Project01 - Privacy Policy
- Last updated:
- August 31, 2026
- Contact for privacy requests:
- support@project01.io
This Privacy Policy explains what personal data Project01 collects, why, who we share it with, and what rights you have. It should be read together with our Data Collection & Processing Disclosure, which sets out more technical detail, and our Terms & Conditions.
1.Who we are
Project01 is operated by an informal team of four founders based in Croatia. We are not yet a registered legal entity. For data protection purposes, we currently act as the data controller for the personal data described in this Policy, through that team. We have not appointed a formal Data Protection Officer, as we do not currently carry out large-scale systematic monitoring or large-scale processing of special-category data that would require one under Article 37 GDPR.
2.Who this Policy applies to
We collect data about four different groups of people, and this Policy addresses each:
- Registered users - people who create a Project01 account.
- Invited people who haven't signed up yet - if a user invites someone to a workspace, we hold that person's email address until the invite is accepted or revoked.
- People named in research you conduct - if you use Project01's research tools to record customer interviews, competitor information, or similar, the names and details of those third parties may be stored on the platform. See Section 4 below - this is important if you are a founder using these tools, and important if you are one of these third parties.
- Site visitors - anyone who loads the Project01 website, even without an account, generates limited, non-cookie analytics data.
3.What we collect, and why
3.1Account and identity data
When you sign up, we collect your name, email address, and (if you use email/password sign-in) an encrypted password. If you sign in with Google, we receive your name, email address and profile picture from Google. We also automatically hold session-security data (such as sign-in timestamps, and, through our infrastructure provider, IP address and browser/device information) to keep accounts secure. Legal basis: performance of our contract with you (providing the Service); legitimate interest in account security.
3.2Everything you and your team create in the platform
This is the core of the Service, and we collect essentially all of it: startup profile information, idea-workspace content and canvases, chat messages with our AI features, generated documents and templates, research boards, uploaded files and their filenames, product-planning content, and AI-generated summaries and analysis derived from the above. Legal basis: performance of our contract with you.
3.3Personal data about third parties you enter (research/interview data)
If you use our customer-research tools, you may enter names, roles, organizations, contact details, interview transcripts and quotes about people who are not Project01 users. We collect and store this because you input it - we do not independently collect it. As explained in our Terms & Conditions, you are the controller for this data and we act as your processor. Legal basis (for our processing): performance of our contract with you as the user; the underlying legal basis for the third party's data is yours to establish.
3.4Technical, security and analytics data
Our infrastructure provider (Supabase) automatically logs session IP addresses and user-agent strings for authentication security. Our website analytics tool, Umami, separately records page views, referring pages, browser/OS, device type and country - without using cookies and without storing IP addresses. Because no cookies or persistent identifiers are used for analytics, we do not currently display a cookie-consent banner; the only cookie set by the Service is a strictly necessary authentication cookie required for you to stay signed in. Legal basis: legitimate interest in operating and securing the Service (Art. 6(1)(f)); the authentication cookie is strictly necessary and does not require consent.
3.5Data your browser stores locally
Some interface state - such as unsaved form drafts and your view preferences - is stored only in your browser's local storage, on your own device. We do not receive this data on our servers. If you use a shared or public computer, be aware that unsaved draft text may remain in that browser until cleared.
4.How we use your data
We use the data described above to: operate and provide the Service; power AI features (via our AI provider, described below); maintain the security of accounts and detect misuse; respond to support requests; and, in the future, send product updates or a newsletter if you opt in.
6.International data transfers
Several of our providers are US-based (Anthropic, Vercel, GitHub, and the underlying entity behind Resend and Cloudflare, among others). Personal data may therefore be transferred outside the European Economic Area. Where this happens, we rely on Standard Contractual Clauses and, where applicable, the provider's certification under the EU-US Data Privacy Framework, as summarized in the table above.
7.How long we keep data
We are honest that we do not yet have a formal retention schedule. In practice: content you and your team create is kept for as long as your account and workspace exist, with no automatic deletion. Certain provider-side logs and backups are deleted on a fixed schedule. See the table below for specifics.
Content you create in the platform (chats, boards, documents, research, uploads, etc.)
- Current retention
- Retained indefinitely while your account and workspace exist. We do not currently run an automatic deletion schedule for this content.
Account information after you delete your account
- Current retention
- Directly identifying fields (name, email) are removed or anonymized; underlying content you contributed to a shared workspace remains, attributed to a "deleted user," for the reasons explained in Section 9 of our Privacy Policy
Nightly database backups
- Current retention
- 30 days
Email delivery logs (Resend)
- Current retention
- 30 days (account-level data up to 90 days after we stop using the provider)
Application/server logs (Vercel)
- Current retention
- 30 days
AI processing (Anthropic)
- Current retention
- Not retained by default; content flagged for safety review may be retained up to 2 years
Website analytics (Umami)
- Current retention
- Plan-dependent; no cookies or IP addresses are stored in any case
Browser local storage (unsaved drafts, UI preferences)
- Current retention
- Stored only on your own device until you clear it or it is overwritten
8.Your rights
Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; request a copy of your data in a portable format; object to or restrict certain processing; and lodge a complaint with your local data protection authority (in Croatia, this is AZOP - Agencija za zaštitu osobnih podataka, Zagreb).
To exercise these rights, email support@project01.io. We will respond within the timeframes required by applicable law.
9.Deleting your account - what actually happens
We want to be specific and honest here, because "delete my account" can mean different things:
- If you are the only member of a workspace and you delete your account, that workspace and its data are deleted along with it.
- If you delete a workspace but keep your account, that startup's data is deleted, but your account itself continues to exist.
- In a shared workspace, only the workspace owner can delete the workspace itself.
- If you delete your account while remaining part of a shared workspace, your directly identifying account information (name, email) is removed or anonymized, but content you contributed to that shared workspace remains, now attributed to a "deleted user," so that your teammates' work is not disrupted.
- You have a 30-day window after requesting deletion to recover your account before the change becomes final.
- Certain AI-derived records (for example, excerpts used to generate research insights) are stored in an append-only format for integrity reasons and may not be fully removable through the standard deletion process today. If this affects you specifically, contact us and we will do what we can on a manual basis.
10.Children and minors
Project01 does not currently operate age verification or a minimum-age gate, similar to the general posture of other widely used AI platforms. If you are a parent or guardian and believe a minor has provided us with personal data you did not authorize, contact us at support@project01.io and we will address it.
11.Security
We use industry-standard measures appropriate to a pre-launch product, including: row-level security on our database, private (non-public) file storage, encryption in transit (TLS) and at rest with all providers, encrypted database backups, and server-side-only access to sensitive service credentials. We have not yet obtained an independent security certification such as SOC 2; several of our infrastructure providers maintain their own compliance certifications, described in their own documentation.
12.Data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (AZOP) without undue delay, and where feasible within 72 hours of becoming aware of it, and will notify affected users directly where required by law.
13.California residents (CCPA/CPRA)
If you are a California resident, you have the right to: know what personal information we collect and how it's used; request deletion of your personal information; request correction of inaccurate personal information; and opt out of the "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising these rights. To exercise them, email support@project01.io; we may need to verify your identity before acting on the request. An authorized agent may submit a request on your behalf with appropriate written permission.
14.Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date, and, for material changes, will make reasonable efforts to notify active users in advance.
15.Contact us
Questions or requests regarding this Policy can be sent to support@project01.io.