Privacy Notice
last updated 25 August 2026
Who is responsible
IJ Marketing LTDA, CNPJ 64.704.051/0001-87, is the controller of the personal data described here. Our data protection officer is Jakson Lucas Campos, reachable at [email protected].
This notice is written under the Lei Geral de Proteção de Dados (Lei 13.709/2018). It says what we hold, why, for how long, and what you can ask us to do about it.
What we hold, and why
| what | why | basis |
|---|---|---|
| Your name, email and picture | To have an account and to show who did what on a board. The picture comes from GitHub, GitLab or Google when you sign in with one. | Performance of the contract |
| Your password, hashed | Only if you signed up with one. We never store it in a form we could read. | Performance of the contract |
| Access tokens for GitHub and GitLab | To do the Git work you asked for. Encrypted with AES-256-GCM before being stored, and never shown again. | Performance of the contract |
| A GitHub authorization that acts as you | Only if you sign in with GitHub. It exists for one thing: creating a repository in your own account, which the app installation cannot do. It is encrypted the same way, replaced each time you sign in, and you can drop it from your account settings at any time — everything else keeps working without it. | Performance of the contract |
| Nothing at all from Google | Signing in with Google asks for your name, email and picture once and never asks again. No token from it is stored: it connects nothing and reaches nothing, so there is nothing worth keeping and keeping it would claim a reach the product does not have. | Performance of the contract |
| Files you attach | Anything put on a card, and the picture on your profile. Held in object storage on our behalf, reachable only through a link this service signs — the bucket is never public. | Performance of the contract |
| Your model provider key | Only if you add one, to run your agents. Encrypted the same way. The provider bills you directly; we never see the invoice. | Performance of the contract |
| Repository and board data | Branch names, pull request numbers, check results, comments, and the timeline of what happened to a card. | Performance of the contract |
| Agent transcripts | What an agent read, wrote and spent on a run. These may contain source code from your repository. | Performance of the contract |
| Billing details | Handled entirely by Stripe. Card numbers never touch our servers; we keep the customer and subscription identifiers and the number of open projects. | Performance of the contract |
| Server logs | Requests, errors and webhook deliveries, to keep the service working and to investigate faults. | Legitimate interest |
| How the public pages get used | Which pages are read, roughly where from and on what kind of device, counted by Google Analytics on this site. It names nobody, it stops at the sign-in page, and the application itself carries no analytics at all. | Legitimate interest |
Who else sees it
We use a small number of processors, and each sees only what its job needs: GitHub and GitLab (the repositories you connect), Google (Analytics on the public pages, and who you are if you sign in with it), Amazon Web Services (the files you attach, and nothing else), Stripe (payments), Resend (the emails we send), and the model provider you chose, which receives what an agent sends it under your own key.
Some of these operate outside Brazil, so your data may be transferred internationally under the safeguards the LGPD allows. We do not sell personal data and we do not use it for advertising.
How long we keep it
Board data lives as long as your workspace does. Agent transcripts are kept for the period your organization sets — they hold source code, so that is a decision we ask you to make rather than a default we choose. Sessions expire on their own, and a revoked one is removed immediately.
What deleting actually does
When you delete your account we remove every session, every provider link and every password reset, immediately and for real. The row that remains is scrubbed: your name becomes "a former member", your email becomes an address nobody can be found at, and your picture and password are removed, and the files you attached to your own profile go with them.
What we keep is the work: the cards you opened, the comments you wrote and the releases you cut stay on the boards they belong to, without your name on them. They are the team's record of what happened, and removing them would rewrite somebody else's history. If that is not what you want, tell us before you delete and we will discuss what can be done.
Your rights
Under the LGPD you may ask us to confirm what we hold, to give you a copy, to correct it, to anonymize or delete what is unnecessary or excessive, to tell you who we shared it with, and to withdraw consent where consent is what we relied on. Write to [email protected] and we will answer within fifteen days.
You may also complain to the Autoridade Nacional de Proteção de Dados if you believe we have not done right by you.
How we protect it
Tokens and model keys are encrypted at rest. Sessions are cookies the page cannot read. An agent runs in a container with no unrestricted network access, unprivileged, with memory and process limits. Dependencies use a proxy restricted to language registries; runtime access is limited to the exact destinations a maintainer declares.
None of that makes a breach impossible. If one happens and it puts you at risk, we will tell you and the authority, as the law requires.
Questions about any of this go to [email protected].
