Last updated: April 14, 2026
This Privacy Policy explains how PMDecks ("PMDecks," "we," "our," or "us") collects, uses, discloses, and protects personal information when you use our services, website, and applications.
1. Scope and Controller
This policy applies to all PMDecks users and visitors. PMDecks is the data controller for personal data processed under this policy unless otherwise stated.
2. Information We Collect
- Account data: name, email address, profile photo, authentication identifiers, username.
- Workspace data: boards, cards, comments, attachments, notes, assignment data, activity logs, and organization membership.
- Billing data: subscription tier, payment/customer references, and billing status (payment processing handled by Stripe).
- Support data: support tickets, support messages, and related metadata.
- Technical data: IP-derived diagnostics, device/browser information, usage events, and security logs.
- AI input/output: prompts, structured outputs, and related generation metadata used for AI features.
3. How We Use Information
- Provide, operate, maintain, and secure PMDecks features.
- Authenticate users and manage account access.
- Enable collaboration features and organization workflows.
- Process subscriptions, enforce plans, and prevent fraud or abuse.
- Respond to support requests and service communications.
- Provide AI-assisted functionality and improve product performance.
- Comply with applicable legal obligations and lawful requests.
4. Legal Bases for Processing (GDPR/UK GDPR)
- Contract: to provide the services you request.
- Legitimate interests: service reliability, security, analytics, and abuse prevention.
- Consent: where required (for example, optional communications or certain cookies).
- Legal obligation: to comply with law, tax, and regulatory duties.
5. AI Processing and Safeguards
AI features route requests through secured backend services. API keys are not exposed in the browser client. AI providers may process prompt content to generate outputs. Do not submit highly sensitive personal data to AI prompts unless you have a lawful basis and authorization to do so.
6. Sharing and Disclosure
We do not sell personal information. We may share data with trusted processors and service providers (for example, hosting, authentication, storage, billing, and support tooling) under contractual safeguards. We may also disclose data when required by law or to protect rights, safety, and platform integrity.
7. International Transfers
Your data may be processed in countries other than your own. Where required, we use lawful transfer mechanisms such as standard contractual clauses or equivalent safeguards.
8. Data Retention
We retain data for as long as needed to provide services, comply with legal obligations, resolve disputes, and enforce agreements. You can request account deletion; certain records may be retained when legally required.
9. Security
We use technical and organizational safeguards, including authentication controls, access restrictions, encrypted transport, and service-provider security tooling. No system can be guaranteed 100% secure.
10. Your Privacy Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object, or port your personal data, and to withdraw consent where applicable.
- California (CCPA/CPRA): rights to know, delete, correct, and limit use of sensitive personal information, plus non-discrimination rights.
- EEA/UK: rights under GDPR/UK GDPR and the right to lodge a complaint with a supervisory authority.
11. Cookies and Similar Technologies
We use local storage and similar technologies for authentication state, preferences, and feature functionality. Where non-essential technologies are used, we will provide notice and choices as required by law.
12. Children’s Privacy
PMDecks is not directed to children under 13 (or higher age where required by local law). If we learn we collected personal data from a child without proper authorization, we will delete it.
13. Changes to This Policy
We may update this policy from time to time. Material updates will be posted with a revised "Last updated" date.