Boardit is local-first. The free workspace stays in your browser. We do not sell personal information, run advertising, or send marketing email. Creating an account and using cloud synchronization are optional.
1. Information Boardit processes
Local workspace data
Folders, boards, cards, notes, URLs, tags, graph connections, images, and preferences are stored locally in extension-controlled browser storage. We do not receive this information unless you enable cloud synchronization or deliberately contact support with it.
Account and synchronized data
If you create an account, we process your email address, authentication records, subscription status, synchronization metadata, and the workspace records and supported assets you choose to synchronize. We do not ask for your name, age, gender, or industry.
Billing information
Stripe processes payment-card and billing information. Boardit receives identifiers and subscription status needed to provide the paid service, but does not receive or store complete payment-card numbers.
Website and service logs
Cloudflare, Supabase, Stripe, and Resend may process limited technical information such as IP address, device or browser information, timestamps, request logs, and delivery events to provide, secure, and troubleshoot their services.
2. How information is used
- Provide local research organization and optional synchronization.
- Authenticate accounts and recover access.
- Process subscriptions and maintain entitlement status.
- Send requested transactional and security email.
- Prevent abuse, diagnose failures, and protect the service.
- Respond to support requests.
3. Service providers
Boardit relies on Cloudflare for website delivery and DNS, Supabase for authentication and optional synchronized storage, Stripe for payments and billing management, Resend for transactional email delivery, Google for Chrome Web Store distribution, and GitHub for source and deployment workflows. Each provider processes information under its own terms and privacy commitments.
4. Retention and deletion
Local workspace data remains in the browser until you delete it, clear browser storage, or remove the extension. Local recycle-bin items are scheduled for removal seven days after deletion.
Paid synchronization includes a seven-day grace period after access ends, followed by up to ninety days without synchronization while export remains available where supported. Cloud research data is scheduled for deletion after that retention period. A requested cloud-account deletion has a thirty-day recovery period before permanent deletion. Local browser data is not deleted by closing a cloud account.
5. Your choices
You may use Boardit without an account, export supported workspace data, stop synchronization by signing out, manage or cancel billing through Stripe, change account credentials, and request cloud-account deletion. You may also contact us about access, correction, or deletion questions.
6. Security
We use access controls, row-level authorization, transport encryption, and restricted service credentials intended to protect synchronized data. No system can guarantee absolute security. Keep your browser profile and account credentials secure.
7. International processing
Our providers may process information in countries outside your own. Their contractual and technical safeguards govern those transfers. Boardit is operated from Canada, although service infrastructure may be located elsewhere.
8. Children
Boardit is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
9. Changes
We may update this policy as Boardit changes. Material revisions will be identified by a new effective date and, where appropriate, communicated through the product.
10. Contact
Privacy questions may be sent to support@boarditworkspace.com.
This policy is an operational draft and should be reviewed for the laws that apply to the business before a public paid launch.