Privacy Policy
Exponential · exponential.at · last updated 2026-07-30
This privacy policy covers the Exponential service and its apps for web, Android, iOS, and desktop (together “Exponential”, “the service”). It describes what data they collect, how it is used, stored, shared, and deleted. Exponential is operated by Dennis Strähhuber, Germany (“we”). It applies to the hosted cloud service at app.exponential.at. If you connect the apps to a self-hosted Exponential instance instead, the operator of that instance is responsible for the data it stores; this policy then applies only to what the apps themselves do on your device.
1. Data we collect
- Account data. When you sign in with Google we receive your name, email address, and profile picture URL via Google’s OAuth flow (scopes
openid,profile,email). We request no other Google scopes and never access your contacts, mail, files, calendar, or location. When you sign in with Apple we receive your name and email address from Apple. If you chose “Hide My Email”, that address is an Apple private-relay address and we never see the real one. No other Apple account data is accessed. - Content you create. Teams, boards, issues, comments, labels, and file attachments (including screenshots submitted through the feedback widget) are stored so the service can function. Issue and comment text may contain whatever you choose to write.
- Feedback widget submissions. If a site operator embeds our feedback widget and you submit feedback or a support request through it, we store what you send (your message and optional screenshot) plus the page URL you were on, your browser’s user-agent and viewport/screen size, and any email, name, or custom data the host site chooses to pass along with your submission. This lets the site operator triage and follow up on your report. The members of the operator’s team who handle feedback can see your email and message. Your email is never exposed outside that team.
- Push notification tokens. If you enable push notifications on Android or iOS, a Firebase Cloud Messaging device token is stored to deliver them. The token identifies the app install, not your physical device identity.
- GitHub integration data. If you connect the Exponential GitHub App, we store the installation reference and repository names you connect. Repository access tokens are short-lived and minted on demand; we do not store your GitHub password or personal access tokens.
- Billing data. Paid subscriptions are processed by Creem (merchant of record). We store your subscription state and a customer reference; payment card details never touch our servers.
- Technical logs. Standard server logs (IP address, request path, timestamps) are kept short-term for security and operations. We run no third-party analytics, no ad networks, and no tracking pixels.
- First-party usage statistics. To understand how people find and start using Exponential, our own servers count aggregate events (page visit, sign-up, first issue, subscription) together with any campaign parameters (ref/UTM) in the arriving link. Visits are counted under a pseudonymous identifier derived from the IP address and browser via a salted hash whose salt rotates daily. The raw values are never stored and visits cannot be linked across days (legitimate interest, Art. 6(1)(f) GDPR). This happens entirely server-side: no analytics cookies, no scripts from third parties, nothing stored on your device.
2. How data is used
Data is used solely to provide the service: authenticating you, syncing your boards in real time across your devices, sending the notifications you enabled, operating the GitHub and billing integrations you chose, and answering support requests. We do not use your data for advertising or profiling, we do not sell it, and we do not use it to train machine-learning models.
3. Sharing and processors
We share data only with the processors required to run the service:
- Hetzner Online GmbH (Germany): servers and object storage for attachments.
- Google Firebase Cloud Messaging: delivery of push notifications (receives the device token and the notification payload).
- Amazon Web Services (Amazon SES): transactional email (receives your email address and the message content, e.g. notification digests, team invitations, and support replies).
- Creem: subscription billing (merchant of record; receives your account email address to create the checkout session, plus the billing and payment details you enter with them).
- GitHub: only if you connect the GitHub App; repository operations happen through GitHub’s API on your behalf.
There are no data brokers, ad networks, or analytics providers. Feedback and support requests you submit through a widget are visible only to the members of the team that operates it.
4. Storage and protection
- All traffic between your devices and the service uses TLS (HTTPS).
- Data is stored in a PostgreSQL database and S3-compatible object storage on servers in Germany (Hetzner), reachable only from the application servers.
- Access is session-authenticated; a team’s data is only synced to members of that team. Server-side authorization enforces the same rules for every API call.
5. Retention and deletion
Your data is retained while your account is active. You can delete issues, comments, attachments, boards, and teams yourself inside the app. Deleting a board moves it to a trash for 48 hours, during which the team owner can restore it from team settings → Boards; after that window it is purged permanently, including the attachments stored on it. All other deletions are immediate and propagate to all synced devices. You can also delete your entire account and all associated data directly in the product: on the web under Account → Notifications → Danger Zone, and in the mobile apps under Settings → your server → “Delete account”. Deletion is immediate and removes your account together with every team where you are the only member. If you are the sole owner of a team that still has other members, transfer ownership or remove those members first. We will not delete a shared team out from under the people still using it. Alternatively, email support@exponential.at from the address tied to your account; requests are honoured within 30 days. Revoking Google access is possible anytime at Google Account → Third-party access; Apple access under Settings → Apple ID → Sign-In & Security → Sign in with Apple on your device, or at appleid.apple.com.
6. Legal bases
Under the GDPR we rely on three legal bases. Performance of a contract (Art. 6(1)(b)) covers everything needed to provide the service you signed up for: your account, your team’s content, and the paid subscription if you have one. Legitimate interests (Art. 6(1)(f)) cover keeping the service secure, preventing abuse, and the short-lived operational logs that come with running servers. Consent (Art. 6(1)(a)) covers anything that asks for it first, such as the push notifications you switch on; you can withdraw it at any time by turning the feature off again.
7. International transfers
The database and attachment storage stay on servers in Germany. Some processors are US companies or process data outside the EU/EEA: Google (Firebase Cloud Messaging) for push notifications, Amazon Web Services for transactional email, and GitHub for the optional repository integration. Those transfers rely on the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses.
8. Cookies and local storage
We use only strictly necessary cookies and local storage: a session cookie to keep you signed in, and device-local preferences such as the team you last opened. There are no advertising cookies, no analytics cookies, and no cross-site tracking. Our usage statistics (section 1) work entirely without storing anything on your device, which is why you see no cookie banner.
9. Your rights
You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable format. Much of this you can do yourself in the app: edit or delete your content, or delete your account outright (see section 5). For anything else, email support@exponential.at from the address tied to your account; requests are honoured within 30 days. You also have the right to lodge a complaint with a data protection supervisory authority, typically the one where you live or work.
Limited Use disclosure
Exponential’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Children
The service is a professional productivity tool and is not directed at children under 16. We do not knowingly collect data from children.
Changes to this policy
If this policy changes, the “last updated” date at the top of the page will be revised. Material changes that reduce user protections will be communicated to registered users by email before they take effect.
Contact
Data controller: Dennis Strähhuber, Germany (see the Imprint for the full postal address). Questions about this policy and all data-deletion requests: support@exponential.at.