Privacy Policy
Last updated: 2026-07-31.
This page explains what data Markboard collects, why, and how it's used. This instance is self-hosted — your data lives in a database the operator runs directly, not a third-party cloud data platform.
What we collect
- Account info: your email address, and optionally a display name, bio, and profile picture.
- Sign-in credentials:if you use a password, it's stored as a salted bcrypt hash, never in plain text. If you sign in with Google or GitHub instead, we store the link to that account, not your password on that service.
- Content you create: workspaces, boards, cards, card descriptions, comments, checklists, labels, dates, and any files you attach.
- Activity data: a log of who changed what on a board, for collaboration and audit purposes.
- API keys: if you create one (for AI-agent access), only a one-way hash is stored — the raw key is shown to you once and never stored in reversible form.
Cookies
A single session cookie keeps you signed in. There are no advertising or analytics/tracking cookies.
Third parties
The following services are used only where the operator has configured them:
- Google / GitHub — only if you choose to sign in with one of them instead of a password.
- Resend — sends workspace invite emails.
- Sentry — receives details of unexpected errors, to help fix bugs. Not used for tracking or advertising.
We don't sell your data, and there are no ads on this service.
Data retention and deletion
Your data is kept for as long as your account exists. There's no self-service “delete my account” button yet — to request deletion of your account and data, contact the operator at [operator contact email — update before going live].
Security
Passwords are hashed with bcrypt; sign-in and every action that changes data are rate-limited against abuse; every request runs over HTTPS in production.
Changes to this policy
This policy may be updated as the service changes. Material changes will be reflected here with an updated date.
Contact
Questions about this policy, or a data request? Contact the operator at [operator contact email — update before going live].