Legal
Privacy Policy
Last updated: 4 August 2026
Effective: 4 August 2026 · Last updated: 4 August 2026
This explains what we collect, why, and what you can do about it. It covers batondeck.com and the BatonDeck service.
Controller: BatonDeck Inc., [REGISTERED ADDRESS — to be completed] · Contact: privacy@batondeck.com
Two roles, and the difference matters. For account and billing data we're a controller — we decide why and how it's processed. For the content you put on your boards, we're a processor acting on your instructions; your own privacy policy governs that data, and
03-dpa.mdsets the terms. This policy covers both, but §2 is where the distinction bites.
1 · What we collect
You give us
| Account | Name, email, company name, profile picture. ⚠️ We don't store passwords — sign-in is handled by an identity provider and we hold only signed, expiring access tokens |
| Billing | Company details and billing address. ⚠️ Card details go to Stripe and never touch our servers |
| Content | Boards, tasks, comments, context items, attachments, memory entries — your Customer Data |
| Support | Whatever you send us in a ticket or email |
Collected automatically
| Usage | Features used, actions taken, timestamps, session duration |
| Device | IP address, browser type and version, operating system, screen size |
| Log | API requests, error traces, performance timings |
| Agent activity | Which Agent connected, which MCP tools were called, when, and with what result |
| Cookies | See §7 |
From third parties
- Stripe — subscription status, payment success/failure, the last four digits of your card
- OAuth providers, if you sign in with one — name, email, avatar
⚠️ What we ask you not to send
Don't put special-category data on your boards — health, biometric, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, government ID numbers, payment card numbers, or children's data. The Service isn't designed for it, and §5 of the Terms prohibits it.
2 · Why we process it, and our legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | Account, content, usage | Contract |
| Process payments | Billing | Contract |
| Support | Account, support, logs | Contract / legitimate interests |
| Security, fraud and abuse prevention | Log, device, usage | Legitimate interests |
| Improve the Service | Aggregated, de-identified usage | Legitimate interests |
| Product and marketing email | Account | Consent (opt-in; unsubscribe any time) |
| Legal compliance | As required | Legal obligation |
For Customer Data specifically we act on your documented instructions as a processor — 03-dpa.md.
⚠️ We do not train AI models on your data
BatonDeck does not use Customer Data to train, fine-tune or improve any AI model, and does not provide Customer Data to any third party for that purpose.
This commitment covers our own conduct. When you connect an Agent, content is transmitted to the model provider you selected in order to fulfil your request. That provider's terms — not ours — govern what it does with the data it receives, and we don't control them. We don't send your data to model providers on our own initiative. If this matters to you, and it should, review your provider's terms.
3 · Who we share it with
We don't sell personal information. We've never done it and we don't intend to.
Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Hosting, database (Firestore), storage, messaging (Pub/Sub) | United States (us-central1) |
| Stripe | Payments and subscription billing | US |
| Anthropic | ⚠️ Only if you connect an Anthropic model — we don't route your data there otherwise | US |
| [EMAIL PROVIDER — to be completed] | Transactional and product email | United States |
| [ANALYTICS — to be completed] | Product analytics | United States |
| [SUPPORT TOOL — to be completed] | Support ticketing | United States |
Current list, with 30 days' notice of changes: [SUBPROCESSOR PAGE URL — to be completed]
Each is bound by a data processing agreement with confidentiality and security obligations at least as protective as ours.
Otherwise
- Legal — where required by law, subpoena or court order. We'll notify you before disclosing, unless legally prohibited.
- Business transfer — in a merger, acquisition or asset sale, with notice and the same protections continuing.
- With your consent — anything else.
4 · International transfers
We're a US company; data is processed in the United States and other countries.
For EEA, UK and Swiss data, we rely on:
- Standard Contractual Clauses (EU Commission Decision 2021/914), plus the UK Addendum where applicable
- Supplementary technical and organisational measures — encryption in transit and at rest, access controls, minimisation
- A transfer impact assessment, reviewed periodically
⚠️ On the EU-US Data Privacy Framework: the adequacy decision remains in force, but it's under active challenge — an appeal to the CJEU is pending, and a 2026 US Supreme Court ruling on FTC independence has raised questions about the oversight the framework depends on. We therefore rely on SCCs as our primary transfer mechanism, not on the DPF alone. If we later certify under the DPF, we'll keep SCCs in place as a fallback.
5 · How long we keep it
| Data | Retention |
|---|---|
| Account | For the life of the account |
| Customer Data | For the life of the account — exportable for 30 days after termination, then deleted |
| Backups | Deleted within [35] days of the primary record |
| Billing records | 7 years — tax and accounting law |
| Security and audit logs | [12] months |
| Support tickets | [24] months after resolution |
| Marketing contacts | Until you unsubscribe, then suppression-list only |
Deletion requests are honoured within 30 days for live systems; backups age out on the schedule above.
6 · Your rights
Everyone
Access · correct · delete · export (machine-readable) · close your account.
Do most of this yourself in account settings, or email privacy@batondeck.com. We respond within 30 days, and we don't charge for it.
EEA / UK (GDPR)
Also: restrict processing, object to processing based on legitimate interests, withdraw consent at any time, and not be subject to solely automated decisions with legal or similarly significant effects — we don't make any.
You may complain to your supervisory authority. [If applicable: our EU representative under Art. 27 is [EU REP — to be completed], and our UK representative is [UK REP — to be completed].]
California (CCPA/CPRA)
Right to know, delete, correct, and to opt out of "sale" or "sharing" — we do neither. We don't process sensitive personal information for inferring characteristics. You won't be discriminated against for exercising these rights. An authorized agent may act for you with proof.
Other US states
Virginia, Colorado, Connecticut, Utah, Texas and others grant comparable rights. Same address, same 30 days.
7 · Cookies
| Type | Purpose | Can you refuse? |
|---|---|---|
| Essential | Session, authentication, security, CSRF | No — the Service won't work |
| Functional | Preferences, theme, layout | Yes |
| Analytics | Aggregate usage and performance | Yes |
We don't use advertising or cross-site tracking cookies.
Where required — EEA, UK — we ask consent before setting anything non-essential, and you can change it any time at https://batondeck.com/privacy#cookies. Browser controls work too, though blocking essential cookies breaks sign-in.
We honour Global Privacy Control signals as an opt-out of sale/sharing where that applies.
8 · Security
We maintain an information security programme with administrative, technical and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration and destruction, appropriate to the nature of the data and the size of our organisation. Our programme is designed to include:
- Encryption — TLS for data in transit, and encryption of data at rest by our cloud provider
- Authentication — OAuth 2.0 with signed, expiring access tokens verified on every request
- Access control — role-based permissions on a least-privilege basis; project membership is required to access any content, and roles are enforced per operation
- Audit logging — attributed action records identifying the actor (human or Agent), the operation and its outcome, including failed attempts at sensitive operations
- Backups — point-in-time recovery with a rolling recovery window, plus scheduled daily and weekly backups
- Vendor assessment — security review of subprocessors before onboarding
⚠️ No method of transmission or storage is completely secure. We do not and cannot guarantee absolute security, and nothing in this policy is a warranty or guarantee that our safeguards will prevent every unauthorized access. Our safeguards may change as the Service and the threat landscape evolve, provided we do not materially reduce overall protection.
Your part matters too: use a strong unique password, enable multi-factor authentication, keep API keys secret, and rotate them if you suspect exposure.
Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify affected customers without undue delay, and in any event within 72 hours of confirming a reportable incident, and notify regulators where legally required. Where full details aren't immediately available, we provide information in phases as our investigation progresses.
9 · Children
The Service isn't for anyone under 18 and we don't knowingly collect their data. If we learn we have, we delete it. Contact privacy@batondeck.com if you believe a child has given us information.
10 · Changes
We'll post updates here with a new "Last updated" date. For material changes we'll email you at least 30 days before they take effect. Prior versions: [POLICY ARCHIVE URL — to be completed].
Privacy questions: privacy@batondeck.com Data protection contact: [DPO NAME / EMAIL, or "we have not appointed a DPO as we're not required to"] Post: BatonDeck Inc., [REGISTERED ADDRESS — to be completed]