Privacy Policy
Last updated: June 6, 2026
1. Introduction
Squircle ("we", "our", or "us") operates the Squircle platform — a workspace and project management tool for teams. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services at squircle.live and related subdomains.
By creating an account or continuing to use Squircle, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of the platform.
2. Information We Collect
2.1 Information You Provide
- Account information: your name, email address, profile photo, and any other details you add to your profile.
- Workspace content: projects, tasks, documents, comments, files, and any data you or your team members create inside Squircle.
- Billing information: payment method details processed securely through our payment provider (Stripe). We do not store full card numbers.
- Communications: messages you send to our support team or through in-app feedback tools.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, actions taken, and timestamps.
- Device & browser data: IP address, browser type, operating system, and referring URLs.
- Cookies and similar technologies: session tokens, authentication cookies, and preference cookies. See Section 6 for details.
2.3 Information from Third Parties
If you sign in using Google or GitHub OAuth, we receive your name, email address, and profile picture from that provider. We do not receive or store your OAuth provider passwords.
3. How We Use Your Information
- Provide, operate, and maintain the Squircle platform.
- Authenticate your identity and keep your account secure.
- Process payments and manage your subscription.
- Send transactional emails (e.g., OTP codes, login alerts, invoices).
- Respond to your support requests and improve our help resources.
- Analyse aggregated, anonymised usage patterns to improve features and performance — we do not sell individual usage profiles.
- Comply with legal obligations and enforce our Terms of Service.
4. How We Share Your Information
We do not sell your personal data. We share information only in these circumstances:
- With your workspace members: your name, profile photo, and activity within a shared workspace are visible to other members of that workspace.
- Service providers: trusted vendors who process data on our behalf (e.g., Stripe for payments, Cloudinary for file hosting, MongoDB Atlas for database hosting, Resend for transactional email). Each is bound by data processing agreements.
- Legal requirements: if required by law, court order, or governmental authority, or to protect the rights, property, or safety of Squircle, our users, or the public.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may transfer to the successor entity, subject to the same privacy protections.
5. Data Retention
We retain your account data for as long as your account is active or as needed to provide you services. If you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, tax, or fraud-prevention purposes.
Workspace content (projects, tasks, documents) is retained until the workspace owner deletes it or the workspace is closed.
6. Cookies
We use the following types of cookies:
- Strictly necessary cookies: authentication tokens (
access_token,refresh_token) and a CSRF protection token (csrf_token) required for the platform to function securely. These cannot be disabled. - Preference cookies: theme preference (light/dark mode) stored in your browser's local storage.
We do not use tracking, advertising, or analytics cookies that profile you across other websites.
7. Security
We take security seriously. Measures include TLS encryption in transit, encrypted secrets storage (AES-256-GCM), CSRF protection on all state-changing requests, rate limiting, and access controls scoped to workspace roles. However, no system is completely impenetrable — please use a strong, unique password or OAuth sign-in and report any suspected breach to security@squircle.live.
8. Your Rights
Depending on your location, you may have rights including:
- Access to the personal data we hold about you.
- Correction of inaccurate or incomplete data.
- Deletion of your account and associated personal data.
- Data portability — receiving your data in a machine-readable format.
- Objection to or restriction of certain processing activities.
To exercise any of these rights, email us at privacy@squircle.live. We will respond within 30 days.
9. Children
Squircle is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via an in-app notice or email at least 14 days before they take effect. Continued use of Squircle after the effective date constitutes acceptance of the updated policy.
11. Contact
Questions or concerns about this policy? Reach us at privacy@squircle.live or write to: Squircle, c/o Privacy Team.