§ Legal

Privacy Policy

What we collect, why, and how to control it.

Last updated

2026-05-13

1. Information We Collect

We collect information you provide directly (account email, name, organization data, billing details), information generated by your use of the Service (audit logs, usage counts, IP address, user-agent), and cookies described in our Cookie Policy.

2. How We Use Information

  • To operate, maintain, and secure the Service.
  • To process payments and prevent fraud.
  • To send transactional email (sign-in, invitations, billing).
  • To improve the Service through aggregated, de-identified analytics.
  • To comply with legal obligations.

3. Service Providers

We share data with vetted processors only where necessary to deliver the Service:

  • Authentication providers (Google, GitHub) when you sign in via OAuth.
  • Payments processed by Creem; we do not store full card numbers.
  • Hosting and infrastructure for application servers and databases.
  • Email delivery for transactional messages.

4. Data Retention

Account data is retained while your account is active. Audit logs are retained for 90 days. Billing records are retained as required by tax and accounting law (typically 7 years).

5. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Two of these are self-serve from your account's Account settings:

  • Download your data. Exports a JSON bundle covering your profile, sessions, linked sign-in providers, organizations, subscription, usage counters, and notifications. Satisfies access (Art. 15) and portability (Art. 20) requests.
  • Delete account. Permanently removes your account and the personal data we hold about you. Active subscriptions are canceled. Satisfies erasure requests (Art. 17). Operational records (e.g. bounce/complaint logs keyed by email address) are retained for the period in §4.

For other rights, or to make a request on behalf of someone else, contact [email protected]. We will respond within the period required by applicable law.

6. Children

The Service is not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

7. International Transfers

We may transfer data outside your country of residence. Where required, we rely on standard contractual clauses or equivalent safeguards.

8. Security

We protect your data with encryption in transit (TLS), encryption at rest where supported, principle-of-least-privilege access, and audit logging. No system is 100% secure; report concerns to [email protected].

9. Changes

We may update this policy. Material changes will be announced; the “last updated” date above always reflects the current version.

10. Contact

Privacy questions: [email protected]. Mailing address: Markey, Remote — operating globally.

Questions? Email [email protected].

We use cookies

Strictly-necessary cookies keep you signed in and protect this site. Optional cookies help us remember preferences and understand product usage. See our Cookie Policy for the full list.