Privacy Policy

Last updated: 1 September 2026

This policy explains what iKanban collects, why, who else can see it, and what you can do about it. It covers the iKanban web application, the marketing site, the desktop app, and the MCP and REST APIs.

iKanban is operated from Singapore and this policy follows Singapore's Personal Data Protection Act 2012 (PDPA).

Who we are

iKanban provides AI-assisted task, project and document management.

For data you enter into a workspace, you — or the organisation whose workspace you joined — decide what goes in and why. We handle that content on your behalf. For account and billing records we need in order to run the service, we are the organisation responsible.

What we collect

Information you give us

DataWhere it comes from
Email address, first and last name, usernameAccount creation and profile
Profile pictureOptional, if you upload one
Workspace, team and project names, and your roleSetting up your workspace
Tasks, comments, documents, uploaded files, chat messagesEverything you create in the product
AI provider API keysOptional, only if you enable AI features
Support and contact messagesWhen you write to us

Your account is authenticated through AWS Cognito. We store the identifier Cognito issues for you so we can match a sign-in to your iKanban account. We never see or store your password.

Information collected automatically

What we do not collect

We do not store card numbers or bank details. Payments run through Stripe; we keep only the identifiers Stripe gives us to link your account to your subscription. We do not sell personal data, and we do not use your workspace content to train our own models.

Why we use it, and your consent

We collect, use and disclose personal data for these purposes:

By creating an account and using iKanban you consent to the above. Some processing is also permitted without consent where the PDPA allows it — for example where it is necessary to conclude or perform a contract with you, or where a legitimate interests exception applies.

You can withdraw consent at any time by writing to us at the contact above. We will tell you the likely consequences — for most processing, withdrawing consent means we can no longer provide the service, and the account would need to be closed.

Analytics

We use PostHog to understand how the product is used. It is configured to capture page views, page-leave events, interaction events and page-performance timings, and it is hosted in the United States.

Being straight about how this currently behaves: analytics start when a page loads, including for visitors who are not signed in. Signed-in users can switch this off in Settings → Privacy → Enable Telemetry; turning it off stops collection for your account. We do not send task content, document contents or prompts to PostHog.

AI features and your provider keys

AI features work on a bring-your-own-key basis. You add your own provider key, requests go to the provider you chose, and they bill your account — we take no markup.

The technical detail — exactly what is sent, and what is stripped out first — is in Data Security.

If you use the coding-agent integrations (@claude, @copilot, @gemini), the task content you reference is sent to GitHub and to that agent's provider so it can do the work you asked for.

Who else sees your data

We share data only with providers who help us run the service:

ProviderWhat forWhere
Amazon Web ServicesHosting, database, file storage, encryption keysUnited States
AWS CognitoSign-in and identityUnited States
StripePayments and subscriptionsUnited States
AWS SESService emailUnited States
PostHogProduct analyticsUnited States
Your chosen AI providerAI features you enableDepends on the provider
GitHub / GitLabOnly if you connect a repositoryUnited States

We also disclose data where the law requires it, or to protect the service and its users.

Sending data outside Singapore

iKanban's infrastructure runs in the United States (AWS, US East). Using the service means your personal data is transferred out of Singapore and processed there.

Under the PDPA's Transfer Limitation Obligation, we must make sure an overseas recipient protects your data to a standard comparable to the PDPA. We do this through our contractual terms with the providers listed above, including their data processing agreements.

Security

No system is perfectly secure, but we treat the data you trust us with accordingly.

If something goes wrong

If a data breach occurs that is likely to result in significant harm to affected individuals, or is of a significant scale, we will notify the Personal Data Protection Commission (PDPC) and affected individuals within the timeframes the PDPA requires.

How long we keep it

We keep personal data only as long as it serves the purposes above, or as long as we are legally required to. Your workspace content is kept while your account or workspace exists. Delete something and it is removed from the product; backups age out on their own cycle.

Your rights

Under the PDPA you may:

Some of this you can do yourself in the product — edit your profile, delete content, remove an AI key, turn analytics off. For anything else, write to us at the address above. We will respond within the timeframes the PDPA sets, and will tell you if a request cannot be met in full and why. A reasonable fee may apply to an access request, and we will tell you in advance if so.

If you are in a jurisdiction with additional data protection rights, you may have further rights beyond those listed here — write to us and we will deal with your request.

If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore.

Children

iKanban is a workplace tool and is not directed at children. We do not knowingly collect the personal data of children without appropriate consent.

Changes

We will update this page when our practices change and move the date at the top. Significant changes will be announced in the product.

Contact

Questions, access or correction requests, or complaints:

A designated Data Protection Officer and their contact details will be published here once the Singapore entity is registered.