Privacy Policy
Effective Date: February 27, 2026 · Last Updated: February 27, 2026
This Privacy Policy explains how WinIt (“we,” “us,” or “our”), operated by OVRS, collects, uses, stores, and protects your personal information when you use the WinIt.space platform and related services (the “Service”). By using WinIt, you agree to the practices described in this policy.
1. Data Controller
The data controller for WinIt.space is OVRS. If you have questions about how your data is handled, please contact us at support@winit.space.
2. Information We Collect
We collect the following categories of personal data:
- Account Information: Email address, first and last name, and optional profile avatar when you create an account.
- Authentication Data: When you sign in via third-party OAuth providers (Google, GitHub, or Discord), we receive your public profile information (name, email, and avatar) as authorized by those providers.
- User-Generated Content: Tasks, boards, groups, comments, checklists, time entries, standup notes, and file attachments you create within the Service.
- Usage Data: Information about how you interact with the Service, including pages visited, features used, and timestamps of activity.
- Device & Browser Data: IP address, browser type, operating system, and device identifiers collected automatically for security and performance purposes.
3. How We Use Your Information
We use your personal data to:
- Create and manage your account and workspace.
- Provide task management, collaboration, and time-tracking features.
- Send transactional notifications (invitations, task assignments, status updates).
- Verify your identity through CAPTCHA challenges (Cloudflare Turnstile) during sign-in and sign-up.
- Detect, prevent, and address security issues, abuse, and technical problems.
- Improve and optimize the Service based on aggregated, anonymized usage patterns.
We do not use your data for advertising. We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Data Storage & Infrastructure
Your data is stored and processed using the following services:
- Supabase: Database (PostgreSQL) and file storage. Supabase provides Row Level Security (RLS) policies ensuring users can only access their own data.
- Vercel: Application hosting and serverless function execution.
- Cloudflare Turnstile: CAPTCHA verification to prevent automated abuse. Cloudflare may process your IP address and browser signals for bot detection.
Data may be processed in data centers located in the United States and the European Union, depending on the infrastructure provider. We ensure all third-party processors maintain appropriate security standards.
5. Cookies & Local Storage
WinIt uses the following browser storage mechanisms:
- Authentication Cookies: Secure, HTTP-only session tokens set by Supabase Auth to maintain your signed-in state.
- Local Storage: Theme preference (light/dark mode) and UI state (sidebar expansion) stored locally on your device. This data never leaves your browser.
We do not use advertising cookies, tracking pixels, or analytics cookies from third-party advertising networks.
6. Data Sharing & Disclosure
We share your personal information only in the following limited circumstances:
- With Your Workspace Collaborators: When you join a workspace or accept a board invitation, your name, email, and avatar are visible to other members of that workspace or board for collaboration purposes.
- Infrastructure Providers: As described in Section 4, our hosting and database providers process your data to operate the Service.
- Legal Requirements: We may disclose your data if required by law, regulation, legal process, or governmental request.
We never sell your personal data to advertisers, data brokers, or any other third parties.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated data.
- Data Portability: Request an export of your data in a machine-readable format.
- Objection: Object to certain types of data processing.
To exercise any of these rights, contact us at support@winit.space. We will respond within 30 days.
8. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, we will remove your personal data from our active databases within 30 days. Certain data may be retained in encrypted backups for up to 90 days after deletion, after which it is permanently purged.
Anonymized, aggregate data (e.g., total number of tasks created) that cannot identify you may be retained indefinitely for analytical purposes.
9. Children's Privacy
WinIt is not intended for use by children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will promptly delete that data.
10. Security
We implement industry-standard security measures to protect your data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Row Level Security (RLS) in our database ensuring users can only access their own data.
- Secure, HTTP-only authentication cookies.
- CAPTCHA verification to prevent automated abuse.
- Regular security reviews and dependency updates.
While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page and updating the “Last Updated” date. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: support@winit.space
- Platform: WinIt.space
- Operated by: OVRS