jectaproBack to home

Privacy Policy

Last updated: [DATE]

This Privacy Policy explains what data jectapro ("the Service", operated by [LEGAL ENTITY NAME]) collects, how it's used, and your choices.

1. What we collect

If you create an account (email/password or "Sign in with Microsoft"):

  • Account info: email address, and for password sign-up, a securely hashed password (we never store your password in plain text).
  • Project data you create: work breakdown structures, tasks, dependencies, team member records you add (name, role, email, availability — these are planning records you create, not separate user accounts), schedules, progress/actuals, and any project settings.
  • Your theme (light/dark) preference, stored against your account.
  • Basic technical data needed to operate the Service (e.g. request logs for debugging/security; [add analytics tooling here if/when adopted — none is used today]).

If you use "Continue as guest":

  • Nothing is sent to or stored on our servers. All project data lives only in your browser's session storage, is never transmitted to us, and is permanently deleted when you close the browser tab. We have no way to access, recover, or delete this data, because we never receive it.

If you purchase a paid plan:

  • Payment is handled entirely by our payment processor ([Stripe]). We receive confirmation that payment succeeded and a reference/subscription ID; we do not receive or store your full card number.

If you join a Team/Enterprise waitlist:

  • The email address you provide, so we can contact you about availability.

2. How we use this data

  • To provide and operate the Service (storing and computing your project schedule, authenticating you, remembering your preferences).
  • To process payments for paid plans, via our payment processor.
  • To contact waitlist members about plan availability.
  • To maintain security and diagnose technical issues.
  • We do not sell your data to third parties.

3. Third parties we share data with

  • [Stripe] — payment processing for paid plans.
  • [Microsoft Entra ID] — if you sign in with Microsoft, authentication is handled by Microsoft; we receive your verified identity, not your Microsoft account credentials.
  • We don't share your project data with any other third party.

4. Cookies and local storage

  • We use browser storage (localStorage/sessionStorage) to keep you signed in (a session token) and, in guest mode, to hold your entire session's project data locally as described above.
  • [Add here if/when any analytics or marketing cookies are introduced — none are used today.]

5. Data retention

  • Account and project data is retained for as long as your account exists.
  • Guest-mode data is never retained by us at all (see above).
  • You can delete a project, or your entire account, at any time; deleted data is removed from active storage [define backup-retention window, e.g. "and purged from backups within X days"].

6. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data. You can already export your project data (CSV/PDF/PNG export features in the app) and delete projects/your account directly. For anything else, contact us at [CONTACT EMAIL]. [Add GDPR/CCPA-specific language here once your target markets and legal entity are finalized.]

7. Children's privacy

The Service is not directed at children under 16, and we don't knowingly collect data from them.

8. International data transfer

[Add once hosting region(s) and target markets are finalized — e.g. "data is hosted in [Azure region] and may be processed in [country]."]

9. Changes to this policy

We may update this Privacy Policy from time to time; material changes will be communicated to registered users.

10. Contact

Questions about this policy or your data: [CONTACT EMAIL].


Note to the team: this is a lightweight starting draft written to unblock a fast public launch, not attorney-reviewed legal advice. It's written to accurately describe the app's actual current data handling (guest mode's browser-only storage, per-account persistence, Stripe for payment, Entra ID for SSO) — but the bracketed sections (retention windows, GDPR/CCPA specifics, hosting region, legal entity/jurisdiction) need real answers, and a legal review is recommended once those are filled in — ideally before launch if feasible, at minimum soon after.