Privacy Policy

Version: 2026-08-17

I. Who is responsible for your data

The controller of personal data used to operate aboutthe.app is Roman Banar, Company ID 72988363, Svobodova 744, Bílovec, Czech Republic (European Union) ("we" or the "Operator").

For privacy questions or requests, email [email protected]. For personal data that a user enters into their own workspace about other people, that user is the controller and we act as their processor as described in Section VII.

II. What we process and why

We process only the categories needed to provide, secure and improve the Service:

CategoryExamplesPurpose and legal basis
Account and accessEmail, display name, avatar, sign-in identity, acceptance of the Terms, workspace membership and invitationsCreate and operate your account and authenticate you — performance of our contract
Workspace contentProduct details, deployments, links, notes, visibility settings, customer names and per-customer overridesStore and display the information you ask us to manage — performance of our contract
BillingBilling email and Paddle customer, subscription, price and transaction status identifiersManage paid plans — performance of our contract; retain required accounting records — legal obligation
MessagesWaitlist address, support requests and transactional email delivery detailsRespond to your request and communicate about the Service — contract or legitimate interest
Technical and website usage dataRequest and error information, security signals, page, referrer, browser, device and approximate countryProtect and diagnose the Service and understand use of the marketing website — legitimate interest

Most data comes directly from you. We may also receive account details from Google, GitHub or Microsoft when you choose that sign-in method, invitation details from another member of a workspace, and billing status from Paddle. Required account data is necessary to provide the Service; without it, we cannot create or operate an account.

We do not sell personal data, use it for third-party advertising, or make decisions about you based solely on automated processing. The Service is not intended for special-category personal data.

III. Public and private workspace content

Content you mark as public is available to anyone through the product's public page, API or embed. Private content is available to authorised workspace members and to anyone who uses that product's unlock code. Search engines or other parties may copy public content outside our control.

You decide what to enter, whether it is public or private and who receives an unlock code. Do not enter passwords, API keys, access tokens or other secret values. If content identifies another person, you are responsible for having a valid legal basis and providing any information that person is entitled to receive.

IV. Cookies and analytics

The Service uses strictly necessary cookies to remember your language across the marketing website and dashboard, and, once you sign in, to keep you signed in and carry a selected plan, invitation or registration state through sign-in. These cookies are required for the requested functionality and are not used for advertising. The public product page and embeddable About box set no cookies at all.

The marketing website uses Umami to produce cookieless, aggregate traffic statistics. It may process the visited page without its query string, referrer, browser, operating system, device, screen size, language, approximate country and technical data needed to group a visit into a session. Invitation pages do not load the analytics script.

The public product page and embeddable About box do not add our analytics or tracking cookies. Requests still pass through hosting and security infrastructure, which may process technical data to deliver and protect the page. Paddle may use its own necessary technologies when you open its checkout; Paddle's own privacy notice applies to that processing.

V. Providers, recipients and international transfers

We use the following providers only where needed to operate the Service:

  • Roští.cz for application and database hosting
  • Váš Hosting, s.r.o. for sending and receiving service email
  • Cloudflare for DNS, content delivery and protection of the Service
  • Google, GitHub and Microsoft for sign-in, only when you choose the relevant provider
  • Paddle as Merchant of Record for checkout, billing, tax and payment support
  • Umami for analytics on the marketing website
  • Sentry for error tracking, to diagnose failures in the Service

We may also disclose data where required by law or needed to establish, exercise or defend legal claims. Some providers operate outside the EU/EEA. Where European data-protection law requires a transfer safeguard, the transfer relies on an adequacy decision, Standard Contractual Clauses or another lawful mechanism made available by the provider.

VI. How long we keep data

  • Account and membership data are kept while the account is active. If you own a workspace, this includes its content too; if you are a member of someone else's workspace, deleting your own account only removes your account and membership — the workspace and its data are unaffected. After deletion is scheduled, the relevant data remain recoverable for 30 days or until the end of a later paid period, then are deleted.
  • Short-lived sign-in links expire within 15 minutes and are deleted within 7 days. Invitations and checkout requests expire when no longer usable and are deleted within 90 days.
  • Billing and accounting records are kept for the period required by applicable law. Records of individual payment provider webhook events are deleted within 90 days. Paddle applies its own retention periods to data for which it is responsible.
  • Waitlist and support data are kept while needed to handle the request or operate the waitlist, and may be deleted sooner on request unless retention is legally required.
  • Technical logs and analytics are retained only for the operational period configured for the relevant service and are then deleted or aggregated.

Deleted data may remain temporarily in rotating backups until those backups expire. We do not restore deleted data from a backup except where necessary to recover the Service as a whole.

VII. Data you enter about other people

If workspace content contains personal data for which you are the controller, you instruct us to process it only to host, organise, display and transmit that content through the features you use. This section is the data-processing agreement between you and the Operator for that content.

  • The subject matter and duration are the provision of the Service for as long as your account and the relevant content remain active. The people and data involved are determined by what you choose to enter.
  • We process the data only on your documented instructions expressed through use of the Service, unless law requires otherwise, and people authorised to process it are bound by confidentiality.
  • We apply appropriate technical and organisational security measures and notify you without undue delay if we become aware of a personal-data breach affecting this content.
  • You authorise the providers listed in Section V as subprocessors where they process this content. We remain responsible for imposing appropriate data-protection obligations on them and will update this policy before adding a materially different subprocessor.
  • Taking account of the nature of the processing, we will reasonably assist with data-subject requests, security duties and information needed to demonstrate compliance.
  • You may object to a new subprocessor added under the point above by closing the affected workspace before the change takes effect; we will tell you without undue delay if we believe one of your instructions would infringe data-protection law; and, on reasonable request and notice, we allow and contribute to an audit of this processing, sharing the relevant compliance information first.
  • You can delete content using the Service and request a copy of your data at [email protected]. When the account ends, we delete it as described in Section VI unless law requires retention.

You are responsible for the lawfulness, accuracy and scope of the data you enter and for responding to requests from the people concerned. Contact [email protected] if you need reasonable compliance information that is not available in the Service.

VIII. Your rights, security and changes

Depending on applicable law, you may ask us to access, correct, delete, restrict or provide a portable copy of your personal data, and you may object to processing based on legitimate interest. Send requests to [email protected]. We may need to verify your identity and will respond within the period required by law, normally one month under the GDPR.

You may complain to your local data-protection authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz). If your request concerns content entered by one of our users about you, contact that user first; we will assist them as their processor.

We use proportionate measures to protect personal data, including encrypted transport, passwordless authentication, access controls and tenant separation. No online service can guarantee absolute security, so please report suspected misuse to [email protected].

We may update this policy when the Service, providers or law changes. The current version and date are published here. If a material change affects how we use your data, we will provide additional notice or request consent where required by law.

This policy is also available in Czech. Both versions carry the same meaning; if a discrepancy is found between them, the English version governs.