Privacy policy

Here we explain, in plain terms, what personal data Kanlane processes, what for, who we share it with and what rights you have. It complies with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).

Last updated:

  1. Who the controller is
  2. Summary in a few lines
  3. What data we process
  4. What for and on what legal basis
  5. Other people's data that you enter
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. Your rights
  10. Security
  11. Minors
  12. Cookies and storage
  13. Changes to this policy

1. Who the controller is

Controller
Tax ID (NIF / CIF)
Registered address
Contact email
Website

Kanlane is a web application for organising work: tasks, calendar, clients and contacts, saved passwords and projects that can be shared with a team.

2. Summary in a few lines

  • Only what is needed. We process the data required for you to have your account and use the application.
  • No advertising or tracking. We do not use analytics, we do not build profiles and we do not sell your data.
  • Your saved passwords. The password and the notes of each credential are encrypted in your browser before being sent. We cannot read or recover them. The rest of your content is not encrypted in this way, except in projects you create with the "Full encryption" mode (see "Projects with full encryption") or "Managed by Kanlane" (see "Projects managed by Kanlane").
  • GitHub, only if you connect it. If you link a project to GitHub Projects, the title, description, column and labels of its tasks are sent to GitHub unencrypted and stay there.
  • AI assistants, only if you connect them. If you create a token so that an assistant can work with a project's tasks, what that assistant reads leaves Kanlane for that assistant's service, unencrypted, and stays there.
  • Guest mode. If you sign in as a guest, everything stays in your browser and does not reach our servers.
  • Your rights. You can access your data, correct it, take it with you or ask for it to be deleted by writing to us.

3. What data we process

Your account data

Your email address, your display name and your profile photo (the one provided by the provider you sign in with or the one you upload), an internal account identifier, the sign-in method (Google, GitHub or email and password) and the sign-up date. If you sign in with email and password, the password is managed by Google's authentication service (Firebase Authentication), which stores it protected; we do not see it.

The content you create

Projects, tasks, subtasks, labels, notes (text, images and files you attach), clients, contacts (name, email, phone and notes), meetings, automations (the rules and buttons you create and when they ran), the tasks you create by sending an email (see below), settings, installed plugins and the data they store and, if you work in a team, the project's members, their roles and the invitations (with the email of the person invited).

Tasks created by email

It is optional and is off until you turn it on in a project. When you turn it on, that project gets its own email address. When someone with permission to edit the project sends a message to that address from their account's email, the subject becomes the title of a task, the body its description (as text, without images or active content) and the supported attachments are stored with it. The task's activity records which address it was created from.

That email does not travel end-to-end encrypted. It is received by Cloudflare, which delivers it to our server, and there it is read in full to check who is sending it and to create the task. That is why projects with full encryption or "Managed by Kanlane" do not accept tasks by email. From the message we store what ends up in the task; the original message is not kept. What is not accepted (a sender without permission, a file that can be executed, a message that is too large, a duplicate) is discarded without being stored.

Besides the task, we store: the capture settings (the project, the chosen column, the list of allowed senders if you create one and, in a personal project, your email address as the only authorised sender), a fingerprint of the project's address (not the address), a fingerprint of each message received so as not to create the same task twice, and a message counter per project and per sender (with a fingerprint of the sender, not their address) to limit abuse. The server's technical logs record the outcome of each message (created, duplicate, rejected and why), without addresses, subject or content.

If you turn capture off, regenerate the address, delete the project or delete your account, the address stops accepting email at that moment. If a person is removed from a team, their email stops creating tasks in it.

Connected AI assistants (MCP server)

It is optional and does not exist until you create it. In Settings → Integrations you can create a token for a project and give it to an AI assistant compatible with the MCP protocol (for example, Claude Code). With that token, the assistant can read that project's tasks: title, description, column, dates, labels, subtasks, notes and activity, the name of the client and of the contact assigned to each task and the name of its attachments (not their content). If the token is not read-only, it can also move tasks between columns, add notes to them and create new tasks. It does not give access to client and contact records, to meetings, to saved passwords or to any other project.

What the assistant reads leaves Kanlane. Kanlane does not include any assistant or send your data to any AI model on its own: it only answers the requests that arrive with your token. Those answers are received by the program you have connected and, through it, by the company that provides that assistant (for example, Anthropic if you use Claude), which processes them as an independent controller, under its own terms and privacy policy, and may process them in the United States. What has already been sent stays there even if you delete the task or the project in Kanlane, revoke the token or close your account. We do not choose or control that service: before connecting it, review its terms.

Those requests are not end-to-end encrypted. They reach Cloudflare, which delivers them to our server, and there the tasks are read or changed in the database. That is why projects with full encryption or "Managed by Kanlane" do not accept assistants. In a team project, any member can create a token, and their assistant can read the whole team's tasks; someone who can only read the project can only create read-only tokens.

We store: a fingerprint of the token (not the token, which is shown only once, when it is created), the project it belongs to, who created it, the name you gave it, whether it is read-only, when it was created and when it was last used (to the nearest hour), as well as a daily counter of changes per project to limit abuse. Every change made with a token is recorded in the task's activity, with the name of whoever created it and the name of the token. The server's technical logs do not store the token or the content of the tasks.

You can revoke a token whenever you like from Settings → Integrations: it stops working on the next request. Tokens are also withdrawn if you delete the project, if it becomes encrypted, if you delete your account or, in a team, if whoever created it stops being a member.

Projects with full encryption

When creating a project you can choose the "Full encryption" mode. In those projects, the content (tasks and their notes, images and attachments, clients, contacts, meetings, the data of each credential and what plugins store in the project) is encrypted in your browser with 256-bit AES-GCM before being sent. The key can only be opened with your encryption password or with your recovery key; we know neither, so we cannot read that content or recover it if you lose them.

Not encrypted are the project's name, its columns and labels, the dates (of creation, of change, due dates and those of meetings), the status and order of the tasks, the people assigned, which tasks have linked contacts or credentials, which plugins are installed, and the number and approximate size of the items. The encryption key is stored in your browser for the duration of the session, or afterwards as well if you mark the device as trusted (see the cookie policy). These projects cannot be linked to GitHub. The application that performs the encryption is served from our site, so this protection also depends on the code your browser receives being the legitimate one.

Projects managed by Kanlane

When creating a project you can also choose the "Managed by Kanlane" mode. The same content as in full encryption is encrypted in your browser with 256-bit AES-GCM before being sent, and the same data listed above stays unencrypted, but there is no encryption password: the project's key is stored in the database wrapped with another key that our server (a Cloudflare Worker) derives from a secret that exists only on that server, and that it hands to your browser when you have signed in with your account. This protects the content if someone obtains a copy of the database, because that secret is not in it. It does not protect against us: whoever controls that server and its secret can technically obtain the key and decrypt the project. There is no separate recovery key either: access depends on your account and on that secret being kept. The key is stored in your browser for the duration of the session and is deleted when it ends. These projects cannot be linked to GitHub or, for now, shared with a team, and their backups are downloaded unencrypted.

Saved passwords

For each credential, the password and the notes are encrypted in your browser with a key derived from your master password (256-bit AES-GCM, with PBKDF2) before being sent. Of those two fields, our servers only hold ciphertext, and we do not know your master password, so we cannot decrypt or recover it if you lose it. The rest of each credential's data (type, client, service name, username or email, address and similar) is stored unencrypted, like the rest of your content: avoid writing there any information you do not want stored in the clear.

Technical data

When you connect, our infrastructure providers (see section 6) receive the IP address, the type of browser and the date and time of the request. They use them to make the service work and to detect abuse and attacks; we do not use them to build profiles.

What we do not do

  • We do not use cookies or tools for analytics or advertising.
  • We do not ask for data beyond the above or cross-reference it with other sources.
  • We do not make automated decisions or build profiles that produce legal effects for you.
  • Special categories of data (health, ideology, origin, etc.) are not intended for this service: we ask you not to enter them.

Guest mode and local mode

If you use the application as a guest, or without signing in, the data is stored only in your browser's storage (IndexedDB). It is not sent to our servers, it is not synced with other devices and it is lost if you clear the browser's data, so it is worth exporting a backup.

If you turn on encrypted backups for your account, the browser encrypts the backup with a random key before storing it in Firebase. Firebase receives the encrypted content, the project's identifier, the date and the number of items of each type. The key stays in your browser and you can save it to recover the backups on another device. Up to seven versions are kept per project. Without the key we cannot decrypt those backups. You can delete versions and stop the automatic backups from Kanlane.

GitHub integration

It is optional. If you link a Kanlane project to a GitHub Project, your browser communicates directly with the GitHub API using your authorisation; that data does not pass through our servers. When syncing, the title, description, column (status) and labels of that project's tasks are sent to GitHub unencrypted, and the new tasks you create in Kanlane are created there as drafts if you have that option turned on. If a task is linked to an issue in a repository, changes to the title, description and labels are applied to that issue. The rest of the task (client, contact, due date, subtasks, notes and linked passwords) is not sent. In a linked team project, the tasks of all members are sent, from the browser of whoever syncs.

GitHub processes that data as an independent controller, under its own terms and privacy statement, and may process it in the United States. If the GitHub Project or the repository is public, those tasks are public too. What has been sent stays on GitHub even if you delete the task or the project in Kanlane, unlink it or close your account: deletions are not propagated to GitHub and, if you want to remove it, you have to do so there.

Access to GitHub (the token you paste or the "Connect to GitHub" authorisation) is stored only in your browser, never on our servers, and does not travel with your account. It gives access to your account's GitHub projects (project permission). "Forget token" or "Remove my GitHub access" delete it from that browser; to revoke it completely, do so on GitHub (Settings → Applications for the authorisation, or Developer settings → Personal access tokens for a token).

4. What we use your data for and on what legal basis

PurposeLegal basis (GDPR)
Creating and maintaining your account and giving you access to the application; storing and syncing your content; enabling teamwork.Performance of the contract: the terms and conditions you accept when using the service (art. 6.1.b).
Verifying your email, sending you essential service notices and managing invitations to projects.Performance of the contract (art. 6.1.b).
Maintaining security, preventing fraud and abuse, and resolving technical incidents.Legitimate interest in protecting the service and its users (art. 6.1.f).
Handling your rights requests and your enquiries.Legal obligation and, for enquiries, performance of the contract or your request (art. 6.1.c and 6.1.b).
Complying with the legal obligations that apply to us, including keeping data blocked while liability may be claimed.Legal obligation (art. 6.1.c).
Storing on your device items that are not essential (for example, analytics), if they were ever used.Your consent (art. 6.1.a), which you can withdraw whenever you like. None is used today.

To create an account we need the sign-in details; if you do not provide them, we will not be able to give you the service. You enter the rest of the data voluntarily when using the application.

5. Other people's data that you enter

In Kanlane you can store data about other people, for example your clients' contacts or the members of your team. In that case:

  • If you do so in the course of a professional or business activity, you are the controller of that data and we are your processor (art. 28 GDPR). It is up to you to have a legal basis for storing it and to inform those people.
  • If you do so for a purely personal or household activity, the GDPR does not apply to that processing.

As processor, and as far as that data is concerned, we undertake to:

  • process it only to provide the service to you and following your instructions (the use you make of the application);
  • maintain the confidentiality of those who access it and apply the security measures in section 10;
  • use only the providers in section 6, which offer sufficient guarantees and are subject to equivalent obligations;
  • help you respond to those people's rights and notify without undue delay any security breach that affects them;
  • delete the data or return it to you when the service ends (you can export a backup at any time) and make available to you the information needed to demonstrate compliance.

These conditions form the data processing agreement between you and us and are understood to be accepted when you accept the terms and conditions.

6. Who we share your data with

We do not sell or hand over your data. To provide the service we use the providers in the table. Google (Firebase) and Cloudflare act as processors. The others are only involved if you choose so (signing in with Google or GitHub, linking a GitHub Project, connecting an AI assistant or installing a third-party plugin) and are governed by their own terms and policies:

ProviderWhat forWhat data it receives
Google Ireland Limited / Google LLC (Firebase Authentication, Cloud Firestore and reCAPTCHA Enterprise/App Check)Sign-in, database and protection against automated access. Data hosted in for Firestore.Account data, content, optional encrypted backups and technical data (including the browser signals that reCAPTCHA uses to tell a person from a program). Firebase's code (www.gstatic.com) and reCAPTCHA's (www.google.com) are downloaded only when you open the application to sign in, not in guest mode.
Cloudflare, Inc.Hosting the website, content delivery network, relaying the sign-in, running date-based automations, receiving the email of projects that have tasks by email turned on, handling the requests of the AI assistants you connect and, in "Managed by Kanlane" projects, holding the secret from which the key that protects the project's key is derived.If you create date-based automations in a project without full encryption: those rules and, when they run, that project's tasks with a due date coming up. If you turn on tasks by email in a project: the messages sent to its address, in full (sender, subject, body and attachments), and the delivery data that Cloudflare records under its own terms. If you connect an AI assistant to a project: the requests made with your token and that project's tasks that the assistant reads, creates or changes. IP address and technical data of the request. In "Managed by Kanlane" projects, in addition, your account's session identifier (to check who is asking for the key) and the technical identifiers of the project and of its key; it does not receive the project's content.
Google (Google Sign-In) or GitHub, Inc. (Microsoft)Only if you choose to sign in with that provider.The data that provider shares with Kanlane (email, name and photo). They are also governed by its own privacy policy.
GitHub, Inc. (Microsoft)Only if you link a project to GitHub Projects: your browser sends the data directly to GitHub, which processes it as an independent controller under its own terms (see section 3).The title, description, column (status) and labels of the linked project's tasks, unencrypted. Kanlane does not receive your token.
The company that provides the AI assistant you connect (for example, Anthropic if you use Claude)Only if you create a token and connect it to an assistant: the assistant requests the data from our server and that company processes it as an independent controller under its own terms (see section 3).That project's tasks that the assistant reads: title, description, column, dates, labels, subtasks, notes and activity, the name of the assigned client and contact and the name of the attachments, unencrypted. Kanlane does not send it anything on its own initiative.
Plugin developersOnly if you install a third-party plugin: it is loaded from its own website, isolated from the application.Only the data covered by the permissions you grant it when installing it. Never your saved passwords.

We may also disclose data to authorities, judges and courts when a law obliges us to. If you work in a team, the other members of the project see that project's data and your name, photo and email.

7. International transfers

Some providers belong to groups based in the United States. Those transfers rely on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (Implementing Decision (EU) 2023/1795), for the companies that have joined it, and, failing that, on the standard contractual clauses approved by the Commission. You can ask us for more information at the email address in section 1.

What you send to GitHub with the GitHub Projects integration does not pass through our servers: your browser sends it directly to GitHub, which may process it in the United States under its own terms.

What an AI assistant you have connected to a project reads is received by the company that provides that assistant, which may process it in the United States or in other countries under its own terms. You decide on that transfer when you connect it.

8. How long we keep your data

  • Account and content: for as long as you keep your account. You can delete projects and their content from the application at any time. The encrypted backups you turn on are kept until you delete them or they are replaced by more recent versions; seven are kept per project.
  • Tasks created by email: the task and its attachments are your content and are kept like the rest. The fingerprints of received messages are stored with a 30-day expiry and the message counters with a 3-day expiry; after that date they are no longer used and our server deletes them in its next periodic clean-up. The capture settings are deleted when you turn it off, delete the project or delete the account.
  • AI assistant tokens: each token's fingerprint and its data (name, who created it, dates) are kept until you revoke it, delete the project, encrypt it or delete your account. The daily change counters are deleted after 3 days, in the server's next periodic clean-up. What the assistant has read is kept in that assistant's service under its terms, even if you delete it in Kanlane.
  • Data sent to GitHub: it is kept on GitHub under its terms, even if you delete the task or the project in Kanlane, unlink it or close your account. To remove it you have to delete it on GitHub.
  • Closing the account: you can delete it yourself from the application (Settings → Account and data → Delete account): your account and your content are deleted at that moment. If you ask us by email to close it, we do so within a maximum of 30 days. Providers may keep encrypted backups for a limited period before deleting them for good.
  • Technical data and security logs: for the time set by our providers, which is short.
  • Legal obligations: if a law requires some data to be kept, we will keep it blocked, available only to the authorities, for the applicable limitation periods, and then delete it.

9. Your rights

You can exercise, free of charge, the following rights over your data:

  • Access: knowing what data of yours we process and receiving a copy.
  • Rectification: correcting inaccurate or incomplete data. Your name, your photo and your password are changed in the application, in Settings → Account and data.
  • Erasure: asking us to delete it. You can delete your account and all your content yourself, in Settings → Account and data → Delete account.
  • Objection: objecting to processing based on our legitimate interest.
  • Restriction: asking us to stop using it while a complaint is being resolved.
  • Portability: receiving your data in a structured, commonly used format. In the application, "Backup" downloads your content as a JSON file.
  • Withdrawing your consent at any time, if the processing is based on it, without affecting what was done before.

To exercise them, write to us at stating which right you want to exercise. We may ask you to prove your identity. We will reply within a maximum of one month, which may be extended by two more months if the request is complex, with prior notice.

If you believe we have not processed your data correctly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es, C/ Jorge Juan, 6, 28001 Madrid), without prejudice to going to another supervisory authority or to the courts.

10. Security

We apply technical and organisational measures appropriate to the risk, including:

  • an encrypted connection (HTTPS) with an HSTS policy and a strict content security policy (CSP) against code injection;
  • database access rules: each account can only read and write what is its own, and in shared projects only the members, according to their role;
  • email verification for accounts with a password and protection against mass sign-in attempts;
  • encryption in your browser of the passwords and notes of saved credentials, and of all the content in projects with "Full encryption";
  • AI assistant tokens limited to one project, with a read-only option, revocable instantly and stored only as a fingerprint, with limits on requests and on daily changes;
  • isolation of plugins in a frame with no access to your session or your passwords.

No system is infallible. If a security breach occurred that poses a risk to your rights, we will notify the supervisory authority within a maximum of 72 hours and, where the risk is high, the people affected as well. You can help too: use a unique, strong password and turn on two-step verification on your Google or GitHub account.

11. Minors

Kanlane is aimed at people over 14, which is the minimum age to consent to data processing in Spain (art. 7 LOPDGDD). We do not knowingly collect data from minors under that age; if we detect such an account, we will delete it.

12. Cookies and storage

Kanlane only uses essential technical storage on your device (for example, to keep you signed in and remember your language and your theme). Everything is explained, with the list of what we store, in the cookie policy, where you can also change your preferences.

13. Changes to this policy

We may update this policy, for example if the law or the service changes. We will show the date of the last revision above and, if the change is significant, we will let you know inside the application. We recommend reviewing it from time to time.