OpenOak
Sign in Create account

Legal

Last updated August 24, 2026

Privacy Policy

This privacy policy explains what OpenOak handles across the shared OpenOak account layer and the OpenOak apps. The goal is simple: collect as little as practical, keep the service usable, and make the processing clear.

OpenOak Account

When you create an OpenOak account, we process the information needed to let you sign in, secure the account, recover access, and connect your account to OpenOak apps.

  • Email address - used for sign-in, account recovery, and service messages.
  • Authentication data - session, security, and access records needed to keep your account working.
  • Technical logs - basic request and security logs used to deliver the service and prevent abuse.

We do not sell personal data, build advertising profiles, or use behavioral analytics. The OpenOak websites do not use analytics, fingerprinting, ads, or tracking scripts. OpenOak apps use only storage needed for sign-in, preferences, offline behavior, and the features you request.

OpenTodo

OpenTodo stores the tasks, lists, settings, and related metadata you create in the app so they can sync across devices and remain attached to your OpenOak account.

OpenOutline

OpenOutline stores the outlines, notes, drafts, settings, and related metadata you create in the app so they can sync across devices and remain attached to your OpenOak account.

OpenKanban

OpenKanban stores the boards, columns, cards, workflow settings, and related metadata you create in the app so they can sync across devices and remain attached to your OpenOak account.

Future apps

Future OpenOak apps may have app-specific privacy details. Those details apply when you use that app, not merely because you created an OpenOak account.

How we use data

  • To authenticate you and keep your account secure.
  • To store and sync the content you create in OpenOak apps.
  • To operate, debug, protect, and improve the service.
  • To comply with legal obligations where they apply.
We do not sell, rent, or share your personal data for advertising or marketing.

Infrastructure providers and hosting location

OpenOak uses Vercel to host and deliver the websites, shared account service, and apps. Server-side application functions are configured to run in Vercel's Frankfurt, Germany region (fra1). Static files and incoming requests may be served or routed through Vercel's global content-delivery and security network.

OpenOak uses Neon for managed PostgreSQL database services. The production database that stores OpenOak account and app data is provisioned in AWS Europe (Frankfurt), Germany (eu-central-1).

OpenOak uses Resend to deliver account verification, password reset, and other essential service email. Resend processes the recipient address and delivery metadata needed to send and troubleshoot those messages.

Privacy and support requests sent to openoaksoftware@proton.me are handled through Proton Mail. The marketing pages request the Space Grotesk font from Google Fonts, which receives ordinary web request information such as an IP address and browser headers.

These providers process data only as needed to provide their services to OpenOak. Operational logs, security systems, support, backups, failover, or provider subprocessors may involve processing in other locations under their applicable safeguards.

Legal basis

Where EU privacy law applies, processing is based on the need to provide the service you request, legitimate interests in running and securing the service, compliance with legal obligations, or consent where consent is required.

Retention and deletion

Account and app data is kept while your account is active or while needed to provide the relevant service. You can delete individual content in the apps. Until self-service account deletion is available, you can request full deletion by emailing the address below from your account email. After verifying the request, we delete active account and app data within 30 days unless retention is legally required.

Vercel and Resend keep operational and delivery logs according to the retention configured for those services. Neon backups expire according to the active database plan and backup settings. Deleted data may remain in those protected backups until they expire and is not restored except during service recovery. Proton correspondence is kept only as long as needed to resolve the request or meet legal obligations. OpenOak does not promise a longer retention period than the provider configuration supports.

Your rights

If you are in the EU, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, and lodge a complaint with your local supervisory authority.

Contact

For privacy questions or requests, contact openoaksoftware@proton.me.

Terms of Service

The hosted OpenOak service will be open sourced soon, once it is ready for public release. By creating an OpenOak account, you agree to the shared OpenOak Terms. App-specific terms apply when you use each OpenOak app.

OpenOak Account

An OpenOak account lets you access OpenOak apps with one account. You are responsible for keeping your account secure and for the activity that happens through it.

You agree not to:

  • Use OpenOak to store, publish, or transmit illegal content.
  • Abuse, disrupt, scrape, overload, or reverse-engineer service infrastructure.
  • Create accounts automatically or in bulk without permission.
  • Try to access another person's account or data.

OpenTodo

OpenTodo is a personal task manager. The tasks, lists, and other content you create remain yours. OpenTodo is provided to help with personal planning, but it should not be your only system of record for critical information.

OpenOutline

OpenOutline is a notes and outlining app. The outlines, notes, drafts, and other content you create remain yours. OpenOutline should not be your only system of record for critical information.

OpenKanban

OpenKanban is a board-based planning app. The boards, columns, cards, and other content you create remain yours. OpenKanban should not be your only system of record for critical project or operational information.

Future apps

New OpenOak apps may have their own app-specific terms. Those terms apply only when you use the relevant app. Creating an OpenOak account today does not mean you accept unknown future app terms.

Your content

You keep ownership of the content you create in OpenOak apps. You give OpenOak the limited permission needed to store, process, and display that content so the service can work.

Open source

Standalone OpenOak app projects are open source. Unless a repository states otherwise, their code is released under AGPL-3.0-or-later. The remaining hosted-service code will be open sourced once it is ready for public release. Source-code licenses are separate from these service terms.

Service infrastructure

The hosted OpenOak service depends on third-party infrastructure, including Vercel for hosting and delivery and Neon for managed PostgreSQL. Server-side application functions and the production database are configured in Frankfurt, Germany. Vercel's global delivery network and provider operations such as security, support, backups, failover, and subprocessors may involve other locations. We may change providers or regions when reasonably needed to operate the service and will update the Privacy Policy when a material change affects how personal data is handled.

No warranty

OpenOak services are provided as-is, without warranty of any kind. We do not guarantee that the services will be available at all times, error-free, or suitable for a particular purpose.

Limitation of liability

To the fullest extent permitted by EU law, OpenOak and its developers are not liable for indirect, incidental, or consequential damages arising from use of the website, account layer, or apps, including data loss.

Account suspension and termination

We may suspend or terminate accounts that violate these terms, create security risks, or abuse the service. Where practical, we will make a reasonable effort to notify you first unless immediate action is needed.

Governing law

These terms are governed by applicable EU and EU member-state law. Jurisdiction is determined under applicable EU rules, and mandatory consumer protections remain unaffected.

Changes

We may update these terms from time to time. The date at the top of this page shows the latest version. Continued use of OpenOak after changes are posted means you accept the updated terms for the services you continue to use.

Contact

For questions about these terms, contact openoaksoftware@proton.me.

OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK 

PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · PRIVACY POLICY · 

OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK 

TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · TERMS OF SERVICE · 

OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK OPENOAK 

Privacy Policy Terms of Service