Privacy policy
This policy explains what Projalo collects, why, who helps us run it, and what choices you have. Projalo is run by [LEGAL ENTITY NAME] ("we" or "us").
Who this covers
This policy covers people who use the Projalo app, people who visit projalo.com, and people whose information ends up in a Projalo workspace, like a client who emails a project inbox or someone who opens a published page.
Workspace content belongs to the organization that owns the workspace. That organization decides what goes in and who can see it, and we handle that content on its behalf. [CONFIRM WITH COUNSEL: controller and processor roles, and whether to offer a data processing agreement]
What we collect
Your account
- Your email address. It's how you sign in.
- The name you give yourself, an optional photo, your title, and the organizations you belong to with your role in each.
Signing in and security
- One-time sign-in codes and invitation links we email you.
- Session records, including your IP address and browser or device details.
- An activity log of what happens in a workspace, including actions taken by Patch, by skills, or through a connected AI app.
Workspace content
- Projects, tasks, pages, templates, chat messages and files you upload.
- Email sent to a project's inbox address, including the sender's name and address, the message and any attachments.
- Skills you build, the findings and approvals they produce, and the edits and decisions people make on them.
Published pages
Anyone with the link can read a page you publish. Each time a published page is opened, we record when, which page, the visitor's IP address and, when our network provides it, an approximate location (city, region and country). Wrong password attempts on a protected page are recorded the same way. This shows up in the project's history.
AI features
- If your organization uses AI, the request and the workspace content needed to answer it.
- Usage records: provider, model, cost, and the member and project involved.
- Any AI provider key your organization adds. We store it encrypted.
Connections
- If an admin connects a service like Slack or Notion, we store its access tokens encrypted and read what that connection allows.
- For Slack, the channels the connected Slack account can see become readable to everyone in the workspace. Direct messages are excluded.
- If you talk to Patch in Slack, we match your Slack email address to your Projalo membership.
Billing
For paid plans, Stripe collects your payment details. We keep your plan, seat count, invoices and AI credit records. We don't store full card numbers.
Notifications
If you turn on browser notifications, we store your browser's push subscription so we can deliver them.
This website
projalo.com doesn't use analytics or advertising cookies. Our host processes standard request data, like IP address, to serve and protect the site.
Cookies
The app uses cookies to keep you signed in and to remember which organization you were last working in. We don't use advertising or tracking cookies. [CONFIRM: cookie list and whether a cookie notice is needed where you operate]
How we use it
- To run Projalo and the features you use.
- To sign you in and keep accounts secure.
- To send sign-in codes, invitations and notifications, and to put project email into the project chat.
- To run AI features your organization turns on.
- To bill for paid plans.
- To help when you contact us, and to meet legal obligations.
We don't sell your personal information, and we don't use your content for advertising. [CONFIRM: "We don't use your content to train AI models."]
AI features
AI in Projalo is optional. It only runs when your organization adds its own AI provider key or turns on AI credits from us.
When it runs, the request and the workspace content needed to answer it go to the provider your organization picked: Anthropic, OpenAI or xAI. With your own key, your organization's agreement with that provider applies. With AI credits, we send it under our account with that provider. [CONFIRM: each provider's data retention and training terms for API use]
Patch and skills only see what the person using them can see. Their work goes to a person for review as findings and approvals.
AI app connector (MCP)
Admins can turn on the AI app connector. Members can then sign in from an AI app like Claude or ChatGPT, and that app can read and change workspace data as them, with their permissions. What that app does with the data is covered by its own provider's terms, not this policy.
Who we share it with
We use these service providers to run Projalo. Each gets only what it needs for its job.
| Provider | What for |
|---|---|
| Railway | Hosting the app and its database, in the United States. |
| Amazon Web Services | Storing files you upload, in the United States. |
| Resend | Sending sign-in codes, invitations and notifications, and receiving email sent to project inboxes. |
| Stripe | Payments and billing for paid plans and AI credits. |
| Anthropic, OpenAI, xAI | AI features, only when your organization turns them on. |
| Google Maps Platform | Map blocks on pages. When a map loads, your browser contacts Google, and the place being looked up is sent to Google. |
| Cloudflare | Domain name service, and hosting for projalo.com. |
| Your browser's push service | Delivering browser notifications you turn on. The service depends on your browser, for example Google, Apple or Mozilla. |
Services your organization connects, like Slack, Notion, Rentman or an AI app, aren't our service providers. They get data through your organization's own accounts, under their own terms.
We may also share information if the law requires it, to protect people or the service, with your permission, or as part of a merger or sale of the business. [CONFIRM WITH COUNSEL]
Where it's stored
Projalo's app, database and files are hosted in the United States. [PLACEHOLDER: transfer mechanism for users outside the US, if needed]
How long we keep it
We keep account and workspace data while your account and organization are active. Changing plans or a failed payment doesn't delete your data.
Files are removed after the page, task, skill or organization they belong to is deleted. Uploads that were never finished are removed after a day.
[PLACEHOLDER: retention periods for deleted organizations, backups, session records and the activity log, including published-page visitor records]
Security
Access tokens and AI provider keys are stored encrypted. Uploaded files are kept in private, encrypted storage, and access is checked on every request. No system is perfectly secure, so we can't promise that nothing will ever go wrong. [PLACEHOLDER: breach notification commitment]
Your choices and rights
- You can change your name and photo in the app.
- For workspace content, start with your organization's owner or admins. They control it.
- To ask for a copy of your data, a correction, or deletion of your account, email [CONTACT EMAIL]. [PLACEHOLDER: export and deletion process and timing]
[PLACEHOLDER: region-specific rights, such as GDPR (EU/UK) and CCPA (California), if they apply]
Children
Projalo is for work and isn't meant for anyone under [MINIMUM AGE].
Changes to this policy
If we change this policy, we'll post the new version here and update the date at the top. For bigger changes we'll also let you know [NOTICE METHOD, for example by email or in the app].
Contact
[LEGAL ENTITY NAME]
[MAILING ADDRESS]
[CONTACT EMAIL]