Skip to content
Draft. Placeholders in [brackets] must be completed before publication.

Schedol

Privacy Policy

Last updated 4 September 2026

1. Who we are

Schedol is operated by [Legal entity name], [registered address] ("Schedol", "we", "us"). We are the data controller for the personal data described here. Questions about this policy go to [dpo@schedol.com].

2. What we collect

Account. Your email address, and the name and avatar image your sign-in provider gives us. Signing in with Google shares the name and picture on your Google account; signing in by email shares only the address you typed. The email address is your identity in Schedol and is what your teammates see when they add you to a board.

Workspace content. Everything you and your teammates create in a workspace: projects, boards, cards, comments, subtasks, tags, sprints, tickets, hand-offs, automation rules, activity history and the names and emails of the people you invite. This is your data; we process it only to run the service for you.

Usage and security logs. Server logs record the IP address, browser identifier, request path and timestamp of each request, and the identifier of any error. Rate-limit counters are keyed by IP address and kept for at most one hour. These exist to keep the service up and to detect abuse.

Cookies. Two are necessary and cannot be turned off: the session cookie that keeps you signed in, and schedol_consent, which remembers your cookie choices. Analytics and marketing cookies are off unless you turn them on, and you can change that at any time at /settings/privacy.

3. Why we use it

  • To provide the service: signing you in, showing you the boards you are on, sending the notifications you have chosen, and keeping every open tab in sync.
  • To keep it secure: rate limiting, abuse detection, an activity log per workspace, and error diagnostics.
  • To bill you: subscription and seat management through Stripe. We never see or store card numbers; Stripe does.
  • To email you: sign-in links and the notifications you have opted into, sent through Resend. Every notification email carries an unsubscribe link.

Our legal bases are performance of the contract with you (the service and billing), our legitimate interest in keeping the service secure and working, and your consent for the optional cookies.

4. Who processes it for us

We use the following sub-processors. Each is bound by its own data processing terms.

ProviderPurposeRegion
SupabaseDatabase and authentication records[fill]
Amazon Web ServicesApplication hosting, file storage[fill]
StripePayments and subscription management[fill]
ResendTransactional email delivery[fill]
GoogleSign in with Google[fill]
CloudflareDNS, TLS and traffic filtering[fill]

We do not sell personal data and we do not share it with advertisers.

5. How long we keep it

Workspace content is kept for as long as the workspace exists. Cards you delete sit in the workspace trash for [period] before they are removed for good. When you delete your account, your profile is removed immediately and your name on past activity is replaced with a placeholder; comments and cards you created remain with the workspace because they belong to the team. Server logs are kept for [period]. Email delivery records are kept for [period]. Backups are kept for [period].

6. Your rights

  • Export. Download everything we hold about you from the account menu, which calls /api/user/export.
  • Delete. Delete your account from account settings. This cannot be undone.
  • Unsubscribe. Every notification email has a one-click unsubscribe link. Sign-in links are not notifications and cannot be unsubscribed from, because they are how you get in.
  • Cookies. Change your choices at any time at /settings/privacy.
  • Access, correction, objection, portability. Email [dpo@schedol.com]. We answer within [period]. You may also complain to your local data protection authority.

7. Contact

[dpo@schedol.com], or by post to [registered address].

8. Governing law

This policy is governed by the laws of [jurisdiction].

9. Changes

When this policy changes in a way that matters, we will tell you by email or in the app before it takes effect. The date at the top is the date of the current version.