kabana
Legal

Privacy Policy

Last updated: 2026-05-07

Draft template. This document describes Kabana's actual data handling, but the legal framing (GDPR / CCPA / your jurisdiction) should be reviewed by a lawyer before you treat it as binding. Update the contact email and controller details before launch.

This Privacy Policy explains what data Kabana ("we", "us") collects, what we do with it, and how you can access or delete it. By creating a Kabana account you agree to this policy. If you do not, do not use the Service.

1. Who we are

The data controller is the Kabana team. The product is a SaaS kanban for software teams. The Service is described in our Terms of Service.

2. What we collect

Account data

Workspace data you create

Billing data

Integrations you connect

API tokens and device codes

What we do NOT collect

3. Why we collect it (legal bases)

4. Sharing and processors

We use a small list of subprocessors to run the Service:

We do not sell personal data, and we do not use your workspace data to train models.

5. International transfers

Our hosting provider and Stripe operate internationally, including in the United States. By using the Service you consent to your data being transferred to and processed in those locations under standard contractual clauses where applicable.

6. Retention

7. Your rights

You have the right to:

8. Security

We use bcrypt for password and token hashing, JWT-strategy session cookies with the HttpOnly flag, TLS in transit, multi-tenant isolation enforced at the database query layer, and per-route ownership checks on every mutation. The agent runs on your machine, so your code never traverses our servers. We do our best, but no system is perfectly secure.

9. Children

Kabana is not directed at children under 16 and we do not knowingly collect data from them.

10. Changes

We may update this policy. The "Last updated" date above reflects the latest change. Material changes will be announced in the changelog. Continued use after a change is acceptance of the updated policy.

11. Contact

For privacy questions, data access requests, or anything else: write to the support email listed in your account settings, or to the address on our public site.