Privacy

Your work stays yours.

Phased stores what it needs to run your workspace, lets you take all of it with you, and keeps analytics away from the content of your client projects. The short version is below; the full notice follows it.

EU-hosted by design

The application runs on Cloudflare and the database is hosted with Turso in the European Union. One workspace owner, ownership checks on every query, no ads and no advertising pixels.

Export and delete, anytime

Settings → Your data gives you a full JSON copy of your workspace. Settings → Account deletes your account and its work data immediately. A pseudonymous trial-abuse marker, short-lived backups, and error diagnostics expire on the schedules below.

Analytics without your client work

Analytics measures a small activation funnel. It never collects client names, project names, descriptions, amounts, report contents, or session replay.

The full notice

Last updated 22 August 2026

What we store

  • Account: your name, email address, and a hashed password (never the password itself).
  • Your work data: what you enter to use the app: projects, phases, tasks, time entries, billing settings, clients, and the reports you generate (including your studio name and logo if you upload one).
  • On your device: a cookie keeps you signed in, and the app saves a few harmless interface preferences in your browser (theme, sidebar and calendar view, your quick-duration presets). None of it identifies or tracks you. Analytics runs cookieless and writes nothing to your browser, which is why there is no cookie banner here.
  • Security: to slow down password guessing and bulk sign-ups, sign-in and sign-up attempts are counted per IP address; these counters are deleted within 24 hours. Each session also records the IP address and browser it was created from; that record is deleted when you sign out and with account deletion, and expired sessions are swept automatically, at least weekly and usually within hours. The sign-up form is protected by Cloudflare Turnstile, which checks that a real browser is filling it in; Cloudflare receives your IP address and browser signals for that check and we receive only a pass/fail token. Turnstile is designed to work without tracking cookies.
  • Subscription: if you subscribe to Pro, we store the identifiers our payment provider gives us (the Creem customer and subscription id, the plan, its status, and the current period end) so the app knows what your account is entitled to. Your card details never reach us; they stay with the payment provider.
  • Terms acceptance: we record the first time you accepted each version of the terms: the version, whether you accepted it at sign-up or when starting a Pro checkout, and when. A checkout acceptance also records that you asked for the service to be supplied right away during the 14-day withdrawal period. It is the evidence of the agreement, and of that request, if either is ever questioned.
  • Trial-abuse prevention: after you verify your email, we store a keyed, one-way HMAC of your address and the date your original trial began. Before it is hashed, variants of the same address are folded into one form: spacing and capitalisation, a "+tag" added to the part before the @, and on Gmail addresses the dots and the googlemail.com spelling. One marker therefore stands for every variant that reaches the same mailbox, which is what stops a second free trial being claimed by adding a tag. The marker contains no plaintext email address or user id. It lets a re-created account resume the same trial instead of receiving another one.
  • Website and product analytics: cookieless page views and allow-listed actions on the public website, such as clicking a call to action or requesting access. Inside the app itself, from sign-up onward, analytics counts only a short, fixed list of feature actions (for example "created a project" or "created a report") together with the app section they happened in. It never records page-by-page browsing in the app, and never the content of your work. Umami does not receive a user or workspace id, and never sees your account. It sets no cookie and stores no IP address: to tell repeat visits apart it derives a one-way hash from your IP address and browser, which cannot be reversed and is scoped to this site, so it cannot follow you anywhere else. Alongside the page or section it records the coarse technical details that come with any web request: browser, operating system, device type, screen size, language, and an approximate country and city. We do not send names, email addresses, client/project/task names, descriptions, amounts, report contents, advertising identifiers, or session replay.
  • Error diagnostics: unexpected app errors may send a sanitized error message, stack trace, page path, internal user id, and error correlation id. No session replay, request body, cookies, email address, or report contents are attached; page URLs are reduced to their path.
  • Access requests: while self-serve sign-up is closed, the name and email address you enter on the access form are sent to our support mailbox by email so we can reply with an invite. They are not written to the product database.
  • Feedback you send us: when you use "Send feedback" in the app, the message you write is saved with the category you picked, the email address on your account, and when you sent it, so a mail that never arrives cannot lose it. A copy goes to our support mailbox as the notification, together with your account id, so we can reply and reproduce what you hit. The saved message is deleted with your account; the emailed copy stays in that mailbox until we clear it, and we remove it earlier if you ask.
  • Service emails: we email you to verify your address, to reset a password if you ask, and once to welcome you after your address is verified. A weekly digest of your own tracked week (your hours, projects, and what that time was worth) is on by default; every digest can be unsubscribed straight from the email, and Settings has the same control ("Weekly summary"). These go through our email provider and carry your name and email address. There is no marketing mail and no newsletter: everything we send is about your account or built from your own data.

Why, and on what basis

Solely to run Phased for you: showing your timesheet, computing your profitability, and rendering your reports. Your data is never sold, shared for marketing, or used to train anything. In GDPR terms: your account and work data are processed to provide the service you signed up for, and your subscription data, together with the record of the terms you accepted, to take and administer your payment (performance of a contract); billing and tax records are kept because accounting law requires it (legal obligation); security counters, bot protection, error diagnostics, and the minimal product analytics rest on our legitimate interest in keeping the service safe and working and preventing trial abuse, collected as narrowly as we know how.

Who processes it

  • Cloudflare hosts the application, renders PDF exports, and provides the Turnstile check on the sign-up form.
  • Creem is our merchant of record: it takes the payment, handles VAT, issues your billing document, and runs the billing portal. It receives the email address and billing details you enter at checkout and is the seller named on your card statement. Creem is a separate controller for that sale, not merely our processor.
  • Turso hosts the database (EU region).
  • Resend delivers our email (password resets, email address confirmations, the welcome note, the weekly digest, and the notification we receive when you request access) when enabled.
  • Sentry receives sanitized technical error reports when error monitoring is enabled.
  • Umami receives the limited cookieless traffic and product-analytics events above.
  • GitHub stores a daily off-platform backup of the production database as a private artifact that expires after 30 days. The backup job encrypts each copy before upload, with a key held only by us, so GitHub stores ciphertext it cannot read. It exists so your data survives even the loss of our hosting accounts.

This list changes only together with the "last updated" date above. If you want to be told when it changes (for example because you hold a DPA with us), email support@phased.studio and we will notify you before a new processor handles your data.

How long we keep it

  • Account and work data: for as long as your account exists; deleted immediately when you delete the account (see below).
  • Billing and tax records: the record of a payment (never your card details, which we do not hold) is kept by the merchant of record for as long as accounting and tax law requires, currently ten years. This is the one category account deletion cannot erase, because we are not allowed to.
  • Terms acceptance: while your account exists; deleted with the account. The merchant of record keeps its own record of the purchase and the consent given at its checkout.
  • Trial-abuse marker: while the verified account exists, then for up to two years after account deletion. Re-registering during that period resumes the original trial clock; an expired marker is purged and no longer affects a later registration.
  • Security counters: IP-based rate-limit counters are deleted within 24 hours. Expired sign-in sessions and expired verification tokens are swept automatically, at least weekly and usually within hours.
  • Backups: the daily off-platform database backup expires after 30 days; the database host's own short-lived recovery copies expire automatically. A deleted account can therefore linger inside the off-platform backup for up to 30 days before the copy holding it expires; backups are only ever restored wholesale, after a disaster.
  • Billing event log: the signed subscription events our payment provider sends us (its identifiers and statuses, never card details) are kept as the audit trail that reconciles your plan with the merchant of record. Deleting your account removes the link between those events and you; the provider-side identifiers remain (legal obligation and our legitimate interest in provable billing).
  • Error diagnostics: sanitized error reports expire in Sentry after at most 90 days.
  • Website and product analytics: aggregate public-site traffic and the allow-listed feature actions are retained in Umami only while they remain useful for understanding and improving the service, then deleted.
  • Access requests: the request email stays in our support mailbox while invites are running, and is deleted earlier if you ask us to.
  • Feedback you send us: the saved message stays while your account exists and is deleted with it. The copy in our support mailbox stays there until we clear it, and is deleted earlier if you ask us to.

Your data, your control

  • Export: Settings → Your data gives you a full JSON copy of your workspace data, any time. The pseudonymous security marker is deliberately not part of workspace backup/import.
  • Deletion: Settings → Account permanently deletes your account, workspace, subscription link, sessions, and pending sign-in or password-reset tokens right away. The pseudonymous trial-abuse marker described above remains for up to two years; the statutory billing record above stays with the merchant of record; residual copies inside backups expire on the schedule above. A running Pro subscription is cancelled with the merchant of record first, immediately rather than at the end of the period, so deletion also ends the remainder of any period you have already paid for. Prefer a human? Email support@phased.studio and we do it for you.
  • Your GDPR rights: you can ask for access, correction, deletion, portability, restriction, or object to processing by emailing support@phased.studio. You also have the right to complain to a data protection authority: your local one, or the one supervising us, the Slovak Office for Personal Data Protection (Úrad na ochranu osobných údajov Slovenskej republiky, dataprotection.gov.sk).

Where it is processed

Your account and work data live and are served from the European Union: the database is hosted in an EU region and the application runs on Cloudflare's network. Some providers above are established outside the EU or operate global infrastructure, so limited data (error diagnostics, product analytics, the Turnstile check, the payment itself, and the daily off-platform backup held privately at GitHub) may be processed elsewhere. Those transfers rely on the European Commission's standard contractual clauses in each provider's data processing terms.

Working with us as a business

For the personal data you store about your own clients, you are the controller and we are your processor: we handle it only to run the service for you, on your instructions, with the providers listed above as sub-processors. If your clients require that in a signed agreement, we will sign a data processing agreement covering the workspace data you store here. Email support@phased.studio and ask for one.

Terms

This notice forms part of the terms of service. Keep your own backup of anything money-critical alongside it. Settings → Your data exports the lot.

Contact

Ing. arch. Marko Rimár, Haanova 2601/46, 851 04 Bratislava-Petržalka, Slovakia · support@phased.studio · contact page