How your account and data are protected
A practical overview. Our full privacy and security policies cover the legal detail.
Signing in
Sign in with email and password, or with Google. New passwords are checked against known breached-password lists before an account is created, and never stored in plain text.
Two-factor authentication
Enable 2FA from Settings → Security for a TOTP authenticator app, plus a set of one-time backup codes in case you lose access to the app.
Sessions
A session stays signed in for 30 rolling days of activity, with a 90-day absolute cap regardless of activity. Settings → Security lists every active session (device and last seen) with the option to revoke any of them remotely.
Board access
- Every board connection is checked twice — a short-lived, board-scoped token and a live membership check — independently of each other.
- A viewer's writes are rejected on the server, not just hidden in the interface.
- Sensitive account and board actions are recorded in an audit log.
Encryption
All traffic between your browser and our servers runs over HTTPS/WSS. Board content is stored durably in our database and backed up on a regular schedule.
Your data
Export takes your board content with you at any time in an open format (SVG or PNG). Deleting your account starts a 30-day grace period — cancellable — before your data is permanently removed.