Legal
Privacy Policy
Last updated: August 8, 2026
KaryaBoard ("KaryaBoard," "we," "us," or "our") is an AI-assisted project management product operated by VioletStack Pvt Ltd. This Privacy Policy explains how we collect, use, store, and share information when you use karyaboard.com, app.karyaboard.com, our API, IDE extension, and related services (collectively, the "Service").
By using the Service, you agree to this Policy. If you do not agree, please do not use the Service. Contact: support@karyaboard.com.
1. Information we collect
Account information. When you sign up we collect your name, email address, and authentication identifiers via Firebase Authentication (email/password or Google sign-in).
Workspace content. Content you create in the Service, including workspaces, projects, Kanban boards, stories, tasks, comments, mentions, attachments, invitations, and inbox activity.
GitHub integration data. If you connect GitHub (optional, typically on Pro/Scale), we receive an OAuth access token with the repo scope and may access repository lists, commit metadata, and commit diffs needed to link commits to tasks and power AI-assisted analysis. We do not use GitHub as your KaryaBoard login.
Billing information. Subscription plan, payment status, and transaction metadata processed by Razorpay. Card details are handled by Razorpay; we do not store full payment card numbers on our servers.
Usage and technical data. Approximate logs such as IP address, browser/device type, timestamps, and error diagnostics needed to operate and secure the Service.
2. How we use information
- Provide, maintain, and improve the Service (boards, stories, collaboration, GitHub features)
- Authenticate users and enforce project roles (owner, member, viewer)
- Generate AI suggestions for stories, tasks, and repository analysis (human review required before applying)
- Process subscriptions, trials, and receipts
- Send service-related messages (invites, security notices, billing)
- Detect abuse, debug issues, and protect the Service
3. Third-party services
We share data with processors only as needed to run KaryaBoard:
- Firebase Authentication (Google) — account sign-in
- GitHub — OAuth and repository/commit APIs when you connect GitHub
- Mistral AI — AI story/task suggestions and repository analysis; relevant context may be sent to generate outputs
- Razorpay — payments and billing
- Managed PostgreSQL hosting — application database
- Vercel — hosting for web frontends
Optional connectors (for example Claude MCP or the VS Code/Cursor extension) access your KaryaBoard data only when you enable them and authenticate. Each provider has its own privacy policy.
4. AI processing
AI features may send story text, task context, or repository/commit context to our AI provider to produce drafts and suggestions. Outputs are proposals; you decide what to keep. Do not submit secrets, credentials, or highly sensitive personal data into prompts or content you expect to be analyzed by AI.
5. Retention and deletion
We retain account and workspace data while your account is active. You may request deletion of your account by emailing support@karyaboard.com. We will delete or anonymize personal data within a reasonable period, except where we must retain records for legal, security, or billing obligations. You can disconnect GitHub at any time from the product; we stop using that token for new API calls after disconnect.
6. Security
We use HTTPS/TLS in transit, Firebase-verified API authentication, role-based project access, and server-side storage of GitHub tokens. No method of transmission or storage is 100% secure. If you believe there has been unauthorized access, contact us immediately.
7. Your choices and rights
- Update profile information in account settings where available
- Disconnect GitHub from the board Git integration
- Cancel or change subscription plans from billing settings
- Request access, correction, or deletion of personal data via support@karyaboard.com
Depending on where you live, you may have additional rights under local privacy laws. We will respond to reasonable requests consistent with applicable law.
9. Children
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps to delete it.
10. International transfers
The Service is operated by VioletStack Pvt Ltd and may process data in countries where our hosting and processors operate. By using KaryaBoard you understand your information may be transferred to and processed in those locations.
11. Changes
We may update this Policy from time to time. We will post the revised version on this page with an updated "Last updated" date. Continued use of the Service after changes means you accept the updated Policy.
12. Contact
Operator: VioletStack Pvt Ltd (KaryaBoard)
Email: support@karyaboard.com
Website: https://karyaboard.com
App: https://app.karyaboard.com
Questions? support@karyaboard.com · Back to home
