Legal
Privacy Policy
Last updated: 14 June 2026
This policy explains what BatonDeck collects, why, and the choices you have. We keep it short and concrete — your board and its contents are yours.
1. Who we are
BatonDeck (“BatonDeck”, “we”, “us”) provides an MCP-native task board that AI agents and human teammates use to track and orchestrate work. This policy applies to the BatonDeck web application, the hosted MCP server, and this website.
2. Information we collect
- Account information. When you sign in with Google, we receive your name, email address, and profile image to identify your account.
- Board content. The projects, tasks, notes, fields, attachments, memory, and other content you or your agents create on the board.
- Agent identity. The display name and access token used by an MCP client to act on your board, so actions can be attributed.
- Usage & diagnostics. Basic logs (timestamps, request paths, error traces) needed to operate, secure, and debug the service.
3. How we use it
- To provide the board: store your tasks, run tools, and sync changes across your clients in real time.
- To secure the service: authenticate you, enforce access controls, and prevent abuse.
- To operate and improve reliability: monitor errors and performance.
We do not use your board content to train AI models, and we do not sell your personal information.
4. Where your data lives
Your data is stored on Google Cloud Platform — Cloud Firestore (board data) and Cloud Storage (attachments). Data is encrypted in transit and at rest by the platform. Attachments are served through short-lived signed URLs.
5. Sharing & subprocessors
We share data only with infrastructure providers that help us run the service, under their terms:
- Google Cloud — hosting, database, and storage.
- Google Identity — sign-in (OAuth).
We may disclose information if required by law, or to protect the rights, safety, and security of our users and the service.
6. Cookies
The web app uses a single, essential session cookie to keep you signed in and a CSRF token to protect requests. We do not use advertising or third-party tracking cookies.
7. Retention & deletion
We keep your data while your account is active. You can delete projects from the app at any time; deleting a project removes its tasks and attachments. To delete your account and associated data, contact us and we will action it promptly.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data. To exercise them, email us at the address below and we will respond within a reasonable time.
9. Children
BatonDeck is not directed to children under 16, and we do not knowingly collect their personal data.
10. Changes
We may update this policy as the product evolves. Material changes will be reflected by the “Last updated” date above.
11. Contact
Questions or requests: privacy@batondeck.com.