Privacy policy
Effective 4 October 2026
This is about the hosted Kanbanto at app.kanbanto.com and this website, kanbanto.com. Kanbanto is run by an independent developer. Questions: support@kanbanto.com.
The short version
- We store what you put into Kanbanto, so we can show it back to you and to the people you share it with. Nothing else is done with it.
- No ads, no tracking scripts, no analytics on your boards, and we never sell data.
- Connecting Google Calendar is optional. Kanbanto only writes to a calendar it makes itself, and can't see your other calendars. Details below.
- You can delete your boards yourself, and your account by writing to us.
What we store
| What | Why |
|---|---|
| Your name and email address, and your password as a one-way hash (we can't read it) | Your account and signing in |
| Your boards, cards, comments, logged time, plans and the files you attach | They are the service |
| Your settings: time zone, which notifications you want | Reminders and summaries at the right time |
| A record of who changed what on a board, kept 90 days | So you and your team can see what happened |
| If you turn on desktop notifications: the address your browser gives for sending them | Sending those notifications |
| If you make API tokens or connect an AI app: a hash of each token, its name and when it was last used | Letting that app act as you |
| A record that an email was sent to you (not its contents) | Sending limits and troubleshooting |
Like any website, the servers that deliver Kanbanto see your IP address and which pages were requested. We don't use that to track you, and our own logs don't contain what's in your boards.
Cookies and your browser
- One cookie keeps you signed in, for up to 30 days.
- One short-lived cookie is set while you connect Google Calendar, and removed when you come back.
- Your theme and view choices are kept in your browser's storage. They never leave it.
There are no advertising or analytics cookies.
Who else handles your data
| Who | What for |
|---|---|
| Railway | Runs the app and its database (in Singapore) |
| Cloudflare | Stores attached files (R2), serves this website, and handles email to our support address |
| Resend | Sends our emails: confirmations, password resets, invites, reminders and summaries |
| Your browser's notification service (Google, Mozilla or Apple) | Delivers desktop notifications, if you turn them on |
| Only if you connect Google Calendar (below) |
If you connect your own storage bucket or your own email key in Account settings, your files or your invites go through that service instead, under your own account with it.
Google Calendar and Google user data
Connecting Google Calendar is optional. You do it in Account settings → Calendar, and nothing below happens unless you do.
What Kanbanto accesses
-
A calendar of its own. Kanbanto asks for Google's permission to "make secondary Google calendars, and see, create, change,
and delete events on them" (
calendar.app.created). With it, Kanbanto creates one calendar in your Google account and manages only the events in that calendar. It cannot see, change or delete your other calendars or their events. - Your Google account's email address, to show you which account is connected.
How Kanbanto uses it
- It writes an event for each due date and reminder on your cards, and updates or removes it when the card changes. An event holds the card's title, its date and time, the board's name and a link back to the card.
- It goes one way, from Kanbanto to Google. Kanbanto does not read your events to use them for anything.
What Kanbanto stores
- Your Google account's email address.
- The token Google gives us to keep the calendar up to date, encrypted.
- The identifiers of the calendar and the events Kanbanto created, so it can update them.
Sharing
- Google user data is not shared with or sold to anyone, not used for advertising, and not used to train AI models.
- Nobody at Kanbanto reads it, except when you ask us for help with it, or where the law or the security of the service requires it.
Kanbanto's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Removing it
- Disconnect in Account settings → Calendar removes the calendar Kanbanto made from your Google account, gives the access back to Google, and deletes the token and identifiers we stored.
- You can also take the access away in your Google account's connections. Kanbanto then stops updating the calendar.
Calendar links
If you make a calendar link, anyone who has that link can read the titles and dates of your cards, and nothing else. Keep it to yourself; you can replace it or turn it off at any time.
AI assistants and other apps you connect
An assistant or app you connect works with your access: it can read what you can read, and change what you let it change. What that app does with what it reads is between you and its maker, so connect only the ones you trust. You can disconnect any of them in Account settings.
What others can see
- People on a board see its cards, comments and files, and the names of the others on it. Its owners also see their email addresses.
- A board with its public link turned on can be viewed by anyone who has the link.
- A private board is seen by its owners only.
Keeping and deleting
- Your data is kept for as long as you have an account.
- You can delete cards and boards yourself; a deleted board's files are deleted with it. You can export a board as a file first.
- To delete your account and everything in it, write to support@kanbanto.com from the account's email address. We do it within 30 days.
Your rights
Wherever you live, you can ask us what we hold about you, to correct it, to give you a copy, or to delete it. Write to support@kanbanto.com.
Running Kanbanto yourself
This policy covers the hosted service only. A copy of Kanbanto that someone else runs is theirs to answer for.
Changes
If this policy changes in a way that matters, we'll say so here and by email before it takes effect.