Privacy Policy
Last updated: 1 September 2026
This policy explains what iKanban collects, why, who else can see it, and what you can do about it. It covers the iKanban web application, the marketing site, the desktop app, and the MCP and REST APIs.
iKanban is operated from Singapore and this policy follows Singapore's Personal Data Protection Act 2012 (PDPA).
Who we are
iKanban provides AI-assisted task, project and document management.
- Operator: iKanban, operated from Singapore. Our registered entity name, UEN and address will be published here once incorporation completes.
- General contact: support@i-kanban.com
- Data protection enquiries: support@i-kanban.com. A designated Data Protection Officer and their published contact details will follow once the Singapore entity is registered.
For data you enter into a workspace, you — or the organisation whose workspace you joined — decide what goes in and why. We handle that content on your behalf. For account and billing records we need in order to run the service, we are the organisation responsible.
What we collect
Information you give us
| Data | Where it comes from |
|---|---|
| Email address, first and last name, username | Account creation and profile |
| Profile picture | Optional, if you upload one |
| Workspace, team and project names, and your role | Setting up your workspace |
| Tasks, comments, documents, uploaded files, chat messages | Everything you create in the product |
| AI provider API keys | Optional, only if you enable AI features |
| Support and contact messages | When you write to us |
Your account is authenticated through AWS Cognito. We store the identifier Cognito issues for you so we can match a sign-in to your iKanban account. We never see or store your password.
Information collected automatically
- Activity records. Actions taken in a workspace — who changed what, and when — including the IP address and browser user-agent of the request. These drive the activity feed and audit history.
- Usage analytics. Pages viewed, clicks, navigation and page-performance timings (see Analytics below).
- Service logs. Ordinary server logs needed to operate and secure the service.
What we do not collect
We do not store card numbers or bank details. Payments run through Stripe; we keep only the identifiers Stripe gives us to link your account to your subscription. We do not sell personal data, and we do not use your workspace content to train our own models.
Why we use it, and your consent
We collect, use and disclose personal data for these purposes:
- To provide the product — your workspace, your data, your collaborators.
- To authenticate you and keep accounts secure.
- To bill you and enforce plan limits.
- To send service email: invitations, notifications and account notices, sent via AWS SES.
- To fix problems and improve the product.
- To meet legal and regulatory obligations.
By creating an account and using iKanban you consent to the above. Some processing is also permitted without consent where the PDPA allows it — for example where it is necessary to conclude or perform a contract with you, or where a legitimate interests exception applies.
You can withdraw consent at any time by writing to us at the contact above. We will tell you the likely consequences — for most processing, withdrawing consent means we can no longer provide the service, and the account would need to be closed.
Analytics
We use PostHog to understand how the product is used. It is configured to capture page views, page-leave events, interaction events and page-performance timings, and it is hosted in the United States.
Being straight about how this currently behaves: analytics start when a page loads, including for visitors who are not signed in. Signed-in users can switch this off in Settings → Privacy → Enable Telemetry; turning it off stops collection for your account. We do not send task content, document contents or prompts to PostHog.
AI features and your provider keys
AI features work on a bring-your-own-key basis. You add your own provider key, requests go to the provider you chose, and they bill your account — we take no markup.
- Keys are encrypted before storage with AES-256, using a key held in AWS KMS. The database stores only ciphertext.
- If you have not added a key, no data is sent to any AI provider — affected features fall back to non-AI behaviour.
- We keep records of AI usage (which model, how much) for cost visibility, and an audit log of actions AI agents take in your workspace.
- Anything sent to a provider is then governed by that provider's data policy. Review their API terms before enabling AI features.
The technical detail — exactly what is sent, and what is stripped out first — is in Data Security.
If you use the coding-agent integrations (@claude, @copilot, @gemini), the task content you reference is sent to GitHub and to that agent's provider so it can do the work you asked for.
Who else sees your data
We share data only with providers who help us run the service:
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, encryption keys | United States |
| AWS Cognito | Sign-in and identity | United States |
| Stripe | Payments and subscriptions | United States |
| AWS SES | Service email | United States |
| PostHog | Product analytics | United States |
| Your chosen AI provider | AI features you enable | Depends on the provider |
| GitHub / GitLab | Only if you connect a repository | United States |
We also disclose data where the law requires it, or to protect the service and its users.
Sending data outside Singapore
iKanban's infrastructure runs in the United States (AWS, US East). Using the service means your personal data is transferred out of Singapore and processed there.
Under the PDPA's Transfer Limitation Obligation, we must make sure an overseas recipient protects your data to a standard comparable to the PDPA. We do this through our contractual terms with the providers listed above, including their data processing agreements.
Security
- Traffic between your browser and iKanban travels over HTTPS/TLS.
- The database runs in a private network with no direct internet access.
- AI provider keys are encrypted at rest with AWS-KMS-backed AES-256.
- Access to a workspace is limited to its members; roles govern what each member can do.
No system is perfectly secure, but we treat the data you trust us with accordingly.
If something goes wrong
If a data breach occurs that is likely to result in significant harm to affected individuals, or is of a significant scale, we will notify the Personal Data Protection Commission (PDPC) and affected individuals within the timeframes the PDPA requires.
How long we keep it
We keep personal data only as long as it serves the purposes above, or as long as we are legally required to. Your workspace content is kept while your account or workspace exists. Delete something and it is removed from the product; backups age out on their own cycle.
Your rights
Under the PDPA you may:
- Access the personal data we hold about you, and ask how it has been used or disclosed in the past year.
- Correct personal data that is inaccurate or incomplete.
- Withdraw consent to our collection, use or disclosure of your personal data.
Some of this you can do yourself in the product — edit your profile, delete content, remove an AI key, turn analytics off. For anything else, write to us at the address above. We will respond within the timeframes the PDPA sets, and will tell you if a request cannot be met in full and why. A reasonable fee may apply to an access request, and we will tell you in advance if so.
If you are in a jurisdiction with additional data protection rights, you may have further rights beyond those listed here — write to us and we will deal with your request.
If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commission of Singapore.
Children
iKanban is a workplace tool and is not directed at children. We do not knowingly collect the personal data of children without appropriate consent.
Changes
We will update this page when our practices change and move the date at the top. Significant changes will be announced in the product.
Contact
Questions, access or correction requests, or complaints:
- support@i-kanban.com — including access and correction requests, and data protection enquiries.
A designated Data Protection Officer and their contact details will be published here once the Singapore entity is registered.