Legal

Privacy policy

Plain language first — this is a working draft pending legal review (M7-01), not final legal copy. It reflects exactly what the product does today.

Last updated:

What we collect

  • Account info you give us: name, email, avatar, timezone.
  • Content you create: workspaces, projects, tasks, comments, files you attach.
  • Messages you send: channel messages and direct messages, including reactions and any files you attach to them.
  • Product usage events: which features you use, tied to your user id — never your email or name (see the full event list on /docs/telemetry).
  • Marketing pageviews: On these pages we count visits on our own server — which page, which site linked here, whether you're on a phone or a laptop, which country, and whether you look like a person or a robot. No cookies, no scripts, and nothing that could tell us it was you. It is counted first-party, on our own server, as it answers the request — there is no analytics code in these pages, so nothing is set in your browser and nothing is read from it. Your IP address arrives with the request the way it does with any web page, and is used to send the page back and nothing else: it is never stored, not even hashed. Neither is your browser's user-agent string, and the table has no session id, visitor id or anything else that could join two visits together. Rows are deleted automatically 400 days after they are written. The full column list is on /docs/telemetry.
  • Billing info: handled by Stripe directly. We store your plan/band and subscription status, never full card numbers.

What we don't do

  • No third-party analytics or ad trackers, anywhere — including the marketing pages you're reading now.
  • No selling or renting your data to anyone, ever.
  • No AI training on your workspace content.

Who can see your data

  • Your teammates, scoped by workspace membership and role (owner/admin/member/guest) — see the permissions matrix in our docs.
  • Chat is scoped tighter than the rest of the workspace: public channels are visible to the whole team, but private channels and direct messages are visible only to their members — not to other members, and not to workspace owners/admins who aren't in them. A workspace export only ever includes the chat you can already see.
  • Sahnga staff, only when needed for support or abuse investigation, and only ever the founder today.
  • Service providers that process data on our behalf: Google Cloud/Firebase (hosting + database), Stripe (billing), Resend (email delivery). Each is bound by its own data-processing terms.

Your rights

  • Export: any workspace owner/admin/member can export full workspace data (JSON + CSV) at any time from the app.
  • Deletion: request account deletion from Account settings. We purge your profile and non-owned memberships after 30 days. If you still own a workspace, transfer ownership or delete it first — we'll tell you if that's blocking.
  • Chat messages you authored are anonymized on deletion, not erased: your name is removed and the author is shown as “Deleted user,” but the message text stays so your teammates' conversations remain readable. Tell us if you need authored messages fully removed instead.
  • Access/correction: edit your profile directly in Account settings, or contact us for anything the UI doesn't cover.

Data location & retention

  • Data lives on Google Cloud (Firestore, Cloud Storage, BigQuery) in the United States (nam5 multi-region).
  • Workspace content — including full chat history — is retained until you delete it or your account is purged. We never expire or gate message history behind a plan. Product-analytics events and the anonymous marketing pageview counts both expire automatically after 400 days. Security/audit logs are retained longer for abuse investigation and are never used for marketing.

Need a data-processing agreement for your business? See our DPA. Questions about anything above — privacy@sahnga.com.

12 N Sarah St. PMB1027
St. Louis, MO 63108

United States
(314) 472-8933