Privacy Policy

Last updated 17 August 2026

Teamdeck is a workspace agencies use to run client work — projects, tasks, chat, documents, invoices, and publishing to their clients' websites. This page explains exactly what we hold, why we hold it, and who else ever sees it. It is written to be accurate about this specific product rather than generically reassuring.

1. Who we are

Teamdeck (“Teamdeck”, “we”) provides the service at teamdeck.in. For the account data of people who sign up, we are the data controller. For the content those people put into their workspace — including information about their clients — we act as a processor on their instructions, and the account holder is the controller.

Contact: privacy@teamdeck.in.

2. Signing in with Google

If you sign in with Google, we receive only your basic profile from Google: your name, your email address, and your profile picture URL. We request no other Google scopes. We do not read your Gmail, Drive, Calendar, Contacts or any other Google service, and we cannot — those permissions were never requested.

Teamdeck's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer, sell or use Google user data for advertising, and no human reads it except where required for security or to comply with law.

You can sign in with an email address and password instead, in which case Google receives nothing. Passwords are hashed by our authentication provider and are never visible to us.

3. What we hold, and why

AccountYour name, email address, profile picture, role, and which organisation you belong to. Needed to sign you in and decide what you can see.
Workspace contentProjects, tasks, comments, chat messages, notes, documents, calendar events, meetings and uploaded files. This is the product; it is stored so you can use it.
Client recordsIf you use the client portal: your clients' names, companies, email addresses, support requests and invoices. You decide what goes in here.
Stored credentialsIf you use the password vault, the secrets you save. Encrypted at rest — see section 7 for exactly what that does and does not mean.
Connected website dataIf you install our connector on a website: page addresses, titles, publication dates, traffic counts, and events such as form submissions or orders. See section 5.
Technical logsIP address, browser, timestamps and error traces, kept to run the service, investigate faults and detect abuse.

We do not use any of it for advertising, we do not sell it, and we do not build profiles of you for anyone else.

4. Artificial intelligence features

Several features send content to third-party AI providers to generate text or code. This only happens when you use the feature, and only the content that feature needs is sent:

  • Blog flows and proposals — your brief, and the relevant brand kit (name, colours, fonts, voice, logo) are sent to Google (Gemini). Blog research additionally queries Exa for public web sources.
  • Note assistance and code runs — the note or task content you act on is sent to Anthropic (Claude).
  • Experimental agent— if an organisation switches it on, a task's title and description, plus team members' names, roles and open task counts, are sent to Google (Gemini) to suggest an owner and an approach. It is off by default.

Stored vault credentials, connector secrets and invoice files are never sent to any AI provider.

AI output is generated text. It can be wrong, and proposals in particular contain placeholder figures. Read anything the model produces before you send it to a client or publish it.

5. Websites you connect

Our connector is a file installed on a website by whoever controls that site. Once installed, Teamdeck can publish posts to it and can read back three things: what pages exist, how they are performing, and events such as form submissions, orders or errors.

Teamdeck always calls the website; the website never calls us. Those events may contain personal information about that site's visitors. If you connect a site, you are responsible for having the right to send us that information and for not forwarding more of it than you need — the connector lets you choose exactly what each route returns.

6. Who else processes your data

We use a small number of providers. Each only receives what it needs to do its job:

SupabaseDatabase, authentication and file storage.
VercelApplication hosting, delivery and server logs.
GoogleSign-in, and the Gemini models behind the AI features.
AnthropicThe Claude models behind note assistance and code runs.
ExaWeb search used when a blog flow researches a topic.

We may also disclose information where the law requires it, or to protect the security and rights of Teamdeck and its users. We do not sell personal information.

7. Security, stated plainly

What we do:

  • All traffic is encrypted in transit over HTTPS.
  • Access is enforced in the database itself with row-level security, so one organisation cannot read another's rows even if application code were wrong.
  • Vault secrets are encrypted at rest and are deliberately excluded from our public API, webhooks and realtime streams.
  • Connector requests are signed and timestamped, so a captured request cannot be replayed and the shared secret never travels.

What this is not: the password vault is not end-to-end encrypted. Secrets are encrypted with a key held in our infrastructure, which means our systems are technically capable of decrypting them to show them to you. Please judge the vault on that basis, and do not store anything in it you would not be willing to hold in a hosted service.

No service is immune to compromise. If a breach affects your data we will tell you and, where required, the relevant authority.

8. Where data is stored

Data is stored in the region configured for our Supabase project and served through Vercel's global network, which means it may be processed outside your country. Where personal data is transferred internationally, we rely on our providers' standard contractual protections.

9. How long we keep it

Workspace content is kept while your account is active, because that is the point of it. If you delete something in the app it is removed from the live database; copies may persist in encrypted backups for a limited period before ageing out. Technical logs are kept for a short period for debugging and abuse detection.

Ask us to close your account and we will delete your workspace content and personal data, other than the minimum we must keep for legal or accounting reasons — invoice records being the usual example.

10. Your rights

Depending on where you live you may have the right to access, correct, export or delete your personal data, to object to certain processing, or to complain to a data protection authority. Most of this you can do yourself in the app; for anything else, email privacy@teamdeck.in and we will respond within 30 days.

If you are a client using a portal your agency gave you, your agency controls that data. We will pass your request to them.

11. Children

Teamdeck is a tool for businesses and is not intended for anyone under 16. We do not knowingly collect their data; if you believe we have, tell us and we will delete it.

12. Changes

If we change this policy we will update the date at the top. For changes that materially affect how we handle your data, we will notify account holders in the app or by email rather than relying on you noticing.

Questions about this page? Email legal@teamdeck.in.