Privacy Policy
This policy explains what Digiboffins Workspace collects, why, and what you can do about it. It covers the Android app (com.digiboffins.workspace) and the web application at workspace.digiboffins.com, which share one account and one database.
Digiboffins Workspace is a project management and team chat tool. It is sold to organisations, and the data in it is created by the people using it at work.
1. Who we are
Digiboffins is the data controller for the information described here. You can reach us at [email protected] about anything in this policy, including a request to see or delete your data.
2. What we collect
Information you give us when you create an account
| Data | Why we need it |
|---|---|
| Name | To show who wrote a message, who a task is assigned to, and who is in a workspace. |
| Email address | To sign you in, to send verification and password-reset codes, and to notify you about work assigned to you. |
| Password | To sign you in. We store it only as a bcrypt hash and cannot read it. |
| Profile photo (optional) | To identify you visually in chats and task lists. |
| Job title and status message (optional) | Shown on your profile to colleagues. |
| Google account ID (optional) | Only if you choose to sign in with Google, to match you to your existing account. |
Information you create while using the service
- Projects, tasks, subtasks, statuses, comments and notes.
- Direct and group chat messages, including reactions and read receipts.
- Files you attach to tasks, projects or messages.
- Your own preferences, such as muted conversations and starred chats.
Information collected automatically
- Server logs. Our web server records the IP address, timestamp and requested URL of requests, as almost all web servers do. These are used to operate and secure the service, and are not used to build a profile of you.
- Nothing else. The app contains no advertising SDK, no analytics SDK and no third-party tracker. It does not collect your location, contacts, calendar, photo library, call logs or device identifiers, and it does not track you across other apps or websites.
- Internet — to reach our server. Without it the app does nothing.
- Notifications — asked for the first time you open Chat or Inbox, so we can tell you about a new message or an assigned task. Declining it costs you notifications and nothing else.
3. How we use it
We use your information only to run the service you signed up for:
- To authenticate you and keep your session secure.
- To show your work to the colleagues you share a workspace or project with.
- To deliver messages, notifications and email alerts.
- To keep the app working offline and sync your changes when you reconnect.
- To diagnose faults and protect the service against abuse.
We do not sell your personal data, and we do not share it with advertisers. We do not use your content to train machine-learning models.
4. Who else sees it
Other people in your workspace
This is a collaboration tool, so it is designed to show your work to your colleagues. Anyone in a project you belong to can see the tasks, comments and files in it; anyone you chat with can see your messages. A workspace owner has administrative access to their workspace. Members marked as viewers (typically clients) are restricted to read-only access and cannot see anything flagged internal.
Service providers
| Provider | What they handle |
|---|---|
| MongoDB Atlas | Hosts the database holding your account and content. |
| Cloudinary | Stores files and images you upload. |
| Google (Gmail SMTP) | Delivers verification codes, password resets and notification emails. |
| Razorpay | Processes subscription payments. Card details go directly to Razorpay; we never see or store them. Payments are made on the web only — there are no purchases in the Android app. |
| OpenRouter | Powers the optional AI assistant on the web. Only the text of a conversation you start with the assistant is sent. The AI assistant is not present in the Android app. |
Each provider receives only what it needs to do its job and is not permitted to use it for anything else.
Legal requests
We may disclose information if we are legally required to, or where it is necessary to protect our rights, our users or the public.
5. How we protect it
- All traffic between the app and our servers is encrypted with HTTPS. The Android app refuses to run against a non-HTTPS server.
- Passwords are stored as bcrypt hashes and are never recoverable in plain text.
- Chat messages are encrypted at rest with AES-256-GCM.
- The app's local database on your phone is encrypted, with the key held in the Android Keystore.
- Access to projects and workspaces is checked on every request on the server, not only hidden in the interface.
No system is perfectly secure, but we take these measures seriously and review them as the service changes.
6. How long we keep it
We keep your account and content for as long as your account exists. When you delete your account, the account record, your profile and the workspaces you own are removed. Content you contributed to a workspace owned by someone else — for example a comment on a colleague's task — may remain, because it forms part of that organisation's records. Backups are overwritten on a rolling basis.
7. Your choices and rights
- See and correct your data. Your name, email, photo, job title and status are all editable in the app under Me → Account.
- Delete your account. In the app, go to Me → Account → Delete account. This is immediate and irreversible. You can also request deletion by email — see our account deletion page.
- Turn off notifications. Per conversation in the app, or entirely in your Android settings.
- Ask us anything. Email [email protected] and we will respond within 30 days.
Depending on where you live, you may have additional rights over your personal data, including the right to a copy of it and the right to object to its processing. Contact us and we will honour them.
8. Children
Digiboffins Workspace is a workplace tool and is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
9. International transfers
Our service providers may process data outside your country. Where that happens, we rely on the safeguards those providers have in place for international transfers.
10. Changes to this policy
If we make a material change, we will update the date at the top of this page and, where the change is significant, tell you in the app or by email. Continuing to use the service after a change means you accept the updated policy.
11. Contact
Digiboffins
[email protected]
workspace.digiboffins.com