Last updated 19 August 2026
Your email address and display name, the organizations you belong to, and the content you create: projects, boards, cards, comments, checklists and uploaded files. Avatars are stored as a URL if you have one.
To run the service. Your email identifies your account, enables sign-in links, and lets teammates see who they're working with. There is no advertising and no profiling.
Members of the organizations you belong to can see your name, email and the content you create there. Access is enforced in the database itself, per row, not only in the interface.
Files you attach to cards are stored on Sanity's content delivery network. Unlike the rest of your data, these are served from an unlisted public URL rather than being access-checked on every request: the address is long and unguessable, but anyone you share it with — or anyone it leaks to — can open it without signing in, and that remains true after the file is deleted for up to 30 days while caches expire. Which files exist on a card is still visible only to members of the project. Don't attach anything you would not be willing to share by link.
Supabase hosts the database, authentication and file staging. Sanity stores uploaded files and public page content. Resend delivers notification emails. Vercel hosts the application. Each sees only what it needs to perform that function.
Notification emails are sent when you're assigned to a card or mentioned in a comment. You can turn them off per organization in Settings. Sign-in and account emails are not optional.
Content persists until deleted. Removing an organization deletes its projects, boards and cards, and the files attached to them are reclaimed from storage. To delete your account and personal data entirely, contact the organization owner or the operator of this instance.
One session cookie, set by Supabase Auth to keep you signed in. No analytics or tracking cookies.
See also the Terms of Service.