Privacy Policy
What we collect, why, and how to control it.
2026-05-13
1. Information We Collect
We collect information you provide directly (account email, name, organization data, billing details), information generated by your use of the Service (audit logs, usage counts, IP address, user-agent), and cookies described in our Cookie Policy.
2. How We Use Information
- To operate, maintain, and secure the Service.
- To process payments and prevent fraud.
- To send transactional email (sign-in, invitations, billing).
- To improve the Service through aggregated, de-identified analytics.
- To comply with legal obligations.
3. Service Providers
We share data with vetted processors only where necessary to deliver the Service:
- Authentication providers (Google, GitHub) when you sign in via OAuth.
- Payments processed by Creem; we do not store full card numbers.
- Hosting and infrastructure for application servers and databases.
- Email delivery for transactional messages.
4. Data Retention
Account data is retained while your account is active. Audit logs are retained for 90 days. Billing records are retained as required by tax and accounting law (typically 7 years).
5. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. Two of these are self-serve from your account's Account settings:
- Download your data. Exports a JSON bundle covering your profile, sessions, linked sign-in providers, organizations, subscription, usage counters, and notifications. Satisfies access (Art. 15) and portability (Art. 20) requests.
- Delete account. Permanently removes your account and the personal data we hold about you. Active subscriptions are canceled. Satisfies erasure requests (Art. 17). Operational records (e.g. bounce/complaint logs keyed by email address) are retained for the period in §4.
For other rights, or to make a request on behalf of someone else, contact [email protected]. We will respond within the period required by applicable law.
6. Children
The Service is not directed to children under 13 (or 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
7. International Transfers
We may transfer data outside your country of residence. Where required, we rely on standard contractual clauses or equivalent safeguards.
8. Security
We protect your data with encryption in transit (TLS), encryption at rest where supported, principle-of-least-privilege access, and audit logging. No system is 100% secure; report concerns to [email protected].
9. Changes
We may update this policy. Material changes will be announced; the “last updated” date above always reflects the current version.
10. Contact
Privacy questions: [email protected]. Mailing address: Markey, Remote — operating globally.
