Privacy
What we store. What we never touch.
This page says what Boardzip keeps, who can see it, and how long it stays. It is written in plain words. If one line is unclear, write to us and we will fix the wording.
Last updated: 12 September 2026
The short version
- We store the words your board writes and the addresses we send links to.
- We store the link to your board pack. We never open the document behind it.
- Nothing you write is used to train a model. There is no AI in this product.
- No advertising trackers. No tracking pixels. Not in the app, not in our email.
- You can delete one meeting, or the whole company account, whenever you want.
What we store
Your company and your sign-in
- The email address you sign in with.
- Your company name.
- Your meeting settings, such as how long a meeting runs.
- Sign-in records, so we can end a session and look into a break-in.
Your meetings
- The meeting title, the date, the time, and the time zone.
- The web link to your board pack.
- The names and email addresses of the board members you invite.
- When private input closes and when the board meets.
What people write
- The one choice the operator asks the board to help with.
- Each director’s private view. Other directors cannot read it before the input deadline.
- Each version of the living decision record: what was decided and any optional owner, date, success test, or official-record link.
- A director’s optional reply to a decision, whether it came from Boardzip or by replying to the email.
- The later check: whether the choice worked, is still in progress, or changed.
The email we send
We keep a record of each message: who it went to, the subject, when the provider accepted it, and any later delivered, delayed, bounced, or complaint event the provider sends us. Provider acceptance is not proof that a person read it. We keep the message body only for the short retry window, then remove it.
A few counts of our own
We count plain events inside our own database, such as how many decision loops were completed. These counts stay in our database. They are never sent to another company, and no outside analytics service runs on this site.
Your board pack stays where it is
We store the web address of your board pack. That is the whole of it. Boardzip never downloads the file. It never opens, reads, copies, parses, indexes, or summarises the document behind the link.
Each person opens the pack in the tool your company already uses, with the access your company already gave them. If someone has no access to the pack, we cannot give it to them.
What we never do
- We never use your data to train a model. There is no AI, and no model of any kind, in this product.
- We never sell your data, and we never rent it.
- We never put advertising trackers in the app.
- We never put a tracking pixel in our email. We cannot tell whether a message was opened or read.
- We never read the document behind your board pack link.
- We never show one company the data of another.
The links we email
- Each link is made for one person. It opens that person’s own board view.
- Email links are short-lived and stop working after they are used. A successful link creates a longer-lived, revocable session on that device.
- We do not store the link itself. We store a fingerprint of it.
- A fingerprint cannot be turned back into a working link, by us or by anyone else.
- We keep a copy of an email only for the short delivery and retry window. It is then deleted even if the provider never confirms delivery.
Treat the link like a door key. Please do not forward it. If a link reaches the wrong person, tell the person who runs the board. They can remove that person, which closes unused links and access to that board.
Who can see what
- Before the input deadline, directors cannot see one another’s private views.
- The operator can use those views after the deadline, with the writer’s name.
- During the meeting, directors talk; Boardzip does not ask them to vote or operate another screen.
- After the operator decides, each invited director can read the latest decision record and send optional private advice.
The operator can see who wrote each private view after input closes. That is on purpose: judgment has context, and the operator remains accountable for the final choice. Everyone is told this before they write.
How long we keep things
While your account is open
We keep your meetings while your account is open. Old meetings are worth keeping: the whole point of the later check is to read a decision made months ago beside what really happened.
When you delete something
- You can delete one meeting, or the whole company account, at any time.
- Deleting a meeting removes its private views, decision records, replies, and later checks.
- Deleting the company removes every meeting in it, and the board member list with them.
- The live copy is removed right away. Encrypted recovery copies, if any, age out with the database host’s backup cycle.
The one thing we keep longer
While the company account is open, we keep a short security record of actions taken in it: which account acted, what kind of action it was, and when. These records hold no question text, no answer text, and no decision text. They exist so we can look into a break-in or a report of misuse. Removing the company also removes these records from the live database.
Google Calendar, only if you connect it
Connecting your calendar is optional. The product works fully without it. You can type a meeting title, date and time by hand and never link an account.
- We ask for the narrowest permission that can do the job, and nothing wider.
- We read only the events you choose to bring in. We do not sweep your whole calendar into our database.
- We write only inside one clearly marked block in the event description. The rest of the invitation is left alone.
- We never create an event you did not ask for, and we never delete one.
- The access keys Google gives us are stored encrypted.
You can disconnect at any time, from your settings or from your Google account. Disconnecting stops the reading and the writing at once. Your meetings and decisions stay, and you keep using the product by hand.
The product runs on email, so we use an outside company to deliver it. To deliver a message, that company has to see the address it goes to and the words inside it. There is no way around that.
- The delivery company sees the recipient address, the subject, and the message text.
- It handles that under its contract with us and may not use it for its own ends.
- We keep the message reference it gives back, so retries are safe and bounces can be shown to the operator.
- If you reply to a decision email, the delivery company sends that reply to us so it can appear privately for the operator.
- We send only the email a meeting needs. We do not send marketing email.
Where your data is held
Your data sits in one Postgres database run by the operator of this product, with access limited to the people who keep it running. If you need to know the country it runs in before you sign up, write to us and we will tell you.
What you can ask us for
- A copy of what we hold about you.
- A correction to a name or an email address.
- Deletion of one meeting, or of the whole company account.
- An answer to any question about this page.
Write to [email protected]. We reply within 30 days. If you are a board member rather than the person who runs the meeting, you can write to us directly, and we will work with your meeting host where we must.
Changes to this page
When we change this page, we change the date at the top. If a change matters to you, such as a new place your data is held, we email the person who runs your meetings before it starts.
How to reach us
Write to [email protected]. A person reads it.