Kardbrd

Last Updated: January 2026

Privacy Policy

Kardbrd ("we," "us," or "our") operates the Kardbrd platform at kardbrd.com and app.kardbrd.com. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

1. Information We Collect

1.1 Information You Provide

  • Account Information: Email address, name, and authentication credentials when you create an account
  • User Content: Cards, boards, comments, checklists, attachments, and other content you create on the platform
  • Communications: Messages you send to us for support or feedback

1.2 Information Collected Automatically

  • Usage Data: How you interact with the platform, including pages visited, features used, and timestamps
  • Device Information: Browser type, operating system, device identifiers, and IP address
  • Cookies and Similar Technologies: Session data and preferences (see our Cookie Policy)

1.3 Information from Third-Party Integrations

When you connect AI tools or other third-party services via MCP (Model Context Protocol):

  • Integration Metadata: Which services you connect and when
  • Access Logs: Records of when third-party services access your boards and cards

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Kardbrd platform
  • Process your requests and respond to inquiries
  • Enable collaboration features between users and AI tools
  • Send service-related communications (account notices, security alerts)
  • Analyze usage patterns to improve our service
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations

3. AI Tool Data Processing

3.1 How AI Tools Access Your Data

Kardbrd is designed for AI-assisted workflows. When you connect an AI tool (such as Claude, GPT, Gemini, or others) via MCP:

  • Board Access: AI tools can read and write to boards you grant them access to
  • Card Operations: Tools can create, update, and comment on cards
  • Context Persistence: Your board content becomes available context for AI tools you authorize

3.2 Third-Party AI Services

We do not control third-party AI services. When you use these integrations:

3.3 Data Minimization

AI tools only access the specific boards and cards you authorize. We do not share your entire account data with AI services.

4. How We Share Your Information

We may share your information in the following circumstances:

4.1 With Your Consent

When you explicitly authorize sharing with collaborators or third-party services.

4.2 Service Providers

  • Cloud hosting and infrastructure providers
  • Analytics services (anonymized/aggregated data only)
  • Customer support tools

4.3 Legal Requirements

  • To comply with applicable laws, regulations, or legal processes
  • To protect our rights, privacy, safety, or property
  • To respond to lawful requests from public authorities

4.4 Business Transfers

In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

5. Your Rights and Choices

5.1 Access and Portability

  • You can access your data through the platform at any time
  • You can export your boards and cards

5.2 Correction

You can update or correct your information through your account settings.

5.3 Deletion

  • You can delete individual cards, boards, and attachments
  • You can request deletion of your entire account by contacting us
  • See our Data Retention Policy for details on deletion timelines

5.4 Opt-Out

  • You can disconnect third-party integrations at any time
  • You can opt out of non-essential communications

5.5 Additional Rights for EU/UK Users

EU and UK users have additional rights including:

  • Right to object to processing
  • Right to restrict processing
  • Right to lodge a complaint with a supervisory authority

6. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS)
  • Encryption at rest for sensitive data
  • Access controls and authentication
  • Regular security assessments
  • Incident response procedures

7. Data Retention

We retain your data as long as your account is active or as needed to provide services. After account deletion:

  • Active content is removed within 30 days
  • Backups are purged within 90 days
  • Some data may be retained longer for legal compliance

8. International Data Transfers

Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place for international transfers, including:

  • Standard Contractual Clauses (SCCs) where required
  • Compliance with applicable data protection frameworks

9. Children's Privacy

Kardbrd is not intended for users under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending an email notification for significant changes
  • Updating the "Last Updated" date

11. Contact Us

For questions about this Privacy Policy or to exercise your rights:

For EU/UK users, you may also contact our Data Protection Officer at [email protected].