Skip to content

Politique de confidentialité

Dernière mise à jour le 21 septembre 2026

What Taktoria stores, why, and who else sees it. The specifics below describe what the software actually does rather than what a privacy policy usually says.

1. Who is responsible for what

For the data inside a workspace, meaning launches, objectives, questions, links and everything else members put there, the workspace's organisation is the controller and we are the processor. The Data Processing Agreement covers that relationship.

For account records, billing and the logs we keep to run the service, we are the controller. That is what this policy is about.

Controller: Taktoria LLC, a Delaware limited liability company. Privacy contact: legal@taktoria.com.

2. What we store about people

  • Account: name, email address, and a profile picture if one is uploaded. Passwords are stored only as a hash.
  • Two-factor authentication, if enabled: a shared secret and backup codes, so codes can be verified.
  • Sessions: an identifier, the IP address and the browser's user-agent string, so a session can be recognised and listed for you to revoke.
  • Single sign-on, if a workspace uses it: the identifiers the identity provider gives us.
  • Billing: a Stripe customer and subscription identifier, seat counts, and invoice records. Card numbers are never sent to us.
  • Sent email: the recipient, subject and rendered body of each message, kept so delivery can be traced and a retried message is not sent twice.
  • Activity: a log of significant workspace actions, with the person who took them.

3. What we deliberately do not store

  • Card numbers, which stay with Stripe.
  • Who followed a go link. Click counts are totals per link per day, with nobody attached to them.
  • Anything about people who never sign in, beyond what an app is explicitly given. See event participants below.

4. Event participants

Dory events can be joined without an account. A participant is identified by a random token in a cookie that lasts thirty days, plus a display name if they choose to give one. A question can be asked anonymously, in which case no name is shown with it. The participant record behind it still exists, because upvotes have to be counted once each.

A host can see the questions, the counts and any display names given. Deleting the event deletes all of it.

5. Uploads

Profile pictures and workspace icons are stored in Cloudflare R2 and served from a public bucket address. Anybody with the URL can fetch the file. The URL contains a random key and changes whenever the picture changes, but it is not a secret. Do not upload anything to those fields that should not be publicly readable.

6. Cookies

These are all necessary for the features they belong to. We do not use advertising or cross-site tracking cookies.

  • A session cookie, so you stay signed in.
  • A workspace cookie, remembering which workspace you last opened.
  • A participant cookie for Dory events, lasting thirty days.
  • A locale cookie, remembering the language you picked.

7. Who else processes it

We use the providers listed in the Data Processing Agreement's annex, each for a specific job: hosting, email delivery, file storage, payments, background job delivery and page analytics. Slack receives data only from a workspace that has connected it, and only the notifications it has asked us to post.

The analytics are Vercel Web Analytics, and they count page views: the page address, where the request came from, and the country, browser and device type. They set no cookie and keep no identifier that would follow somebody between visits or to another site. The address of a page inside a workspace contains that workspace's name, so the counts can show a workspace is being used and which of its pages are busy, but nothing in them says who opened one. Go links are not counted this way at all: a go link is a redirect and never renders a page.

Vercel Speed Insights sits alongside them and measures how quickly pages load and respond, from the timings the browser already records for itself. It reports the route rather than the address, meaning /app/[workspace]/launchcal rather than the workspace's name, so the performance figures carry no workspace in them at all. It sets no cookie either.

8. Where it is processed

Data is processed in the United States. Where a provider processes data outside that area, the transfer relies on the Standard Contractual Clauses or another mechanism recognised under applicable law.

9. How long it is kept

Workspace data is kept until the workspace deletes it or closes. Deleting a workspace removes its data from live systems immediately, and from backups within 30 days.

Account records are kept while the account exists. Billing records are kept for 7 years because tax law requires it.

10. Your rights

You can ask for a copy of your personal data, ask us to correct or delete it, or object to our processing of it. Much of it you can change yourself in account settings; for the rest, write to legal@taktoria.com and we will answer within 30 days.

If a workspace holds data about you and you are not its account holder, the workspace's organisation is the controller and the request belongs with them. We will pass it on.

11. Changes

If this policy changes materially we will tell workspace admins by email before the change takes effect. The date at the top of this page is when the text last changed.