Privacy Policy
What personal data the platform holds, why, and what it will never do with it.
Last updated 21 August 2026
What we hold
For each identity: a name, an email address, the roles held, and the tenancy. Optionally a mobile number, where one has been given for notices that ride SMS. Nothing else about a person is required to use the product.
What the record contains about people
Every event names its actor, because an audit record that cannot say who did something is not an audit record. That attribution is the point of the system and cannot be switched off. It is visible to those in your tenancy whose role permits it, and to nobody outside it.
Communication
The platform sends across email, in-app, SMS and push. Most of it is subject to your preferences, which you set per category and per channel. A defined set of notices is not: security events, payment failures, compliance breaches, and data-protection notices such as a deletion request. You are entitled to be told your account was locked whatever you have muted, and a preference control that could suppress that would be a control that harms you.
Marketing mail is separate and consent-based, with a working unsubscribe on every message and a permanent withdrawal until you re-subscribe. Mandatory notices carry no unsubscribe link, because an unsubscribe that cannot work is worse than none.
What we do not do
- We do not sell personal data, and we do not share it with advertisers.
- We do not train models on your project data.
- We do not use geolocation to decide what language to show you — that asks where somebody is standing to answer what they read, and is wrong for every expatriate engineer on a project.
- We do not send project figures by email. The weekly issue is role-targeted, not data-personalised, because a message leaves the platform's access controls behind the moment it is sent.
Your rights
You can request an export of the personal data we hold about you, and its deletion. Deletion of an identity removes the person's contact details and credentials. It does not rewrite the event chain, because doing so would destroy the integrity of a record other parties rely on — the events retain an actor reference, and the person behind it is no longer resolvable.
Sub-processors
Email is delivered through an SMTP relay you can see named in your own delivery log. AI actions are executed by the provider recorded on the event, with the model class and cost. Every channel that has no provider configured records as dispatched-not-transmitted rather than as delivered.
This document describes how the platform behaves. Where it states a technical guarantee — chaining, redaction, tenancy isolation, notice handling — that behaviour is implemented and tested, and the corresponding test is the thing that keeps this page true.