Privacy Policy
{# Operator note: set LEGAL_COMPANY_NAME / LEGAL_COMPANY_ADDRESS (and the other LEGAL_* vars in settings.py) to publish the controller's identity, which GDPR Art. 13(1)(a) requires. Until then this notice stands in for the missing details. #}⚠ This policy is being finalised. KanAssist is currently free and in open beta. The controller's registered details and the final legal review will be published before any paid plan launches. The disclosures below — including which providers receive your content — are accurate today.
The one thing to read first. KanAssist's AI planning features work by sending your project content — your brief, your task text, and the text of PDFs you upload — to a third-party AI provider so that a plan can be generated. That provider is named in section 5. If you cannot share a document with a third-party processor, do not upload it to KanAssist and do not use the AI features on it. Everything else in KanAssist (boards, backlog, sprints, timeline) works without any AI call.
1. Who we are (data controller)
KanAssist is a hosted service operated by KanAssist, . We are the data controller for the personal data described here.
This is not self-hosted software and there is no separate "instance operator" to refer you to — we run the servers and we are the party you contact. Privacy questions, requests, and complaints go to support@kanassist.com.
Where you use KanAssist to manage a team and you invite collaborators, you may be a controller in your own right for the personal data you choose to put into your projects; we act as your processor for that content.
2. What we collect
Data you give us
- Account data — username, email address, and a salted hash of your password. We never store your password in readable form.
- Google Sign-In data — if you sign in with Google, we receive your Google account email, name, and profile identifier from Google. We never receive your Google password.
- Profile data — display preferences such as your accent colour and onboarding progress.
- Project content — project and board names, column names, task titles and descriptions, labels, assignees, dates, story points, comments, sprint data, and any other text you type into the product. This content can contain personal data about you and about people you write about, because you decide what to type.
- Uploads — PDF documents you attach to a project for AI grounding (we also store extracted text chunks from them), card cover images, and screenshots you paste or upload for photo-to-board import.
- AI inputs and outputs — the briefs and instructions you write, and the generated plans, critiques, and suggestions, which we store on your project so you can return to them.
- Invitation data — the email addresses you enter when inviting collaborators.
- Support correspondence — anything you send us by email.
- Billing data (once paid plans launch) — name, billing address, country, and tax identifiers. We do not receive or store your full card number; card details are entered directly with our payment processor.
Data collected automatically
- Authentication and session data — a session identifier stored in a cookie, and timestamps such as last login.
- Server logs — generated by our hosting provider and web server. These typically include IP address, timestamp, requested URL, HTTP status, and user agent. We use them for security, abuse prevention, and debugging.
- Product usage records — records of actions in the product (for example that a plan job was run and whether it succeeded), used to operate the service and diagnose failures.
We do not run third-party analytics, advertising, or tracking pixels on KanAssist. We do not sell personal data and we do not share it for cross-context behavioural advertising.
3. Why we use it, and our legal bases
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Create and run your account; provide boards, backlog, sprints, timeline | Account, profile, project content | Performance of a contract (Art. 6(1)(b)) |
| Generate AI plans, critiques, and rewrites you request | Briefs, project content, uploaded document text | Performance of a contract (Art. 6(1)(b)) |
| Send collaborator invitations and the welcome email | Email addresses, project name | Performance of a contract; legitimate interests (Art. 6(1)(f)) |
| Billing, invoicing, tax records (once paid plans launch) | Billing and transaction data | Contract; legal obligation (Art. 6(1)(c)) |
| Security, abuse prevention, rate limiting, debugging | Server logs, session data, usage records | Legitimate interests (Art. 6(1)(f)) — keeping the service available and secure |
| Responding to support requests | Correspondence, account data | Contract; legitimate interests |
| Complying with legal requests and retaining records | Whatever the obligation requires | Legal obligation (Art. 6(1)(c)) |
We do not use your content to train AI models, ours or anyone else's, and we do not use it to build advertising profiles.
4. Automated processing
KanAssist uses large language models to generate planning suggestions. This is automated processing of the content you submit, but it does not produce legal or similarly significant decisions about you — the output is a draft plan that you review and edit. AI output can be wrong; see the AI disclaimer in our Terms of Service.
5. Who we share data with (subprocessors)
We use the following categories of third parties to run KanAssist. Which ones are active depends on how the production environment is configured; the list below covers everything the software is built to call. Verify this list against the live configuration before publishing.
| Provider | What it does | What it receives |
|---|---|---|
| DeepSeek (primary AI planning provider) | Generates plans, task breakdowns, critiques, and rewrites | Your brief, project text, and text extracted from PDFs you upload |
| OpenAI (configurable provider; also the vision model for photo-to-board import) | Plan generation where configured; reads screenshots for board import | Your brief and project text; the board screenshot you upload |
| Anthropic (configurable alternative provider) | Plan generation and vision where configured | Your brief, project text, and uploaded images |
| Railway | Application hosting, database hosting, and server logs | Everything stored in the service, plus request metadata including IP address |
| AWS S3 / S3-compatible object storage (including Wasabi) | Stores uploaded files — PDFs, card covers, imported screenshots — when object storage is enabled | The files you upload and their filenames |
| SkyMailr | Sends transactional email: collaborator invitations, "added to project" notices, welcome email | Recipient email address, sender name, project name, invitation link |
| Mailgun (used instead of / alongside SkyMailr where configured) | Transactional email delivery | Recipient email address and message content |
| Google (Sign-In) | Optional single sign-on | Only what is needed to authenticate you; Google tells us your email, name, and account id |
| Google Fonts | Serves the web fonts used on our public marketing pages | Your IP address and browser details, when your browser fetches the font files |
| Unsplash | Board background image search; images are served from Unsplash's CDN | Your search term; your IP address when your browser loads an image |
| Openverse (used when Unsplash is not configured) | Board background image search | Your search term; your IP address when your browser loads an image |
| Stripe (planned — not yet live) | Payment processing and subscription billing when paid plans launch | Name, email, billing address, card details entered directly with Stripe, and transaction records |
We may also disclose data to professional advisers, to a successor in a merger or acquisition (with notice to you), and to authorities where we are legally required to. We do not sell your data to anyone.
6. International transfers
KanAssist is operated from, and the providers above are largely located in, the United States, and the AI providers listed may process data in the United States or China (DeepSeek). If you are in the UK, EEA, or Switzerland, your data will therefore be transferred outside your country. Where we do this we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum / UK IDTA where applicable), together with the additional safeguards our providers offer. Standard Contractual Clauses (and the UK Addendum where applicable). Contact us at support@kanassist.com for a copy of the relevant safeguards.
7. How long we keep it
- Account data — for as long as your account exists.
- Project content, uploads, and generated plans — until you delete them, or until your account is deleted.
- After account deletion — we delete or irreversibly anonymise your account and content within 30 days, except for copies held in our hosting provider's backups, which are overwritten on that provider's normal rotation (on our hosting provider's standard rotation).
- Server logs — retained for a short operational period, typically 30 days, then deleted or rotated by our hosting provider.
- Billing and tax records — retained for as long as tax and accounting law requires (commonly 6–7 years), even after account deletion.
- Records of your acceptance of these terms — retained for the life of the account plus any applicable limitation period, because we may need to evidence the agreement.
8. Your rights
Depending on where you live, you have some or all of the following rights. In the UK/EEA these are GDPR Articles 15–22; in California they are the CCPA/CPRA equivalents.
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that is wrong or incomplete. Most of it you can edit yourself in the product.
- Erasure — ask us to delete your account and content ("right to be forgotten").
- Portability — receive your project data in a structured, machine-readable format. You can also export it yourself through our REST API and the plan PDF export.
- Restriction — ask us to pause processing while a dispute is resolved.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
- Non-discrimination — we will not degrade the service or charge you more because you exercised a right.
To exercise any of these, email support@kanassist.com from the address on your account. We will respond within 30 days (extendable where the law allows, in which case we will tell you). We may need to verify your identity first. You may use an authorised agent where the law allows.
9. Complaints
If you think we have handled your data badly, please tell us first at support@kanassist.com so we can put it right. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the data protection authority of the country where you live, work, or where the issue arose. Complaining to us first does not affect that right.
10. Cookies and local storage
KanAssist uses only strictly necessary cookies. We do not use analytics, advertising, or cross-site tracking cookies, and there is therefore no consent banner to click.
sessionid— keeps you signed in. Necessary. Expires when the session ends or you sign out.csrftoken— protects forms against cross-site request forgery. Necessary.- Cookies set by Google during Google Sign-In, if you use it, under Google's own policy.
We also use your browser's local storage to remember your light/dark theme preference
(kanassist-theme). That value never leaves your browser.
11. Children
KanAssist is not intended for children. You must be at least 16 to create an account. We do not knowingly collect personal data from anyone under 16; if you believe a child has given us data, email support@kanassist.com and we will delete it.
12. Security
- All traffic is served over HTTPS; session and CSRF cookies are marked secure in production and the session cookie is HTTP-only.
- Passwords are stored as salted hashes using Django's password hashing, never in plain text.
- Project access is enforced server-side on every request: you only see projects you own or were invited to.
- API credentials for AI, email, storage, and payment providers are held as server-side environment variables and are never sent to your browser.
- Database backups are handled by our hosting provider under its own retention and access controls: on our hosting provider's standard rotation.
No system is perfectly secure. If you find a vulnerability, please report it privately to support@kanassist.com rather than disclosing it publicly. Where the law requires it, we will notify affected users and the relevant authority of a personal data breach without undue delay.
13. Changes to this policy
We will update this page when our processing changes — including whenever we add or remove a subprocessor from section 5. Material changes will be announced by email or in-product notice at least 30 days before they take effect, and the version and effective date at the top will change.
14. Contact
KanAssist
Email: support@kanassist.com
Terms of Service · Refund & Cancellation Policy · ← Back to home