to connect.
When you connect a third-party service, we process the authorization tokens, API credentials, service-account material, and configuration required to retrieve the data you requested. We do not ask for or store your password for those services.
How we use information
Information is used to authenticate you, create and operate your workspace, retrieve requested source data, generate boards and briefs, run schedules, enable board sharing, prevent duplicate jobs, and keep an operational record of successful or failed runs.
Connected-source data is not sold and is not used to train general purpose AI models. The service does not run advertising trackers.
Storage and security
Structured application data is stored in a managed Cloudflare D1 database. Connection credentials and new dashboard snapshots are encrypted with AES-GCM before storage. Webhook tokens are stored as one-way hashes. Authorization checks are enforced on the server for workspace and board access.
Third-party services
The service sends requests only to providers you connect, such as Google, Microsoft, Slack, Atlassian, GitHub, GitLab, Apple, RevenueCat, and analytics providers. Their handling of information is governed by their own terms and privacy policies.
Retention and deletion
Data is retained while your account or a workspace you participate in remains active. You can disconnect sources individually. You can also permanently delete your account from Settings → Account & Security. Workspaces where you are the only owner are deleted with their credentials, reports, snapshots, webhooks, and run history. Shared workspaces with another owner are retained and your access is removed.
Your choices
You control which providers are connected, which reports run, which boards are shared, and when schedules are enabled. You may revoke a provider authorization at the provider and remove the corresponding connection from the service.
Contact
Privacy requests can be completed through the in-product account and connection controls. A dedicated privacy contact will be published with the final production domain before general availability.