Kanbanto

Privacy policy

Effective 4 October 2026

This is about the hosted Kanbanto at app.kanbanto.com and this website, kanbanto.com. Kanbanto is run by an independent developer. Questions: support@kanbanto.com.

The short version

What we store

What Why
Your name and email address, and your password as a one-way hash (we can't read it) Your account and signing in
Your boards, cards, comments, logged time, plans and the files you attach They are the service
Your settings: time zone, which notifications you want Reminders and summaries at the right time
A record of who changed what on a board, kept 180 days So you and your team can see what happened
If you turn on desktop notifications: the address your browser gives for sending them Sending those notifications
If you make API tokens or connect an AI app: a hash of each token, its name and when it was last used Letting that app act as you
A record that an email was sent to you (not its contents) Sending limits and troubleshooting

Like any website, the servers that deliver Kanbanto see your IP address and which pages were requested. We don't use that to track you, and our own logs don't contain what's in your boards.

Cookies and your browser

There are no advertising or analytics cookies.

Who else handles your data

Who What for
Railway Runs the app and its database (in Singapore)
Cloudflare Stores attached files (R2), serves this website, and handles email to our support address
Resend Sends our emails: confirmations, password resets, invites, reminders and summaries
Your browser's notification service (Google, Mozilla or Apple) Delivers desktop notifications, if you turn them on
Google Only if you connect Google Calendar (below)

If you connect your own storage bucket or your own email key in Account settings, your files or your invites go through that service instead, under your own account with it.

Google Calendar and Google user data

Connecting Google Calendar is optional. You do it in Account settings → Calendar, and nothing below happens unless you do.

What Kanbanto accesses

How Kanbanto uses it

What Kanbanto stores

Sharing

Kanbanto's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Removing it

Calendar links

If you make a calendar link, anyone who has that link can read the titles and dates of your cards, and nothing else. Keep it to yourself; you can replace it or turn it off at any time.

AI assistants and other apps you connect

An assistant or app you connect works with your access: it can read what you can read, and change what you let it change. What that app does with what it reads is between you and its maker, so connect only the ones you trust. You can disconnect any of them in Account settings.

What others can see

Keeping and deleting

Your rights

Wherever you live, you can ask us what we hold about you, to correct it, to give you a copy, or to delete it. Write to support@kanbanto.com.

Running Kanbanto yourself

This policy covers the hosted service only. A copy of Kanbanto that someone else runs is theirs to answer for.

Changes

If this policy changes in a way that matters, we'll say so here and by email before it takes effect.