Privacy Policy

Last updated: August 8, 2026

1. Introduction

Cyrus365 ("we," "our," or "us") operates Projects.ink (the "Service"), available as a website at projects.ink and projects.cyrus365.com, and as mobile applications for iOS and Android distributed through the Apple App Store and Google Play. This Privacy Policy explains what data we collect, how we use it, which service providers we use, and what choices you have.

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with this policy, please discontinue use of the Service.

2. Information We Collect

2.1 Personal Information

We collect personal information you provide directly, including:

  • Name and email address
  • Profile information (avatar, display name)
  • Organization and membership details
  • Support and contact messages

2.2 Usage Data

We automatically collect technical and usage data, including:

  • Browser type and version
  • Operating system and device type (including mobile platform and app version when using our iOS/Android apps)
  • Pages visited, time spent, clicks, scroll depth, and feature usage (product analytics)
  • IP address, device identifiers, and approximate location derived from IP
  • Authentication and session metadata (e.g., session IDs, token timestamps)
  • Error and performance diagnostics (stack traces, performance traces, console logs) when something goes wrong

2.3 Project Data

We store and process project data you create in the Service, including projects, tasks, comments, assignees, sprint/group structures, attachments, and collaboration metadata. Project data is visible to authorized members based on project visibility and role settings.

2.4 Analytics, Error Monitoring, and Session Replay

We use PostHog (PostHog, Inc., United States) for product analytics on both the website and the mobile apps. When you are signed in, analytics events are associated with your account (user ID, email, name, role, and plan) so we can understand how the Service is used and improve it. On our public marketing pages only (for example, the landing, features, and pricing pages), PostHog session replay may record your browsing session; all text inputs are masked, and authenticated pages of the Service are never recorded.

We use Sentry (Functional Software, Inc., United States) for error and performance monitoring across the website, server, and mobile apps. Sentry receives diagnostic data such as stack traces, performance traces, and console logs. Sentry is configured to not attach default personally identifiable information (such as cookies, request headers, or IP addresses) to error reports.

2.5 Push Notifications (Mobile Apps)

If you use our iOS or Android app and grant notification permission, we collect a device push token (generated via Expo and delivered through Apple Push Notification service or Google Firebase Cloud Messaging) so we can send you project-related notifications, such as task assignments and deadline reminders. The push token is removed from our systems when you sign out of the app, and you can revoke notification permission at any time in your device settings.

2.6 AI Processing

Certain features use artificial intelligence provided by Google Cloud Vertex AI (Gemini), including AI chat assistants, AI-generated project summaries and dashboards, task title/description refinement, and AI-assisted task import. When you or your organization use these features, relevant project content (such as task titles and descriptions) is sent to Google's AI services to generate a response. These features do not make automated decisions that produce legal or similarly significant effects on you.

3. How We Use Your Information

We use collected data to operate and improve the Service, including to:

  • Provide project collaboration features, access controls, and account management
  • Authenticate users and maintain secure sessions across Cyrus365 services
  • Store and synchronize project updates, including offline/local-first workflows
  • Deliver product notifications, support communications, and transactional email
  • Detect abuse, fraud, and unauthorized access; monitor reliability and performance
  • Comply with legal obligations and enforce our terms, security, and billing rules

4. Data Sharing and Disclosure

We do not sell your personal information. We share data only as needed to run the Service, including with the following categories of recipients:

  • Infrastructure and storage providers: Hosting, database, and cache providers used to operate projects.ink/projects.cyrus365.com.
  • Authentication and identity services: Cyrus365 authentication services, including token/session validation and user verification.
  • Synchronization services: Local-first sync infrastructure for project data replication and upload processing.
  • Product integrations you enable: File storage providers (attachments), mailbox providers (Google/Microsoft), and webhook recipients configured by your organization.
  • Analytics and error-monitoring providers: PostHog, Inc. (product analytics) and Functional Software, Inc. d/b/a Sentry (error and performance monitoring), both located in the United States.
  • AI processing providers: Google Cloud Vertex AI (Gemini), used to power AI chat, summaries, and content refinement features.
  • Push notification delivery: Expo (Expo, Inc.), Apple Push Notification service, and Google Firebase Cloud Messaging, used to deliver notifications to our mobile apps.
  • App distribution platforms: The Apple App Store and Google Play, which distribute our mobile apps and are governed by their own terms and policies.
  • Authorized workspace members: Data shared according to project membership, visibility, and role permissions.
  • Legal and business events: Lawful requests, dispute resolution, or corporate transactions (e.g., merger or acquisition).

5. Data Security

We use technical and organizational safeguards to protect data against unauthorized access, disclosure, alteration, and destruction. Controls include:

  • Encryption in transit and managed encryption at rest where supported
  • Signed authentication tokens, session controls, and permission checks
  • Role-based access controls and project visibility constraints
  • Operational logging, monitoring, and incident response procedures

No system is completely secure. While we continuously improve our controls, we cannot guarantee absolute security.

6. Data Retention

We retain data for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type.

  • Account and project data: Retained while the account/workspace is active, then deleted or anonymized within a reasonable operational period unless legally required.
  • Session/security logs: Retained for security, audit, and fraud prevention for limited periods based on operational needs.
  • Backups and recovery copies: May persist temporarily until rotated out by backup schedules.

7. Your Rights

Depending on your location and applicable law, you may have rights to:

  • Access: Request confirmation and access to personal data we hold about you
  • Correction: Request correction of incomplete or inaccurate data
  • Deletion: Request deletion of personal data, subject to legal exceptions
  • Portability: Request export of relevant data in a commonly used format
  • Restriction/Objection: Request limits on certain processing activities
  • Consent withdrawal: Withdraw consent where processing relies on consent

To exercise these rights, contact us at contact@cyrus365.com. We may verify your identity and request additional details to process your request.

8. Cookies and Tracking

We use cookies and similar technologies that are necessary to operate authentication, session continuity, security controls, and core product functionality. These strictly-necessary cookies cannot be disabled without breaking sign-in and core features.

We also use analytics storage (a PostHog identifier stored in a cookie or your browser's local storage) to recognize returning visits and measure product usage as described in Section 2.4. Analytics are optional for the Service to function: you can block them via browser settings, privacy extensions, or content blockers, and the Service will continue to work normally.

You can control cookies in your browser settings. Blocking required cookies may prevent login, session refresh, and parts of the Service from working correctly.

9. Third-Party Services

We rely on third-party providers to deliver parts of the Service. Depending on your usage, this may include cloud infrastructure, database/storage services, email delivery, payment, analytics/monitoring, file storage, identity providers, and mailbox providers.

Third-party services are governed by their own terms and privacy notices. Where integrations are configured by your organization (for example, webhooks and external mailbox links), your organization is responsible for its own lawful use and disclosures.

10. Children's Privacy

The Service is intended for business and professional use and is not directed to children. We do not knowingly collect personal information from children under the age required by applicable law. If you believe a child submitted personal information, contact us and we will take appropriate action.

11. International Data Transfers

Because our providers and infrastructure may operate in multiple regions, your information may be processed outside your country. In particular, our analytics provider (PostHog), error-monitoring provider (Sentry), and AI processing provider (Google Cloud Vertex AI) process data in the United States and other regions where they operate. Where required, we use appropriate safeguards and contractual protections for cross-border transfers.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material updates will be reflected by updating the "Last updated" date on this page and, where appropriate, by additional in-product or email notice.

13. Contact Us

For questions, data rights requests, or privacy concerns, please contact us:

  • By email: contact@cyrus365.com
  • By visiting our contact page: Contact Us
  • Primary domain: projects.ink (also available at projects.cyrus365.com)