Privacy Policy

Version 2026-01-15 · Effective January 15, 2026

This Privacy Policy explains what information we collect, how we use it, and the choices you have.

This is a starter-kit template, not legal advice. Replace it with a policy reviewed by your own counsel before launch.

1. Information we collect

  • Account data — your name, email address, and authentication metadata.
  • Organization data — the content you and your team create in the product.
  • Operational data — logs, device information for security, and usage events used to run and improve the service.

2. How we use information

We use your information to provide and secure the service, communicate with you, process payments where applicable, and comply with legal obligations. We do not sell your personal information.

3. Where your data lives

The service is self-hostable. When you run it, your data lives in the Postgres database you control. This policy describes the practices of the operator of the instance you are using.

4. Security

We enforce tenant isolation at multiple layers, including database row-level security, and connect to the database as a least-privilege role. No system is perfectly secure, but isolation is treated as a guarantee, not a convention.

5. Your choices

You can access and update your profile, export your organization's data, and delete your account. Deleting your account soft-deletes it immediately and purges it after a retention window.

6. Changes to this policy

We may update this policy. When we make material changes, we will update the version and ask you to re-accept the current version the next time you sign in.

7. Contact

Privacy questions? Reach us through the contact page.