Privacy Policy.
This is a starter template. Replace this placeholder with your jurisdiction-specific privacy policy before accepting user data.
WHAT WE COLLECT
Identity email and password hash. Per-workspace display name and avatar. Audit-log rows for sign-in, role changes, and key rotations. No tracking pixels, no analytics SDK.
WHO SEES IT
Your workspace owners can see all data inside their workspace. rojas.cr operators can see tenant-level metadata (slug, plan, status). No cross-workspace data sharing.
WHERE IT LIVES
Cloudflare D1 (SQLite) + R2 (blobs). Sensitive fields are encrypted with a per-tenant derived key. Keys are versioned and rotatable by operators.
YOUR RIGHTS
When the privacy-rights module is enabled, you can export or anonymize your data from /account at any time. Otherwise, contact your workspace owner.
Questions? Want to exercise your rights? For questions, contact hola@rojas.cr.