Privacy Policy
This privacy policy explains what OpenOak handles across the shared OpenOak account layer and the OpenOak apps. The goal is simple: collect as little as practical, keep the service usable, and make the processing clear.
OpenOak Account
When you create an OpenOak account, we process the information needed to let you sign in, secure the account, recover access, and connect your account to OpenOak apps.
- Email address - used for sign-in, account recovery, and service messages.
- Authentication data - session, security, and access records needed to keep your account working.
- Technical logs - basic request and security logs used to deliver the service and prevent abuse.
We do not sell personal data, build advertising profiles, or use behavioral analytics. The OpenOak websites do not use analytics, fingerprinting, ads, or tracking scripts. OpenOak apps use only storage needed for sign-in, preferences, offline behavior, and the features you request.
OpenTodo
OpenTodo stores the tasks, lists, settings, and related metadata you create in the app so they can sync across devices and remain attached to your OpenOak account.
OpenOutline
OpenOutline stores the outlines, notes, drafts, settings, and related metadata you create in the app so they can sync across devices and remain attached to your OpenOak account.
OpenKanban
OpenKanban stores the boards, columns, cards, workflow settings, and related metadata you create in the app so they can sync across devices and remain attached to your OpenOak account.
Future apps
Future OpenOak apps may have app-specific privacy details. Those details apply when you use that app, not merely because you created an OpenOak account.
How we use data
- To authenticate you and keep your account secure.
- To store and sync the content you create in OpenOak apps.
- To operate, debug, protect, and improve the service.
- To comply with legal obligations where they apply.
Infrastructure providers and hosting location
OpenOak uses Vercel to host and deliver the websites, shared account service, and apps. Server-side application functions are configured to run in Vercel's Frankfurt, Germany region (fra1). Static files and incoming requests may be served or routed through Vercel's global content-delivery and security network.
OpenOak uses Neon for managed PostgreSQL database services. The production database that stores OpenOak account and app data is provisioned in AWS Europe (Frankfurt), Germany (eu-central-1).
OpenOak uses Resend to deliver account verification, password reset, and other essential service email. Resend processes the recipient address and delivery metadata needed to send and troubleshoot those messages.
Privacy and support requests sent to openoaksoftware@proton.me are handled through Proton Mail. The marketing pages request the Space Grotesk font from Google Fonts, which receives ordinary web request information such as an IP address and browser headers.
These providers process data only as needed to provide their services to OpenOak. Operational logs, security systems, support, backups, failover, or provider subprocessors may involve processing in other locations under their applicable safeguards.
Legal basis
Where EU privacy law applies, processing is based on the need to provide the service you request, legitimate interests in running and securing the service, compliance with legal obligations, or consent where consent is required.
Retention and deletion
Account and app data is kept while your account is active or while needed to provide the relevant service. You can delete individual content in the apps. Until self-service account deletion is available, you can request full deletion by emailing the address below from your account email. After verifying the request, we delete active account and app data within 30 days unless retention is legally required.
Vercel and Resend keep operational and delivery logs according to the retention configured for those services. Neon backups expire according to the active database plan and backup settings. Deleted data may remain in those protected backups until they expire and is not restored except during service recovery. Proton correspondence is kept only as long as needed to resolve the request or meet legal obligations. OpenOak does not promise a longer retention period than the provider configuration supports.
Your rights
If you are in the EU, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, and lodge a complaint with your local supervisory authority.
Contact
For privacy questions or requests, contact openoaksoftware@proton.me.