Privacy Policy

Last updated: August 9, 2026

This Privacy Policy explains how do things (“we”, “us”, or “our”) collects, uses, and shares information when you use our workspace application (the “Service”). We aim to collect only what we need to run the Service.

1. Information we collect

  • Account information — your name, username, email address, and workspace details you provide when signing up or being invited.
  • Customer Data — the tasks, projects, comments, and files you and your team create in the Service.
  • Billing information — handled by Stripe. We store a customer and subscription identifier and plan status; we do not store full card numbers.
  • Technical data — authentication cookies, and limited log and error data used to keep the Service secure and working.

2. How we use information

  • to provide, maintain, and improve the Service;
  • to authenticate you and secure your account and workspace;
  • to process subscriptions and payments;
  • to send transactional email (invitations, billing notices, and account alerts);
  • to diagnose problems, prevent abuse, and comply with legal obligations.

3. Legal bases

Where the GDPR or similar laws apply, we process personal data to perform our contract with you (providing the Service), to pursue our legitimate interests (security and improvement), to comply with legal obligations, and, where required, with your consent.

4. Service providers

We share information with processors who help us run the Service:

  • Supabase — database, authentication, and file storage hosting.
  • Stripe — subscription billing and payment processing.
  • Resend — delivery of transactional email.
  • Vercel — application hosting and delivery.
  • GitHub — only if you connect a repository, to sync issues and pull requests you choose to share.

These providers process data on our behalf under their own security and privacy commitments. We do not sell your personal data.

5. Cookies

We use first-party cookies that are necessary to sign you in and remember your active workspace. For details, see our Cookie Policy.

6. Data retention

We keep account and Customer Data for as long as your workspace is active. When a workspace or account is deleted, we remove or anonymize associated data within a reasonable period, except where we must retain it to meet legal, tax, or security obligations.

7. Security

We use industry-standard measures to protect data, including encryption in transit, scoped access controls, and tenant isolation between workspaces. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.

8. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage much of your data directly in the app, or contact us to exercise these rights.

9. International transfers

Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for those transfers.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you and will update the “Last updated” date above.

12. Contact

For privacy questions or requests, contact us at support@dothings.fyi.