My Project Company
ENBack to site

Privacy policy

My Project Company ("MPC") is a collaborative workspace that brings kanban boards, wiki, todolists, messaging, AI agents and files together into a single application, desktop or web. This policy describes the data we process, how we protect it and your rights over it.

Last updated: September 18, 2026

Service publisher

My Project Company operates and publishes the application. For any question, use the contact form built into the app (help menu "?" → "Contact the administrator"): your message reaches us directly, together with the app version, the platform and — if you attach them — your screenshots.

Data we process

  • Account: email, hashed password, display name, avatar, organizations you belong to.
  • Project content: tickets, wiki pages, todos, messages, files, transcripts and comments you create.
  • Third-party connectors: OAuth tokens (Notion, Jira…) you authorize, stored encrypted at rest and used only for your own calls.
  • Technical logs: IP address, user-agent, error and diagnostic reports, app version and platform, status and duration of connector calls (without their content) — kept up to 90 days for diagnostic purposes, then deleted automatically.
  • Device identifier: a random identifier generated by the desktop app, linked to your account to tell your devices apart (scheduled tasks, transcripts, AI configurations). It cannot be used to track you outside MPC.
  • Managed AI usage: date, organization, user, device and credits charged for each request — kept as billing records, without the request content.

What we do not do

  • We do not sell your data and we do not train any AI model on your project content.
  • We do not expose your content to other organizations: each organization stays isolated.
  • We do not access the local workspace (the folder linked to a project on the client side) — it stays on your machine.

Sub-processors

  • Web application and API hosting: Vercel Inc., United States (transfer covered by the EU–US Data Privacy Framework and standard contractual clauses).
  • Database: Neon Inc., data stored on Amazon Web Services in London, United Kingdom (a country covered by a European Commission adequacy decision).
  • Attached file storage: Amazon Web Services (Amazon S3).
  • Hosting: Hetzner Online GmbH, Germany.
  • Account verification emails: Resend (Plus Five Five, Inc.), United States (standard contractual clauses).
  • AI model providers (Anthropic, OpenAI, Google, Mistral AI, Groq, DeepSeek, OpenRouter, Hetzner Inference, 1min.ai, local Ollama…): called only when you or one of your agents sends a message, with the data strictly needed for the request.
  • Providers of the OAuth connectors you authorize (Notion, Atlassian/Jira…): called only to perform the actions you request.

Retention

Your content is kept as long as your account is active. If you delete your account, your content is removed within 30 days; encrypted backups are purged within 90 days.

Your rights

Under the GDPR, you have the right to access, rectify, erase, port and object to the processing of your data. To exercise these rights, send us a request from the contact form built into the app (help menu "?" → "Contact the administrator"): the request reaches us with your account identifier, which lets us process it within 30 days.

You can also exercise two of these rights yourself directly in the app, from the account settings: "Export my data" (General tab) downloads a copy of your data as JSON, and "Delete my account" (Danger tab) permanently deletes your account.

Cookies

The site and the application only use technical cookies strictly required for your session (authentication). Some preferences, such as language, are saved in your browser’s local storage and are never shared with third parties. No advertising cookies, no third-party trackers.

Contact

A question about this policy or about your data? Use the contact form built into the app (help menu "?" → "Contact the administrator"). This is the only official channel: we do not publish a contact inbox — this prevents spam and ensures your message reaches the publisher directly with the useful technical context.