Privacy Policy

Effective [effective date]

Template draft
Bracketed text such as [effective date] is a placeholder that has not been filled in, so this is not a final, published Privacy Policy.

[Legal business name] operates [Product name]. This policy explains what personal information we handle when you visit the site, sign in, use a workspace, or call the API. Contact us at [privacy email] with questions or requests.

Information we handle

We receive your email address, name, and any profile information you provide. We keep workspace membership, invitations, billing contact details, API key identifiers, usage counts, and account settings. When you agree to the Terms, we record the version, the time, and the exact wording you agreed to. For security and troubleshooting, we process session information, IP address, browser details, request metadata, and audit events. API requests include the content you choose to send for processing.

Why we use it

We use this information to send sign-in and invitation emails, authenticate users, provide the API, enforce plan limits, manage subscriptions, support users, and protect the service against abuse. Where data-protection law requires a lawful basis, we rely on steps you request before a contract or the contract itself to provide the service, our legitimate interests to keep it secure, and legal obligations for required billing records. We will ask separately before using information for an optional purpose that requires consent.

Service providers

Hosting, database, email, anti-abuse, and payment providers process information to help us run the service. Depending on deployment, these may include [hosting provider], [database provider], [email provider], [anti-abuse provider], and [payment provider]. If payments are enabled, the payment provider collects payment details and sends us billing and subscription status. Providers may process information in other countries; [describe applicable transfers and safeguards].

Sentry is our error-monitoring provider. It processes stack traces, route names, request methods, and sampled timing data so we can diagnose failures and slow requests. We configure diagnostic events to exclude request bodies, query parameters, headers, cookies, user identity, and database query contents.

Cookies and retention

We use session cookies to keep you signed in and a preference cookie for the workspace sidebar. Sessions expire after seven days unless revoked sooner. When the retention job is enabled, workspace audit events older than 90 days are deleted daily. We keep the record of each agreement to the Terms for as long as your account exists. We keep other account, billing, and usage records for as long as needed to provide the service, meet legal obligations, or resolve disputes. Account and workspace deletion controls are in settings; some records may remain where law requires retention.

Security

We use access controls and other reasonable measures to protect information. No online service can guarantee absolute security.

Your choices and rights

You can update your account information, revoke sessions and API keys, export workspace data if your role allows it, and request deletion in settings. Depending on where you live, you may also request access, correction, or a copy of your information, object to certain uses, or complain to a data-protection authority. Send a request to [privacy email].

Changes

We will post the current policy here, show a notice in the app when it changes, and give additional notice when required by law. If we introduce a new use that needs your consent, we will ask for it separately before that use begins.

Contact

Contact [privacy email] or [business mailing address] about this policy or your privacy rights.