Legal

Privacy Policy

What we collect, why we collect it, and how long we keep it.

Last updated August 10, 2026 Effective August 10, 2026 Version 0.1 (draft)
Draft — not yet reviewed by counsel

untactit is pre-launch. This document describes how we intend to operate and is published so you can see it early. It has not been through legal review and is not yet a binding agreement. If you need executed terms before that review completes, contact us and we will handle it directly.

English is the governing version

Translations of this page may be provided for convenience. Where a translation conflicts with the English text, the English text controls.

1. Scope

This policy covers personal information we handle as a controller — account data, billing data, and product analytics. Content you upload into your workspace is handled as a processor on your instructions and is governed by our Data Processing Addendum instead.

2. What we collect

CategoryWhat it includesWhere it comes from
IdentityName, email address, profile picture, identity provider subject identifierYour identity provider at sign-in
OrganizationWorkspace name, verified domains, role assignments, invitation recordsYou and your administrators
BillingPlan, seat counts, invoices, billing contactYou. Card details go directly to our payment processor — we never receive them
UsageFeature usage, credit consumption, error reports, approximate location from IPAutomatically, as you use the product
AuditWho did what and when, including IP address and user agent Automatically. Retained per your plan

We do not store passwords. Authentication happens at your identity provider, so there is no credential database here.

3. How we use it

  • To operate the service, authenticate users, and enforce permissions.
  • To bill you accurately and prevent abuse of usage limits.
  • To investigate security incidents and maintain the audit trail your plan provides.
  • To support you when you contact us.
  • To understand which features are used, in aggregate, so we build the right things.

We do not use your data to train machine learning models, and we do not sell personal information or share it for cross-context behavioral advertising.

4. Legal bases

Where GDPR or similar law applies, we rely on:

  • Contract — to provide the service you signed up for.
  • Legitimate interests — security, abuse prevention, and product improvement, balanced against your rights.
  • Legal obligation — tax, accounting, and lawful requests.
  • Consent — for optional communications, which you can withdraw at any time.

5. Who we share it with

We share personal information with the subprocessors listed in our subprocessor list, each bound by contract to process it only on our instructions.

We may also disclose information when required by law, to protect our rights or someone's safety, or as part of a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.

6. How long we keep it

DataRetention
Account and profileWhile your account is active, then deleted within 30 days
Workspace contentUntil you delete it, or 30 days after account closure
Audit logsPer your plan — 90 days, 1 year, or 3 years
Billing recordsSeven years, as required for tax and accounting
Support correspondenceThree years

7. Your rights

Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to complain to a supervisory authority.

Most of this is available directly in the product: you can export your data at any time and delete your account from workspace settings. For anything else, write to privacy@untactit.com and we will respond within 30 days. We do not charge for these requests and we will not treat you differently for making one.

If you are a member of a workspace your employer administers, direct requests about workspace content to them — they control that data, and we act on their instructions.

8. International transfers

We operate from the United States and our infrastructure providers operate globally. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with additional technical measures including encryption in transit and at rest.

Enterprise customers can request regional data residency.

9. Cookies

We use the minimum set of cookies needed to run the product:

CookiePurposeDuration
SessionKeeps you signed inSession or up to 30 days
CSRF tokenPrevents cross-site request forgerySession
PreferencesLanguage and interface settings1 year

We do not use advertising or cross-site tracking cookies.

10. Children

The service is for organizations and is not directed to anyone under 16. We do not knowingly collect information from children. If you believe we have, write to privacy@untactit.com and we will delete it.

11. Changes

We will post changes here and update the date at the top. For material changes we will notify account administrators by email at least 30 days before they take effect.

12. Contact

Privacy questions or requests: privacy@untactit.com
Security matters: security@untactit.com

A registered business address and, where required, an EU/UK representative will be published here before general availability.