Data and privacy

Boards are private by default and only reachable by people you invite. Files live in private storage and are served through signed URLs that expire, never from a public bucket. Deleted clusters are recoverable for 30 days, then purged. Everything you put in can be exported or read back out through the API.

Who can see a board

Private by default. A new cluster is visible only to you until you do one of two things:

Making a board genuinely public and discoverable is a separate, reviewed step — see Explore. Nothing becomes public by accident.

Where files live

In private object storage, served back through signed URLs that expire. There is no public bucket and nothing is reachable by guessing a path.

Uploads go from your browser straight to storage. A file referenced by a board is protected from cleanup for as long as the board references it.

Retention

ThingKept
Deleted cluster30 days in the trash, then purged
Board version snapshotsFor rollback and workspace recovery
Files no longer referenced by any boardEligible for cleanup after a grace period
Resolved commentsArchived, not deleted

Restoring a cluster within the trash window restores its images with it.

Getting your data out

Nothing is trapped:

Deleting your account

Settings → Profile → Delete account. Before it asks you to confirm, it tells you what will actually happen to your account — how many clusters go, and what becomes of anything you share:

  • Workspaces only you are in are deleted, with every cluster, card, comment, tag and uploaded file in them.
  • Workspaces you created that other people are in are not deleted. Ownership passes to the longest-standing other member, who is named on the confirmation screen. Their work is never destroyed by your leaving.
  • Workspaces you were only a member of simply lose you.
  • Comments, tags and votes you left on other people's clusters stay where they are, with your name removed — deleting them would take away context that belongs to someone else.
  • Any subscription is canceled as part of the deletion, so nothing bills a removed account.
  • Your analytics and error records are anonymised, not merely unlinked: the session identifier is dropped too, so the rows cannot be tied back to you.

Confirmation is typing your own email address. There is no grace period and no undo — once it completes, support cannot restore the account, and the address is free to sign up again from scratch.

Accounts and access

Sign-in is a one-time emailed code. There is no password to be reused or leaked.

API tokens are stored only as a hash — the value is shown once and cannot be recovered. A token acts as you, reaching exactly what your account reaches under the same access rules the app uses, and can be revoked at any time with immediate effect.

Error reporting

Errors are recorded first-party, in Clusters' own infrastructure, to fix crashes. There is no Google Analytics and no third-party error monitoring service in the app.

When Clusters asks you a question

Clusters may ask you one question, once: on a day you come back, it asks what brings you back today, offering a short list of answers. Tapping one is the whole answer. It then asks a single follow-up in your own words, which you can skip — the tap has already been recorded either way.

The list is fixed and always in this order: picking up where you left off, adding material you have collected since, starting something new, looking back through what you have got, showing it to someone. Alongside them sit Nothing in particular, which is a real answer, and Not now, which is not.

  • It is asked once per account, ever. Answering closes it permanently and that is recorded on the server, so it will not return if you clear your browser storage. Choosing Not now is remembered in this browser.
  • It counts as asked only once it has actually been on your screen for a few seconds, so a question that appears as you are closing the tab does not use up your one time.
  • It never appears on your first session, and it does not appear when you have arrived through someone else's share or invite link.
  • Whatever you type in the optional free-text follow-up is stored as written text you chose to send, readable by Clusters staff. It is not analysed automatically and is not shared with anyone outside Clusters. If it cannot be sent straight away it waits in your browser's own storage until it can, for at most a week.
  • The tap itself is recorded as one of the fixed answers above, together with the length of anything you wrote — never its content.
  • Nothing you type into your own clusters — card contents, notes, documents, search terms — is ever collected this way. Search is measured by shape only (how many results, whether any were opened), never by content.

If you would rather it had never been asked, deleting your account removes it along with everything else.

The full policies: Privacy · Terms · Cookies.

Those documents govern; this page is a plain-language summary of how the product behaves.

Frequently asked questions

How do I delete my account?

Settings then Profile, at the foot of the tab. It shows what will happen first — clusters removed, and which shared workspaces pass to which collaborator — and asks you to type your email to confirm. There is no undo and no grace period.

Are my boards private by default?

Yes. A new cluster is visible only to you until you invite someone or create a public link.

Can someone guess the URL of my image?

No. Files are in private storage and served through signed URLs that expire. There is no public bucket to enumerate.

How do I get all my data out?

Export boards and documents, download original files, or read everything programmatically through the REST API.

Machine-readable: /docs/account/data-and-privacy.md · /llms.txt
What changed and when: /changelog