DRAFT TEMPLATE — this document has not been reviewed by an attorney and is not a compliance statement. It must be reviewed and finalized by qualified counsel before commercial use.
What your workspace puts in: members and roles, calendar events, tasks, contacts, knowledge notes, vault entries, learning assignments, and profile photos. Operational records: sign-in methods (hashed passwords, passkey public keys, one-time link hashes), an audit log of actions, and plan/billing status. Vault secret values are encrypted at rest with a key derived per workspace.
Payments are processed by Stripe. We never see or store card numbers — only subscription status and a customer reference.
Transactional email (sign-in links, invites, receipts) is delivered via our email provider using the address on your member profile. We don't send marketing email without explicit opt-in.
Child accounts exist inside a workspace, are created and controlled by that workspace's adults, and have the most restricted role by default. We collect no more information about children than the workspace itself chooses to store.
The workspace Owner can export all workspace data (Settings → export) and delete the workspace entirely, which removes its data from the live system; encrypted off-site backups age out on their retention schedule.
Privacy questions: contact the support address shown in-app.