Privacy Policy

Effective date: August 3, 2026

This Privacy Policy explains how Rossilite, LLC, a Georgia limited liability company ("Rossilite," "we," "us," or "our"), collects, uses, and shares information when you use the Projects application - on macOS (direct download or the Mac App Store), on Windows, or in a browser - the Cloud Sync service, and our websites (collectively, the "Service").

The short version: used offline, Projects keeps your data on your device and we never see it. If you sign in, we collect your email; if you use Cloud Sync, your boards - including anything you type or any image you upload as a background - are stored on our servers so we can sync and share them for you, visible only to the people you invite to that board. Payments are handled by Stripe or, on the Mac App Store, by Apple - we never see your card number either way. We don't sell your data, and we don't show ads.

1. Information We Collect

Local-only use - nothing

If you use Projects without signing in, your boards and projects are stored only on your device (in the app's local storage, plus one daily local backup snapshot on the desktop app, capped at 30). This data never reaches our servers, and we have no access to it.

Account information

When you sign in, we collect your email address. We use it to send one-time sign-in codes, identify your account, deliver board invitations, and send service-related messages. Sign-in codes are stored server-side for 15 minutes, allow at most 5 attempts, and require a 60-second cooldown between requests. Session tokens are stored in hashed (sha256) form on our servers and remain valid for 90 days per device. You may also set a display name, shown to other members of boards you share.

Cloud board content

When you create or join a cloud board, the board's content is stored on our servers (Amazon Web Services, United States) so we can sync it across your devices and display it to the board's members. This includes project titles, descriptions, column names, comments, checklists, assignees, due dates, activity/timeline entries, and nested boards, plus metadata such as who made a change and when. Comments carry the author's email, a snapshot of their display name at the time, and a timestamp.

Uploaded images (board wallpapers)

Cloud boards let you set a custom background image. When you upload one, it is stored on our servers and is visible to every member of that board - the same as any other board content. It is downscaled to at most 1MB before upload, and we verify it is a genuine image file before storing it. It is not publicly accessible: it lives at a private storage location that only our server can read, and our server only returns it to signed-in requests from active members of that specific board. On local boards (not synced to Cloud Sync), a custom background image never leaves your device.

Imported files

You can import a Microsoft Planner export (.xlsx) to create a board. The file itself is parsed entirely in your browser and is never uploaded to us; only the resulting board content (titles, buckets, due dates, checklists) is created, and it syncs like any other board content if you're using Cloud Sync.

Billing information

Depending on how you subscribe, payments are processed by Stripe, Inc. (web, macOS direct-download, and Windows) or by Apple Inc. through In-App Purchase (the Mac App Store version only). Your full payment card details go directly to Stripe or Apple and are never stored on our servers. We store your subscription status, plan, billing period dates, and an identifier from the relevant processor (a Stripe customer/subscription ID, or an Apple original transaction ID) - whichever rail you used unlocks Cloud Sync for that email address across all platforms. Stripe's handling of your information is described in Stripe's Privacy Policy; Apple's is described in Apple's Privacy Policy.

Technical and log information

Our servers automatically record limited technical information when you use cloud features or our websites, including IP addresses, timestamps, and request details, which we use for security, rate-limiting abuse (sign-in attempts, contact-form submissions, downloads, uploads), and debugging. Installer downloads are recorded via CDN access logs, which we retain for 30 days and use to produce an aggregate, public download-count dashboard - individual download events are not published.

Contact form

If you use our contact form, we collect the name, email, app, topic, and message you provide, and email it to our support inbox with your address set as the reply-to. No account is required to submit it.

Other user-controlled data

If you block a sender, we store that email address on your account so we can silently drop future invitations from them (they are not told they were blocked).

Usage analytics and diagnostics

We may collect aggregated, non-identifying usage statistics (such as feature usage counts, app version, operating system version) and crash or error reports to understand how the Service is used and to improve it. We do not use third-party advertising trackers, and we do not collect analytics designed to profile you across other companies' apps or websites.

Not collected: we do not use advertising trackers, we do not run cross-site or cross-app profiling, we do not sell your data, and we do not show ads.

2. How We Use Information

3. How We Share Information

We do not sell or rent your personal information. We share information only:

4. Automatic Software Updates

The macOS (direct-download) and Windows versions of the app check for updates automatically - on launch and roughly every 30 minutes - and can download and apply a new version of the app's content without requiring you to reinstall. Update files are cryptographically signed, and the app verifies that signature before applying an update; if your version is far enough out of date, you may see a non-dismissible prompt to update. Using the Service on these platforms means you consent to this automatic update mechanism. The Mac App Store version does not use this mechanism - it updates only through the App Store, per Apple's requirements.

5. Data Retention

We keep account information and cloud board content for as long as your account is active or as needed to provide the Service. Cloud boards you delete are removed from the live database promptly and from routine backups on a rolling basis. Sign-in codes expire within minutes; sessions expire automatically after 90 days, but cannot currently be revoked remotely before then - signing out clears the session on that device only. We may retain limited records (such as billing history) as required for tax, accounting, or legal purposes.

6. Your Choices and Rights

Depending on where you live, you may have additional rights under applicable privacy laws - such as rights of access, deletion, correction, portability, or objection to certain processing (including, for residents of the EU/UK/EEA, rights under the GDPR). We process your information on the following legal bases: performance of a contract with you (providing the Service you signed up for), our legitimate interests (security, fraud prevention, and improving the Service), and, where applicable, your consent. We honor rights requests as required by applicable law and do not discriminate against you for exercising them. We do not sell or "share" personal information as those terms are defined under U.S. state privacy laws.

7. Security

We use reasonable technical and organizational safeguards to protect your information: data is encrypted in transit (TLS), session tokens are stored hashed, board wallpaper images are access-controlled to a board's members, access to production systems is restricted, and payments are handled by processors that are themselves subject to industry payment-card security standards. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security - please keep control of the email account you use to sign in, since it can be used to access your account.

8. Age Requirement and Children's Privacy

The Service requires users to be at least 13 years old. Users between 13 and 17 may use the Service only with a parent or legal guardian's involvement and consent, as described in our Terms of Service. The Service is not directed to children, and we do not knowingly collect personal information from anyone under 13, consistent with the Children's Online Privacy Protection Act (COPPA). If we learn that we have collected personal information from a child under 13, we will delete it. If you believe a child under 13 has provided us personal information, contact us at contact@rossilite.com.

9. International Users

The Service is offered in many countries and regions, including the EU and UK, but is operated from the United States, and information we collect is stored and processed in the United States. If you use the Service from outside the U.S., your information will be transferred to and processed in the U.S., where data protection laws may differ from those in your jurisdiction; by using the Service you consent to this transfer to the extent permitted by applicable law. If you are located in the EU, UK, or Switzerland and have questions about the safeguards that apply to this transfer, contact us.

10. Accessibility

We want the Service to be usable by as many people as possible. If you encounter an accessibility barrier using Projects or our websites, please tell us at contact@rossilite.com so we can address it.

11. Copyright Concerns

If you believe content stored on the Service infringes your copyright, see our Copyright/DMCA Policy for how to submit a notice.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice - for example, by email, in-app notice, or by updating the effective date on this page. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

13. Data Incident Notification

If we become aware of a security incident involving personal information, we will investigate it, take reasonable steps to contain and remediate it, and notify affected users, regulators, or other parties when required by applicable law. Any notice will describe the incident and recommended protective steps to the extent reasonably known and legally permitted.

14. Contact

Rossilite, LLC - Dahlonega, Georgia, United States
contact@rossilite.com