Privacy Policy
This policy explains what personal information Saarah Project collects about you, why, who else sees it, how long it is kept, and how you can read it back or have it deleted. It is written to the Australian Privacy Principles in the Privacy Act 1988 (Cth).
The short version
- Two kinds of information are held. What your account needs: your name, your email address, and a hash of your password. And what you add while you work: messages, tasks, files and the like, which the people on the project can see.
- Nothing is sold, and nothing is shared for advertising.
- There are no analytics, no tracking pixels and no third-party advertising cookies. None.
- You can download everything held about you, or delete all of it, from Settings. Deletion removes it from the live service immediately; encrypted backups expire under the provider's retention schedule.
What is collected, and why
When you create an account
Your name, email address and password. The password is stored only as a cryptographic hash and cannot be read back by anyone, including us. These exist so you can sign in and so what you add carries your name. If you add a passkey, its public key is stored too.
When you use the service
Saarah Project is a project hub, so most of what it stores is the work your organisation does in it. About you, as a user of the service, it holds:
- Your membership of a workspace: which workspace, your role in it, and whether you may export data.
- The projects you are on, and how you want to be notified about each.
- What you add to a project — messages, tasks, comments and the like — kept on the project and attributed to you, and a log of what you did there, which the people on the project can see.
- Invitations you send, including the address you sent them to.
- Your direct messages, kudos, and project status updates (“Health”), attributed to you.
- Things only you see: your bookmarks, private notes, starred projects, your Do Today and Up Next lists, the calendar feed links you have made (when each was last read by your calendar app), your work hours, what you've asked Saarah Project to email you, and when you last opened each project.
- Time you log on a project's timesheet, which the project's team can see.
- In a project that follows a workflow, the roles you hold in it, and the outcome and note of any stage gate you record. Workflows you make, and the versions of them you publish, are kept in the workspace's library with your name on them.
- When each of those was created and last changed.
What other people add to a project is the workspace's record, not yours. A request under “seeing it” below returns what is about you and what you wrote, not the rest of the project.
Automatically, when you use the site
Your IP address and browser user-agent are recorded against your active sessions, and your IP address is counted against sign-in attempts to stop password guessing. Authenticated high-cost actions use your internal account id instead. Account-id counters are deleted with the account.
Cookies
Three, all first-party and all functional, and a fourth that lasts only while you use a passkey:
- The session cookie keeps you signed in.
primo.workspaceremembers which of your workspaces you were last in, for a year. It is checked against your memberships on every request and grants nothing by itself.sidebar_stateremembers whether you had the sidebar open, for a week.- A passkey cookie is set for a few minutes while you add a passkey or sign in with one.
There are no advertising or analytics cookies, so there is nothing here to opt out of. Your browser also keeps a few preferences on your own device, such as which reminders you have dismissed and whether you asked for desktop notifications.
Who else sees it
Personal information is not sold, rented, or disclosed for marketing. These providers process it in order to run the service:
- Supabase — the database, hosted in Sydney, Australia. Everything you type lives here.
- Amazon Web Services (S3) — file storage, in Sydney, Australia. It holds the files you upload or attach: in a project's files, in chat and direct messages, and attachments on email forwarded into a project. Your browser sends files to it and fetches them from it directly.
- Vercel — hosting. Application servers are pinned to Sydney; the content delivery network that serves images and scripts is global, and sees the requests that pass through it.
- Resend — email, operated from the United States. It receives your email address and the message being sent: account messages (confirming an address, resetting a password, changing your email, an invitation, a notice to administrators that someone joined) and, unless you turn them off in Settings, notifications (a mention, an assignment, a direct message, a due reminder, or a catch-up summary). A notification includes a line about what happened and a short excerpt of it.
Sending email therefore involves an overseas provider. The database and the files stay in Australia.
How long it is kept
- Your account — until you delete it. Your sign-in is shared with the other products that share this login; deleting your Saarah Project account removes the sign-in too unless you still use one of them.
- A project or an item moved to the trash — kept for 30 days so a mistake can be undone, then deleted for good along with its files. The clean-up runs when someone in the workspace opens their projects or the trash, so it can happen a little after the thirtieth day.
- Abuse-prevention counters, which hold an IP address or internal account id — account-linked rows are deleted with the account.
Deleting removes information from the live database immediately. Routine encrypted backups may retain a copy for a limited period afterwards before they expire in the normal course; those backups are not used for anything except restoring the service after a failure.
Seeing it, correcting it, deleting it
- See it. Settings → Download my data returns everything held about you, in every workspace you belong to, as a file — including the projects you are on, what you wrote in them, what you did there, the invitations you sent, your direct messages, kudos, bookmarks and notes. Your current password is required before the download. Anything in a project you have since left is not in it; an owner of that workspace can find it for you. The password hash and session tokens, and the secret part of calendar feed links, are deliberately excluded because they are credentials. IP-based counters shared by a household or network are also excluded because they cannot reliably be assigned to one account.
- Correct it. Your name in Settings, and your email in Settings after approving the change from the old inbox and verifying the new one. If you cannot access the old address: a contact address will be published here before launch.
- Delete it.Settings will delete your account and everything attached to it, including any workspace nobody else belongs to. Notes you wrote and work assigned to you in a shared workspace are that workspace's records and stay with it; your name comes off them once your sign-in is removed. Account deletion asks for your password and for your email address typed out, because it cannot be undone. If you are the only owner of a workspace other people use, it passes to the longest-standing administrator there, or member if there is none; if everyone else there is suspended, you will be asked to restore someone's access and make them an owner, or delete the workspace, first.
You do not have to ask us to do any of this and you will not be charged for it.
Keeping it safe
Traffic is encrypted in transit. Passwords are hashed, never stored in a readable form. The application connects to the database with an account that has only the permissions it needs, and it cannot see the data of any other application sharing the same server. User-owned data is additionally protected by database row-level policies tied to the signed-in account. Every response containing your information is marked so that it is never cached by anything between our servers and your browser. No system is perfectly secure, and this policy does not claim otherwise.
Children
This service is not intended for people under 16. If you believe a child has created an account, it will be removed on request; a contact address will be published here before launch.
Complaints
If you think your privacy has been mishandled, you will be able to write to us: a contact address will be published here before launch. We will acknowledge your complaint and respond within a reasonable time.
If you are not satisfied with the response, you can escalate to the Office of the Australian Information Commissioner, the independent regulator for privacy in Australia.
Changes
If this policy changes in a way that affects how your information is used, the change will be noted here and the date at the foot of the page updated. Continuing to use the service after a change means accepting the updated policy.