Project01 - Data Collection & Processing Disclosure
- Last updated:
- August 31, 2026
- Contact:
- support@project01.io
This document is a more detailed, technical companion to our Privacy Policy. It sets out exactly what categories of data exist on the platform, where they are processed, and how we approach security and compliance. If anything here conflicts with the Privacy Policy, the Privacy Policy governs your rights; this document is provided for transparency.
1.Categories of data on the platform
- Identity & account data: name, email address, encrypted password or Google sign-in identifier, profile picture (if using Google sign-in).
- Security & session data: sign-in timestamps, session identifiers, and (via our infrastructure provider) IP address and browser/device information, used to detect suspicious activity such as credential stuffing.
- Audit trail: a security log of account events (sign-in, sign-out, password changes, account deletion, etc.), used for fraud and abuse prevention.
- Startup / business content: your startup's profile, description, business model, team, target audience, competitive landscape, funding and revenue status, and traction - treated as confidential business information.
- User-generated workspace content: chat conversations, canvases, generated documents, templates, and product-planning items (features, flow diagrams) created inside the platform.
- Customer & market research content: research boards, interview records, transcripts and quotes (which may include personal data about people who are not Project01 users - see Section 3), and competitor profiles.
- Uploaded files: any file you upload to a research or idea-workspace attachment, currently without a file-type restriction.
- AI-derived data: summaries, extracted "signals," and vector embeddings generated by our AI features from the content above, used to power search, clustering and insight features.
- Analytics data: page views, referring page, browser/OS, device type and country, collected without cookies and without storing IP addresses.
- Local device data: unsaved form drafts and interface preferences, stored only in your browser and never transmitted to us.
2.Where data is processed, and by whom
Supabase, Inc.
- Role / What it receives
- Database, authentication, file storage, edge functions. Receives essentially all data on the platform (processor).
- Location
- Hosted on AWS, Ireland (eu-west-1)
- Transfer safeguard
- Standard Contractual Clauses (SCCs) + UK Addendum
- Retention
- No fixed expiry - retained until deleted by us or you
Vercel, Inc.
- Role / What it receives
- Application hosting and request processing. Every request (including AI prompts and database reads) passes through it (processor).
- Location
- United States (exact region being confirmed)
- Transfer safeguard
- EU-US Data Privacy Framework (DPF) certified, plus SCCs and UK IDTA
- Retention
- Request logs: 30 days
Anthropic, PBC
- Role / What it receives
- Powers our AI features (chat, summarization, research analysis). Receives prompts, startup and research content, and text extracted from uploaded files (processor).
- Location
- United States
- Transfer safeguard
- SCCs (DPF participation being verified - see note below)
- Retention
- Conversation content is not retained by default; content flagged for trust & safety review may be kept up to 2 years
Resend
- Role / What it receives
- Sends account, authentication and (in future) newsletter emails. Receives recipient address and message content (processor).
- Location
- Sending infrastructure in the EU (eu-west-1); account/log data in the US
- Transfer safeguard
- EU-US DPF certified + SCCs
- Retention
- Email and log data: 30 days. Account data deleted within 90 days of contract termination
Cloudflare, Inc.
- Role / What it receives
- Domain name resolution, inbound email routing for our support address, and encrypted nightly database backups (processor).
- Location
- Backups stored with an EU location hint (residency guarantee being finalized)
- Transfer safeguard
- SCCs + DPF certification for US transfers
- Retention
- Backups: 30 days
GitHub (Microsoft)
- Role / What it receives
- Runs the automated job that produces our nightly encrypted database backup (processor).
- Location
- United States
- Transfer safeguard
- Standard GitHub / Microsoft data processing terms
- Retention
- No data retained beyond the backup process itself; the resulting backup is stored per the Cloudflare row above
Umami Software
- Role / What it receives
- Privacy-focused website analytics: page views, referring page, browser/OS, device type, and country. No cookies are set and no IP address is stored (processor).
- Location
- Region being confirmed (US or Germany)
- Transfer safeguard
- Depends on confirmed hosting region
- Retention
- Plan-dependent
Google LLC / Google Ireland Ltd
- Role / What it receives
- Provides the "Sign in with Google" option. We receive your name, email address and profile picture from Google.
- Location
- Google's own infrastructure
- Transfer safeguard
- Google acts as an independent controller for the sign-in event, not as our processor
- Retention
- Governed by Google's own privacy policy
Personal email accounts of two founding team members
- Role / What it receives
- Currently receives messages sent to our support/contact address, via Cloudflare Email Routing.
- Location
- Google infrastructure (personal, non-business Gmail accounts)
- Transfer safeguard
- None currently in place - see note below
- Retention
- Indefinite, until manually deleted
3.Personal data about people who are not Project01 users
Our research tools are designed to help you organize customer interviews and competitive research - by nature, this means the platform can hold personal data about people (interviewees, contacts) who never signed up and never saw a Project01 privacy notice. As explained in our Terms & Conditions and Privacy Policy: if you enter this kind of data, you are responsible for it as the controller, and we process it as your processor, on your instructions. We do not independently reach out to these individuals or use their data for any purpose beyond providing you the Service.
4.How long we retain data
Content you create in the platform (chats, boards, documents, research, uploads, etc.)
- Current retention
- Retained indefinitely while your account and workspace exist. We do not currently run an automatic deletion schedule for this content.
Account information after you delete your account
- Current retention
- Directly identifying fields (name, email) are removed or anonymized; underlying content you contributed to a shared workspace remains, attributed to a "deleted user," for the reasons explained in Section 9 of our Privacy Policy
Nightly database backups
- Current retention
- 30 days
Email delivery logs (Resend)
- Current retention
- 30 days (account-level data up to 90 days after we stop using the provider)
Application/server logs (Vercel)
- Current retention
- 30 days
AI processing (Anthropic)
- Current retention
- Not retained by default; content flagged for safety review may be retained up to 2 years
Website analytics (Umami)
- Current retention
- Plan-dependent; no cookies or IP addresses are stored in any case
Browser local storage (unsaved drafts, UI preferences)
- Current retention
- Stored only on your own device until you clear it or it is overwritten
We do not currently operate an automatic data-minimization or deletion schedule for content inside the platform. This is an intentional, honest disclosure rather than a promise of automatic deletion: content persists until you or we remove it.
5.Security measures
- Row-level security enforced on every database table, so a user can only access data belonging to their own workspace(s).
- File storage buckets are private (not publicly accessible).
- Encryption in transit (TLS) and at rest across all of our infrastructure providers.
- Database backups are encrypted before leaving our infrastructure.
- Access to sensitive service credentials is restricted to server-side systems and is not exposed to end users or the browser.
On formal certifications: Project01 does not currently hold an independent security certification such as SOC 2, ISO 27001, or similar. This is common for a pre-launch product and something we may pursue as the platform matures. Several of the infrastructure providers we rely on (for example, our hosting and database providers) maintain their own independent compliance certifications and audit reports, details of which are available in their own public documentation.
6.Data breach response
If we become aware of a security incident affecting personal data, we will: (1) investigate and contain the incident; (2) assess whether it constitutes a reportable personal data breach under applicable law; (3) where required, notify the competent supervisory authority (AZOP in Croatia) without undue delay, and where feasible within 72 hours of becoming aware; and (4) notify affected users directly where the breach is likely to result in a high risk to their rights and freedoms.
7.U.S. state privacy law disclosures (including CCPA/CPRA)
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and similar U.S. state privacy laws. California and other applicable U.S. state residents may exercise rights to know, delete, and correct their personal information, and will not be discriminated against for doing so, by contacting support@project01.io.
9.Questions
For any question about how data is collected or processed on Project01, contact support@project01.io.