Privacy
Projano uses the information described here to operate and secure the project-tracking service. We do not sell personal information.
Information we process
- Account and sign-in data: name, email address, profile image, OAuth provider identifiers and tokens, and database session tokens and expiry times.
- Project content: project details, columns, tasks, descriptions, priorities, due dates, checklists, status notes, snapshots, ordering, and timestamps.
- Collaboration data: project memberships, permissions, invited email addresses, invitation status, and expiry timestamps.
Why we use it
We process this information to authenticate users, provide the board and reporting features, save changes, enforce project permissions, support collaboration, protect the service, and respond to support or privacy requests.
Service providers
Google, GitHub, or Microsoft process sign-in information when you choose an enabled OAuth provider. Hostinger provides production hosting, database, network, backup, and related infrastructure. If enabled, Plausible provides cookieless, aggregate product analytics. Projano sends Plausible only named usage events—not project names, project IDs, email addresses, task content, or other event properties.
Cookies
Projano uses technically necessary Auth.js cookies for sign-in, session continuity, callback state, and cross-site request protection. The configured Plausible integration is cookieless. Projano does not load the analytics script when analytics is not configured.
Retention and deletion
- Deleting an owned project deletes its columns, tasks, checklists, snapshots, memberships, and invitations through database relations.
- Sessions expire and are removed through sign-out and account lifecycle processes.
- Invitations expire after seven days. Accepted or revoked invitations are deleted; an expired record may remain until it is replaced, its project is deleted, or it is removed during maintenance.
- Account and OAuth records are retained while the service account exists, and may be retained as needed for security, operations, or legal obligations.
Projano does not yet provide in-app account deletion. To request access, correction, export, or deletion of personal information, email privacy@projano.com from the address associated with your account.
Security and international processing
We use access controls, encrypted HTTPS transport, restricted production configuration, and provider-managed infrastructure to protect data. No online service can guarantee absolute security. Service providers may process data in the countries where they operate, subject to their own safeguards and applicable law.
Changes and contact
We may update this notice as Projano evolves and will update the date above when changes are material. Questions and privacy requests can be sent to privacy@projano.com.