Privacy Policy

Effective October 3, 2026

This policy covers BoardKit, which turns project templates into GitHub issues, labels, and project boards in repositories you choose. It explains what personal data is collected, why, who it is shared with, how long it is kept, and the rights you have over it. It is written to meet the EU General Data Protection Regulation (GDPR), Portugal's data protection and electronic communications laws, and United States federal and state privacy laws.

Who is responsible for your data

BoardKit is operated by Erica Thompson (Brave Haven), the controller of your personal data. For anything about your data, email hr@bravehaven.io. No data protection officer has been appointed, because one is not required at this size.

The short version

What we collect, why, and for how long

Signing you in with GitHub

What
Your GitHub user ID, username, email address, and profile picture, from GitHub
Why we are allowed to
Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
How long we keep it
For as long as you keep your account. Ask us to delete it and it is deleted within 30 days

Creating boards in your repositories

What
A GitHub access token that lets BoardKit create repositories, issues, labels, and projects for you. It is kept only inside your encrypted sign-in cookie, never in our database
Why we are allowed to
Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
How long we keep it
Until you sign out or your session expires. You can revoke it any time in GitHub's settings

Your plan and billing

What
Your GitHub user ID, email, plan, and Stripe customer and subscription IDs
Why we are allowed to
Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b))
How long we keep it
For as long as you keep your account. Ask us to delete it and it is deleted within 30 days

Taking payment

What
Your email, what you bought, amount, and Stripe customer and payment IDs. Card details are handled by Stripe and never reach us
Why we are allowed to
Contract: needed to provide the service you signed up for (GDPR Art. 6(1)(b)), and legal obligation: tax and accounting law (gdpr art. 6(1)(c))
How long we keep it
As long as tax and accounting law requires, up to 10 years

Preventing abuse

What
Your GitHub user ID or, if you are signed out, your IP address, counted to limit how many requests one person can make
Why we are allowed to
Legitimate interests (GDPR Art. 6(1)(f)): keeping the service available for everyone
How long we keep it
Minutes, until the rate-limit window ends

Running and securing the site

What
IP address, browser and device type, pages requested, and time of request, in server logs
Why we are allowed to
Legitimate interests (GDPR Art. 6(1)(f)): keeping the site working and protecting it from abuse
How long we keep it
No more than 30 days, then deleted automatically by our host

Understanding how the site is used (only if you accept)

What
When each page was viewed, the page address, the referring site, approximate location (country, region, city), browser, operating system, and device type. No cookies. Visits are told apart by a hash of the request that Vercel discards after 24 hours, so the data is not tied to you
Why we are allowed to
Consent (GDPR Art. 6(1)(a)). You can withdraw it at any time
How long we keep it
Vercel keeps it for our plan's reporting window, and may keep it longer. Withdrawing consent stops any further collection

What stays on your device

Custom templates you create and the repository you last picked are saved in your browser (localStorage). They never leave your device.

Cookies and similar technologies

These are strictly necessary for the site to work, so they do not need your consent:

Vercel Web Analytics sets no cookies. Its script is loaded only if you choose Accept analytics; until then nothing about your visit is sent to it. You can change your choice at any time with Analytics settings at the bottom of every page. If your browser sends a Global Privacy Control signal, we treat it as a refusal and do not ask.

Who we share it with

We use these service providers (processors). Each may use your data only to provide its service to us, under a data processing agreement:

You may also use these services, which are responsible for your data themselves:

We do not sell personal information and do not share it for cross-context behavioral advertising. We would disclose data to authorities only where the law requires it.

International transfers

Our providers store or process data in the United States. For transfers of personal data from the European Economic Area, the UK, or Switzerland, we rely on the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions) where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses in the provider's data processing terms.

Your rights

In the European Union, the UK, and Switzerland

You can complain to a data protection authority. In Portugal that is the Comissão Nacional de Proteção de Dados (CNPD), www.cnpd.pt. Elsewhere, contact the authority where you live or work. We would appreciate the chance to put things right first.

In the United States

Depending on your state (including California, Colorado, Connecticut, Virginia, Texas, and others with comprehensive privacy laws), you may have the right to know what personal information we collect and how we use it, to access it, to correct it, to delete it, and to opt out of its sale, of targeted advertising, and of profiling. We do none of those three. We will not treat you differently for using any of these rights. You can use an authorized agent, and if we turn down a request you can appeal by replying to our answer.

How to make a request

Email hr@bravehaven.io and say what you would like. To protect your account, we will ask you to confirm the request from the email address on it. We answer within one month (GDPR), or within 45 days for US state privacy law requests, and tell you if a complex request needs longer. Requests are free.

How we protect it

Children

BoardKit is not intended for anyone under 16, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.

Changes to this policy

When this policy changes, we update this page and its effective date, and email account holders about significant changes.