Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains how do things (“we”, “us”, or “our”) collects, uses, and shares information when you use our workspace application (the “Service”). We aim to collect only what we need to run the Service.
1. Information we collect
- Account information — your name, username, email address, and workspace details you provide when signing up or being invited.
- Customer Data — the tasks, projects, comments, and files you and your team create in the Service.
- Billing information — handled by Stripe. We store a customer and subscription identifier and plan status; we do not store full card numbers.
- Technical data — authentication cookies, and limited log and error data used to keep the Service secure and working.
2. How we use information
- to provide, maintain, and improve the Service;
- to authenticate you and secure your account and workspace;
- to process subscriptions and payments;
- to send transactional email (invitations, billing notices, and account alerts);
- to diagnose problems, prevent abuse, and comply with legal obligations.
3. Legal bases
Where the GDPR or similar laws apply, we process personal data to perform our contract with you (providing the Service), to pursue our legitimate interests (security and improvement), to comply with legal obligations, and, where required, with your consent.
4. Service providers
We share information with processors who help us run the Service:
- Supabase — database, authentication, and file storage hosting.
- Stripe — subscription billing and payment processing.
- Resend — delivery of transactional email.
- Vercel — application hosting and delivery.
- GitHub — only if you connect a repository, to sync issues and pull requests you choose to share.
These providers process data on our behalf under their own security and privacy commitments. We do not sell your personal data.
5. Cookies
We use first-party cookies that are necessary to sign you in and remember your active workspace. For details, see our Cookie Policy.
6. Data retention
We keep account and Customer Data for as long as your workspace is active. When a workspace or account is deleted, we remove or anonymize associated data within a reasonable period, except where we must retain it to meet legal, tax, or security obligations.
7. Security
We use industry-standard measures to protect data, including encryption in transit, scoped access controls, and tenant isolation between workspaces. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage much of your data directly in the app, or contact us to exercise these rights.
9. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for those transfers.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you and will update the “Last updated” date above.
12. Contact
For privacy questions or requests, contact us at support@dothings.fyi.