Privacy Policy
What Axonplane collects, why, and what you can ask us to do about it.
This document is a draft awaiting legal review. It was prepared from what the platform technically does. Every item marked
[CONFIRM]needs a decision from Axonplane before this is published.
Axonplane takes two different roles with personal data, and which one applies changes what you should do about it.
- Your account — your name, email and sign-in details. Axonplane decides how these are used, so Axonplane is the controller.
- What your workspace holds — employee records, customer contacts, support tickets, files. Your employer decides what goes in and why. Axonplane is the processor, acting on their instructions. If you want that data changed or removed, ask them; we act on their instruction, not directly on yours.
What we collect
To give you an account
Name, email address, password (stored hashed, never in readable form), profile picture if you add one, and multi-factor settings if you turn them on. If you sign in with Google or GitHub we receive your name and email from them, not your password.
Because the service runs
Audit records of security-relevant actions — signing in, changing a role, removing a member — each with an IP address and browser identifier. Product analytics about which features are used. Both are kept per workspace.
What your workspace puts in
This is the widest category and it is worth being specific, because some of it is sensitive:
| Kind | Examples |
|---|---|
| Work | Projects, tasks, comments, time logs, files |
| People | Employee records, time off, performance reviews, onboarding |
| Pay and benefits | Payroll runs, payslips, benefit enrolments |
| Documents | Contracts, NDAs, certifications, identity documents |
| Recruitment | Candidates, applications, interview notes |
| Customers | CRM contacts, deals, support tickets and their correspondence |
Payroll, identity documents and benefit records are sensitive. They are held because a workspace administrator chose to put them there.
Who else sees it
Axonplane does not sell personal data and does not share it for advertising. It reaches these processors because the service needs them to work:
| Who | What for | What reaches them |
|---|---|---|
| Amazon Web Services | File storage and hosting | Uploaded files, database contents |
| Polar | Subscriptions and payment | Billing email, plan, subscription state. Card details go to their processor and never touch Axonplane |
| Resend | Sending email | Recipient address and message contents |
| Sentry | Error diagnostics | Technical error data, which can incidentally include a user identifier |
| Anthropic | AI features, only if a workspace enables them | The text submitted to that feature |
| Google, GitHub | Sign-in, only if you use it | Your name and email, from them to us |
| Slack, Microsoft Teams, Jira | Integrations, only if a workspace connects one | The notifications and records that integration is set up to send |
[CONFIRM] Where the data is hosted, and the transfer mechanism for anyone
outside that region.
How long it is kept
Account data is kept while the account exists. Workspace data is kept while the workspace exists; deleting a workspace removes its data.
[CONFIRM] Retention periods for audit logs, analytics, backups, and how long
a deleted workspace is recoverable.
Keeping it safe
Passwords are hashed. Traffic is encrypted in transit. Stored credentials for third-party services are encrypted. Access is controlled by role, and every record is confined to its own workspace at the database level. Multi-factor authentication is available and can be required.
No system is perfect, and saying otherwise in a document like this would be a promise nobody can keep.
What you can ask for
Depending on where you live you may have the right to see a copy of your data, correct it, delete it, take it elsewhere, or object to some uses. Axonplane can act directly on these for your account. For anything inside a workspace, ask whoever runs it — we will help them, but the instruction has to come from them.
[CONFIRM] Which regimes are being claimed — UK GDPR, EU GDPR, CCPA — and the
response window.
Cookies
Axonplane sets the cookies it needs to keep you signed in and to remember preferences such as your theme and language. It does not use advertising cookies.
[CONFIRM] Whether analytics counts as strictly necessary in your jurisdiction,
and whether a consent banner is required.
Contact
[CONFIRM] Legal entity name, registered address, privacy contact address, and
a data protection officer or EU/UK representative if one is required.
Changes
Material changes will be announced before they take effect.
[CONFIRM] How — in-product notice, email, or both — and the notice period.