Legal

Privacy Policy

What we collect, what we do with it, and who else touches it. The plain-language summary is the honest short version, so read that first.

Last updated 30 July 2026

In plain language

What we collect
Your account details, the content you create in the app (tasks, docs, messages, files, meeting recordings and transcripts), and the basic technical data needed to run and secure the service.
What we do with it
Operate the product, keep it secure, bill your plan, and support you when you ask. We do not sell your data, we do not share it for advertising, and we do not train models on it.
No analytics, no ad tech
There is no third-party analytics SDK, tracking pixel or advertising script in the app or on this site. The only third-party script anywhere is Cloudflare Turnstile, on the contact form, to keep it from being flooded with spam.
Who else processes it
Cloudflare hosts the service and handles file storage, email sending and bot protection. PlanetScale hosts the database, in AWS London. Paddle handles payments as merchant of record. Anthropic powers the AI features. Google is involved only if you sign in with it or link a Google Doc. GitHub only if you connect a repository.
Where it lives
The production database runs in London (AWS eu-west-2). Files are stored on Cloudflare R2.
AI and your content
AI features send the relevant content to Anthropic through Cloudflare AI Gateway to produce a result, such as a summary, a suggestion or an answer. That content is not used to train models. If a project never uses an AI feature, none of its content is sent anywhere for that purpose.
Your rights
You can export or delete your data. You control exactly what clients and collaborators can see on each project, and internal docs, threads and GitHub references are never visible to a client account.

The full text below is not written yet. The summary above is accurate and describes what the product actually does. The numbered sections are the structure the reviewed document will fill. They are deliberately empty rather than filled with text that reads like law but has not been checked by anyone qualified to write it.

01 Who we are and how to reach us

Pending review The legal entity acting as data controller, its address, and the contact route for privacy questions and requests.

02 The data we collect

Pending review Each category (account, content, billing, technical and support data) with what it is and where it comes from.

03 Why we process it, and on what legal basis

Pending review The GDPR Article 6 basis for each purpose: contract, legitimate interest, consent or legal obligation.

04 How long we keep it

Pending review Retention periods per category, what happens on cancellation, and how long backups persist after deletion.

05 Subprocessors and international transfers

Pending review The formal subprocessor list with each one’s role and location, plus the transfer mechanism where data leaves the UK/EEA.

06 Your rights and how to exercise them

Pending review Access, rectification, erasure, portability, restriction and objection, with how to make a request, response times, and the right to complain to a supervisory authority.

07 Cookies and local storage

Pending review What is stored in the browser, what each item is for, and which are strictly necessary.

08 Security

Pending review The technical and organisational measures protecting the data, and the breach-notification commitment.

09 Changes to this policy

Pending review How changes are made and how you are told about material ones.

Questions about any of this? Get in touch.