Privacy Policy
What personal data Projments collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
- Effective
- 16 August 2026
- Last updated
- 16 August 2026
- Version
- 1.0
In short
- We collect what the service needs to work: your account details, the work content you and your team put into a workspace, time-tracking and activity data, files, messages, room scans, and billing records held at Stripe.
- We do not sell personal data, we do not run advertising, and we do not use behavioural analytics or tracking cookies.
- Most of what lives in a workspace belongs to the organisation that created it, not to us — for that content we act on the organisation’s instructions, and requests about it are answered by the workspace owner.
This summary is for orientation only. The sections below are the document that applies.
1. Who we are and what this covers#
Projments provides project management, time-tracking, collaboration and 3D room-scanning software. This policy explains how we handle personal data across every surface of the product:
- the Projments web application and marketing site
- the Projments desktop time-tracking agent (Windows)
- the Projments mobile app for Android
- the 3D Room Scanner web app and its Android scanning app
It does not cover third-party sites or services you reach from Projments, which have their own policies.
Questions about this policy, or about your data, go through our Support Center. Our full company details are in Contact and company details.
2. Our role: controller and processor#
Projments is sold to organisations, and that changes who is answerable for what. There are two distinct relationships, and it matters which one your data falls under.
- We are the controller
- for the data we need in order to run a business: account registration details, sign-in and security records, subscription and payment records, support conversations, and the technical logs the service produces.
- We are a processor
- for the content an organisation puts into its workspace: projects, tasks, checklists, client records, files, sheets, chat messages, call logs, time entries, screenshots and room scans. The organisation decides what goes in, who may see it and how long it stays; we process it on their instructions.
3. What we collect#
Account and profile data
- Name, email address and profile picture.
- A password, stored only as a bcrypt hash — we never hold the password itself and cannot recover it for you.
- Your role and permissions, workspace memberships, team assignments and licence assignments.
- Account status and the timestamp of the last password change, used to expire sessions issued before it.
Workspace content
- Projects, tasks, submissions, checklists, tags, calendars and reports.
- Client and contact records your organisation enters, including names and contact details of people who are not Projments users.
- Contracts, expenses, sales, labour rates and paid-hours records.
- Files, sheets, drawings, sheet versions and markups uploaded to a workspace.
Time, activity and screenshots
- Time entries and sessions: what you tracked, against which project or task, when it started and stopped.
- Periodic screenshots of your screen, captured by the desktop agent while a timer is running.
- The number of key presses and mouse clicks in each interval — counts only. The keys themselves are never recorded or transmitted; Projments is not a keylogger and captures no typed content.
- An activity percentage, and the name of the application in the foreground when a snapshot is taken.
This is the most sensitive category in the product and it has its own document: read Monitoring and Workplace Transparency Notice for exactly what is captured, when, who can see it, and what a member can switch off.
Communication data
- Chat messages, attachments and reactions, and posts in project rooms.
- Call records: who called whom, when, how long, and whether it was answered. Audio and video are streamed live and are not recorded by Projments.
- Meetings, attendee lists and meeting links.
- Notifications generated for you and whether you have read them.
3D Room Scanner data
- Camera access on your phone during a scan. The camera feed is processed on the device to derive room geometry.
- What is uploaded is the derived plan: wall and opening geometry, measurements, room and floor dimensions, plus the names and notes you enter (project, client, building, floor, room).
- A rendered 2D preview and a PNG thumbnail of the plan.
- No photographs, video or point clouds from the camera feed are uploaded to our servers.
Billing data
- Your plan, billing cycle, subscription status, current period dates and trial end.
- Stripe customer, subscription and price identifiers, and the storage or scanner packages you have bought.
- Card numbers are entered on Stripe’s own checkout and never reach our servers. We see the last four digits, card brand and expiry through Stripe, along with your invoice history.
Technical and security data
- Audit records of significant administrative actions: who did what, to which object, and when.
- The IP address a password-reset request came from, and rate-limiting counters keyed to an address or account, both used to detect abuse.
- Device push tokens, so notifications can reach your phone.
- Server logs, error reports and diagnostic data produced while serving requests.
Support data
- Support requests you raise, the messages in them, and any attachments or screenshots you choose to include.
4. Why we use it, and on what legal basis#
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the service you signed up for — workspaces, projects, tracking, chat, calls, files, scans | Account data, workspace content, communication data, scan data | Performance of a contract |
| Authenticating you and keeping accounts secure | Credentials, session data, reset tokens, IP addresses, rate-limit counters | Contract, and our legitimate interest in a secure service |
| Taking payment, managing subscriptions and issuing invoices | Billing data held by us and by Stripe | Contract, and legal obligation for tax and accounting records |
| Time tracking, activity measurement and screenshots | Time entries, snapshots, activity counts, active application names | Instructions of the workspace owner, who must have their own lawful basis — see §5 |
| Sending service email and push notifications you have asked for | Email address, device tokens, notification content | Contract, and legitimate interest in operational messages |
| Support, troubleshooting and answering your questions | Support requests, account data, diagnostic logs | Contract, and legitimate interest in supporting customers |
| Detecting, investigating and preventing abuse, fraud and security incidents | Audit logs, IP addresses, rate-limit counters, server logs | Legitimate interest in protecting the service and its users |
| Meeting legal, tax and regulatory obligations | Billing records, correspondence, records of consent | Legal obligation |
We do not use your data to train machine-learning models, we do not profile you for advertising, and we take no automated decisions that produce legal or similarly significant effects for you.
5. Screenshots and employee monitoring#
When a workspace uses the desktop agent, Projments captures screenshots and activity measurements of the people who track time in it. We build that feature; we do not decide to point it at anyone. That decision belongs to the organisation running the workspace.
The full description of what the agent captures, what it never captures, and what members can control is in the Monitoring and Workplace Transparency Notice. We recommend giving that page to your team rather than paraphrasing it.
6. Who we share data with#
We do not sell personal data and we do not share it for advertising. Data is shared in four situations only.
Inside your workspace
Other members see what your role and the workspace’s permission settings allow them to see — your name and profile picture, your time entries, your messages, your tasks, and, where the workspace has enabled it, your screenshots and activity records.
Service providers (sub-processors)
These companies process data on our behalf, under contract, only to deliver the parts of the service we use them for:
| Provider | What it does for us | Data it handles |
|---|---|---|
| Stripe | Payments, subscriptions, invoices and refunds | Name, email, billing address, card details (entered directly with Stripe), payment and invoice history |
| Cloudflare R2 | Object storage | Uploaded files, sheets, screenshots and scan thumbnails |
| LiveKit | Audio, video and screen-sharing calls | Live media streams and participant identifiers, in transit only — calls are not recorded |
| Pusher | Real-time delivery of chat and notifications | Message payloads and channel identifiers, in transit |
| Google Firebase Cloud Messaging | Push notifications to mobile devices | Device push tokens and notification content |
| Our email provider | Transactional email — invitations, password resets, notifications | Recipient address and message content |
| Our hosting and database providers | Running the application and storing its database | All data held by the service, as infrastructure |
Legal requirements
We disclose data when we are legally required to — a valid court order, a lawful request from an authority with jurisdiction over us — or where disclosure is necessary to protect the rights, safety or property of our users or ourselves. Where we are permitted to tell you about such a request, we will.
Business transfers
If the business is sold, merged or reorganised, data may transfer to the acquirer as part of it. We will tell you before your data becomes subject to a different privacy policy, and the protections in this one carry over until then.
7. International transfers#
Our providers operate globally, so your data may be stored or processed in countries other than your own. Where data leaves a jurisdiction that restricts transfers — for example the European Economic Area or the United Kingdom — we rely on the transfer mechanisms our providers offer, principally the European Commission’s Standard Contractual Clauses, together with the technical measures described below.
8. How we protect data#
- Passwords are stored as bcrypt hashes with a per-password salt. Sign-in takes the same amount of work whether or not the email exists, so the form cannot be used to discover who has an account.
- Sessions are signed tokens with a 30-day maximum lifetime. Changing a password invalidates every session issued before the change, across web, mobile and the desktop agent.
- Password reset links are single-use, short-lived, and stored only as a hash — a copy of our database yields no usable reset link.
- Traffic is encrypted in transit with TLS. Stored files are served through short-lived signed URLs rather than public links.
- Access to workspace data is checked on every API request against your role and permissions; administrative actions are written to an audit log.
- Sensitive operations are rate-limited to blunt brute-force and enumeration attempts.
No system is perfectly secure. If you believe you have found a vulnerability, please report it through our Support Center, marked as a security report, before disclosing it publicly, and give us a reasonable opportunity to fix it. We will not pursue researchers who act in good faith.
If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected customers without undue delay, and give you what you need to notify your own people.
9. How long we keep data#
Retention differs sharply by category — a screenshot and a tax invoice have nothing in common. Every category, its period and what triggers deletion is set out in the Data Retention and Account Deletion Policy.
In summary: workspace content stays until you or your workspace owner deletes it or closes the account; billing records are kept for as long as tax law requires; security and audit records are kept while they remain useful for investigating abuse; and anything else is deleted when it is no longer needed for the purpose it was collected for.
10. Your rights#
Depending on where you live, you have some or all of the following rights over your personal data. We honour these requests regardless of jurisdiction where we reasonably can.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of data that is wrong or incomplete. Most of it you can edit yourself in your profile and workspace settings.
- Erasure — deletion of your data, subject to records we are legally required to keep.
- Portability — a machine-readable export of data you provided. Reports export to Excel and PDF, and scans export as a data bundle, directly from the app.
- Restriction and objection — ask us to pause a use, or object to processing based on legitimate interests.
- Withdraw consent — where we relied on consent, withdraw it at any time; this does not affect processing already carried out.
- Complain — to your local data-protection authority, at any time.
To exercise any of these, raise a request from our Support Center while signed in to the account concerned. We answer within 30 days; if a request is complex we will tell you and may take up to 60. Raising it from the account is itself part of how we verify who is asking — we will not hand your data to someone who merely knows your email address.
11. Cookies and local storage#
Projments uses cookies to keep you signed in and local storage to remember preferences such as your theme and last workspace. We use no advertising cookies and no third-party behavioural analytics. Each cookie, what it does and how long it lasts is listed in the Cookie Policy.
12. Children#
Projments is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16, and accounts may only be created by people old enough to enter a contract in their country. If you believe a child has given us data, write to us and we will delete it.
13. Changes to this policy#
We update this policy when the product or the law changes. The version and date at the top of this page always reflect the current text. For changes that materially affect your rights, we will give notice in the app or by email before they take effect, and we keep a record of what changed. This version is 1.0, effective 16 August 2026.
14. Contact us#
Privacy questions, data-rights requests, security reports and general help all go to the same place — our Support Center, where the thread stays attached to your account. Full company details are on the Legal Center page, and the Help Center answers most questions before you need to ask one.
