Privacy policy
What we collect, why we have it, who else sees it, and how to get rid of it.
Last updated
Who is responsible
ROOTLESS ENTREPRENEUR LLC, identification number 001435285, of 33 Valleywood Rd, Hopkinton, MA 01748, USA, decides how and why your data is used. In European terms, we are the data controller. Write to support@implements.app about anything on this page.
What we collect
- Your account
- Your email address, a name if you give one, and an encrypted form of your password. We never see the password itself.
- Your subscription
- Whether it is active, which plan, when the period ends, and the identifiers Stripe gives us. We never see or store your card number. That goes straight to Stripe.
- What you put in the tools
- Trips, expenses, polls, to-do lists and anything else you save, including details you enter about other people, such as a name or a way to pay them.
- Support messages
- What you write to us, the address to reply to, and when you sent it.
- Technical data
- Server logs, which hold the pages requested and times. Where we count requests to stop abuse, your IP address is hashed before it is stored, so the stored value cannot be turned back into an address.
There is no analytics, no advertising, no tracking pixels and no third-party scripts that watch you. We do not sell or share your data for anyone's marketing.
Why we have it, and on what basis
- To run the service: your account, your content and your subscription. This is what performing our contract with you requires.
- To take payment and meet tax rules: a legal obligation, and our contract.
- To answer support messages: our legitimate interest in helping you, and our contract.
- To keep the service standing up, through rate limits and logs: our legitimate interest in preventing abuse.
- To email you about the service, such as confirming your address, resetting a password, or a change to these documents: our contract, and our legitimate interest in telling you about changes that matter.
Who else sees it
Only the companies that make the service work. Each one handles data on our instructions under a contract, and none of them may use it for their own purposes.
- Supabase hosts the database and the login system: your account and everything you save.
- Stripe takes payments: your card details go directly to them, along with your email address and the identifiers linking a payment to your account.
- Brevo sends email: your address and the contents of the message.
- Amazon Web Services hosts the server the site runs on.
We may also disclose data where the law requires it, or to establish or defend a legal claim.
Where your data is
We are in the United States, and the service runs on servers there. If you are in the European Economic Area or the United Kingdom, using implements means your data is transferred to the United States. Where that transfer needs a legal safeguard, we and our providers rely on the European Commission's standard contractual clauses or an equivalent mechanism.
How long we keep it
- Your account and content: until you delete your account. Deleting is immediate, and takes your profile, your subscription records in our database, and everything saved in every tool with it.
- Deleted items inside a tool: a deleted to-do is kept for up to 30 days so a device that was offline cannot bring it back, then purged.
- Payment records: Stripe keeps invoices and payment records after you delete your account, because tax and accounting rules require it. This is the one thing deletion does not remove.
- Support messages: kept so we have a record of what was asked, with the link to your account removed when the account is deleted.
- Rate limit counters: hashed and deleted within a day.
Your rights
Wherever you live, we offer everyone the same rights: to know what we hold, to get a copy, to have mistakes corrected, to have your data deleted, and to object to how we use it. If you are in the EEA or the UK, these are your rights under the GDPR.
- Deletion is self-service. Open your account page and use Delete account. It happens at once.
- For a copy of your data, or anything else, write to support@implements.app. We answer within 30 days.
- If you are in the EEA or UK and think we have handled your data badly, you can complain to your local data protection authority.
Cookies and storage on your device
We use no advertising or analytics cookies, so there is no consent banner to click through. What we do store is needed for the service to work at all:
- Session cookies, set when you log in, so the site knows it is you. They cannot be read by scripts in the browser, and they are removed when you log out.
- Local storage, for things that make the app usable: the last answer about whether your subscription is active (so an installed tool opens offline), a count of changes not yet synced, whether you dismissed the install prompt, and which name you chose on a poll on this device.
- A local database and offline cache for tools that work without a connection, such as the To-do List, plus pages the app has cached for offline use.
Logging out clears all of it on that device. Stripe sets its own cookies on Stripe's pages when you pay; that is covered by Stripe's privacy policy.
Security
Traffic is encrypted in transit. Passwords are stored only in hashed form, by Supabase Auth. Access to your rows in the database is enforced by the database itself, not only by the app. Payment details never touch our servers. No system is perfectly safe, and we do not claim otherwise; if a breach ever affects you, we will tell you and the relevant authority as the law requires.
Children
implements is not meant for children under 13, and we do not knowingly collect their data. If you believe a child has given us data, write to us and we will delete it.
Changes
If we change this policy in a way that affects you, we will email subscribers and update the date at the top before it takes effect.