Vondet

Privacy Policy

This explains how Vondet ("the Service") handles personal information.

Effective: August 11, 2026 · Last revised: September 21, 2026

About this document

The Service follows Japan's Act on the Protection of Personal Information, and is priced and offered in US dollars for the markets we serve today. We have not yet expanded to the European Economic Area or the United Kingdom. We do not price or communicate in EEA or UK currencies or languages, and we run no EEA- or UK-directed advertising. When we do expand there, we will first put the corresponding safeguards in place — an EU/UK representative and the applicable data-subject rights — and say so here.

Operator

Name
Hatobash
Postal address
Ask at the contact address given on this page and we will provide it without delay.
Contact
hello@vondet.com

What we collect, and why

The Service does not collect information it cannot justify a purpose for. What we collect is used to provide the Service, to improve it, to prevent abuse, and to understand how people came to hear about the Service so we can decide where to focus how we introduce it. We do not serve advertising, we do not track you for advertising, and we do not follow you across other sites. We do not send usage information to any third-party analytics service.

If you create an account

We collect your email address to sign you in, and an identifier issued by the authentication provider (Supabase Auth) so we can recognize you as the same person. Your name is optional and used only for display. The Service is built without passwords. We record, once, how you first arrived at the Service, alongside your account: any short tags carried by the link (ref and the utm_ parameters), the page you first landed on, and the domain name of the referring site. We use this to understand how people came to hear about the Service so we can decide where to focus how we introduce it, and we do not record your IP address or device details. Only your first arrival is kept — later visits from other channels do not overwrite it — except that if you register more than 30 days after that first visit, the arrival recorded is the one at that later time. It is removed when you delete your account. When you first sign in, we ask for a display name, country/region, and role — all optional and changeable later; the country/region helps us apply the right laws to you.

What you write on the board

Everything written on the board — plans, goals, tasks, their reasoning, decisions. Today only you can read it; there is no way to invite anyone yet. For how content may be used, see "Using content, and turning it off" below.

If you join the waitlist

To tell you when it opens, we collect your email address, the language you were reading, which consent wording you agreed to and when, and a token used for unsubscribing. To stop the same sender from signing up repeatedly, we also record a value derived from the IP address. The IP address itself is not stored, but that value corresponds one-to-one with it. Once an address is unsubscribed, it stays unsubscribed even if submitted again. If you ask us to delete the record itself, the record of the stop goes with it.

When you answer the cancellation survey

If you hold a paid plan, the cancellation dialog asks why you are leaving (answering is optional). Only when you answer it do we record the one reason you pick, the optional note you may write, the plan you were on, how many months you had it, the time you answered and the time the record was created, linked to your account. Where we cannot tell the number of months, we leave it blank. We use this only to work out what to fix, and for nothing else. Your cancellation goes through whether or not you answer. If you delete your account, this record is deleted with it.

When you tell us why you are leaving

While you delete your account we ask why you are leaving. Only if you answer, we record the one reason you pick and the date you answered (the day only). This record is not tied to your account or your email address in any way. No name and no written note is kept — there is no free-text box to write one in. We keep the day rather than the time so the record cannot be matched against anything else to work out whose it was. We use it only to decide what to fix, and for nothing else. Leaving goes ahead whether or not you answer.

Traffic logs

Our hosting provider (Cloudflare) keeps access logs to prevent attacks. The Service does not use these logs for analysis.

About AI

The Service lets an AI you connect (such as Claude) read and write the board. To connect, you place a connection URL you issue yourself into the AI's settings. Once connected, board content is available to that AI, and how it is handled from there is governed by your agreement with that AI's provider. If you have not issued a connection URL, no AI can see the board, and you can revoke a URL at any time. If we later add features where the Service itself sends data to an AI, we will update this policy and the list of processors below first.

Requests to GitHub

If a task on your board carries a GitHub issue or pull request URL, the Service asks GitHub whether it is closed — each time an AI you connected reads the board (at most 12 per read). We send only the owner, repository name, and number taken from that URL — nothing that identifies you. The request is made under the Service's own account, so your IP address is not passed to GitHub. Note that if the URL points to a private repository, its name is part of that request. Separately, if you sign in with GitHub, we treat GitHub not as our processor but as an authentication provider you chose yourself.

Records of how the Service is used

The Service records who did what, and when. Specifically: the time and kind of each write to a board; the name of each tool an AI called, how many bytes its response was, when it was called, and which connection it came from (this one also covers reads — calls that only fetch and change nothing; what is recorded is the size of the response, not the response itself); which field of a task was changed, by whom, and its value before and after (including the text itself, such as a title or the reasoning); when a connection URL was issued, last used, and revoked, along with the name, version, and declared capabilities of the AI application that connected; when you signed in or joined the waitlist; and when you last visited (stored in your browser). In addition, the Service collects its own server logs in full, to investigate errors — these are separate from the logs our hosting provider keeps to prevent attacks.Note that these logs include the request URL, so if an error occurs while an AI is connected, that connection URL can end up in them. If you have reason to think that happened, reissue it from the screen — the old one stops working immediately.

These records serve three purposes: providing the Service (confirming a connection is in use), improving it (learning where people get stuck), and preventing abuse.

The records kept for providing the Service and preventing abuse cannot be turned off; without them the Service does not work. If you would rather your usage were not used for analysis to improve the Service, write to the contact address above and we will leave you out of it from then on.

Using content, and turning it off

On the Free and Pro plans, board content may be anonymized and used to improve suggestions. You can turn this off any time in account settings. On Team plans and above it is off by default. When off, content is no longer used to improve suggestions. Usage signals — which screens are opened, how often a tool is called — are handled separately from content. We never sell content to third parties. If improving suggestions ever requires handing content to an outside processor, we add that processor to the list of processors below first.

Processors and overseas transfer

The Service does not sell or provide personal information to third parties. The following are engaged to run the service, all located outside Japan. You can review each provider's published information about the regime in their country (APPI Article 28).

  • SUPABASE PTE. LTD. (contracting entity: Singapore; data stored in the United States) — database and sign-in
  • Cloudflare, Inc. (United States and elsewhere) — serving the site and running the app
  • Plus Five Five, Inc. (Resend; United States) — sending sign-in and notification email
  • Functional Software, Inc. (d/b/a Sentry; contracting entity: United States; data stored in the United States) — error monitoring: the type of error, the area of the app where it occurred, how many times it happened, and the version of our software. We do not send the contents of your board, your connection token, or your IP address

We expect to add a payment provider (Paddle). When we do, we will update this list before connecting them.

Disclosure, correction, deletion

On your request, we will disclose the information we hold, correct it, and stop using or delete it (APPI Articles 33–35). Contact us at the address above.

You can delete your account yourself from the screen. Deleting it removes your board, goals, tasks, decisions, and connection URLs. Two things are not yet removed by that action: records held in the sign-in system (Supabase Auth), and your waitlist entry if you had joined the waitlist. If you want these removed, tell us at the address above and we will remove them within 30 days of your request. Even after deletion, some data remains for a time in server logs and backups; these are removed once their retention period passes — logs within 90 days, backups within 30 days. The value derived from your IP address, which we keep to prevent repeated sign-ups in a short window, cannot be deleted on request: we hold no way to link it back to you.

Safeguards

  • All traffic is encrypted (HTTPS).
  • A connection URL is stored only as a fingerprint (a transformed value). After it is shown once at issue time, we cannot read it back out of our database. The connection URL is itself the secret, however, so if it may have been seen by someone else, issue a new one from the screen. The old one stops working immediately.
  • Boards are isolated per owner; you cannot read anyone else's board.
  • The Service is currently run by one person, with no other staff.

Cookies and other browser storage

The Service uses cookies to keep you signed in (a session cookie, plus — only during sign-in — one that remembers where to send you back and one that carries the source tag from the link you followed), to remember how you first arrived (for 30 days: only the short tags carried by the link (ref and the utm_ parameters), the path of the page you landed on and the referring site's domain name, never your name or IP address; it is deleted once you have finished signing in, and kept if we had to turn your registration away, so it is still there when you come back), and to remember your display language. It does not use them for tracking or advertising, and does not send them to any third party other than the service providers listed above. It used to store a visit timestamp as well, to show what changed since your last visit, but that feature turned out never to have been built, so we stopped storing it on 27 August 2026 and clear any already stored on your next visit.

Besides cookies, the Service holds a connection URL you have just issued in your browser for a short while. The same URL can never be shown again, so this keeps it from being lost if you move away from the page before you have pasted it. It is held in storage that lives only inside that browser tab (session storage), kept separately for each board, and is never sent to our servers. It is erased when you press “I've pasted it” or when you close that tab. It is not used for tracking or advertising.

Changes to this document

If we change the contents, we will post the updated content and the effective date on this page before that effective date. For changes that significantly affect users, we will give notice a reasonable time in advance, on this page or by other appropriate means.

Japanese and English versions

The Japanese version of this page is the original; the English version is a translation. If the two differ, the Japanese version governs.