Home · Privacy Policy

Privacy Policy

Global data privacy policy for My MaNaGeR.

Effective Date: August 30, 2026 ยท Last Revised: September 4, 2026

Terms of Service · Contact

Global Data Privacy Policy

This Privacy Policy governs the use of My MaNaGeR ("the Application"), an offline-first, local-browser construction project management workspace deployed as static web assets via Cloudflare Workers. This document establishes how the Application natively honors global data sovereignty laws, including but not limited to the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA, Brazil's LGPD, India's DPDP Act, South Africa's POPIA, and Australian Privacy Principles across all continents and jurisdictions.

1. Core Principle: Local-First Privacy (Data Minimization)

The Application is architected as a local-first utility. We do not operate remote application databases for user project data, server-side data collection mechanisms, user tracking endpoints, or analytical profiling systems.

  • Absolute User Control: Every piece of information input into the platform, including work breakdown structures (WBS), schedules, budgets, risk matrix evaluations, field voice notes, meeting minutes, procurement sheets, claims packages, and all other project data, is stored exclusively in your local web browser sandbox (localStorage, IndexedDB). No project data leaves your device during standard operation.
  • Zero Server Transmission of Project Data: Your project data is never uploaded, transferred, shared, or sold to us or any remote third-party server during standard operation. Closing your browser tab preserves your information natively on your local device. The Application functions fully offline with zero network dependency.
  • No Behavioral Profiling: The Application contains zero advertising SDKs, zero tracking pixels, zero analytics beacons, and zero monetization hooks that observe, profile, or monetize your usage patterns, workflows, or project content.

2. Statutory Data Subject Rights (Global Compliance)

International data privacy frameworks guarantee citizens specific legal protections regarding their Personal Identifiable Information (PII). Because of the Application's decentralized architecture, these rights are automatically executed and managed directly by the user without requiring any request to the Application operator:

  • Right to Access & Portability (GDPR Art. 20, CCPA §1798.100): You have immediate, unrestricted access to 100% of your project data at all times. You can extract your complete workspace configuration into a portable, machine-readable .json file at any time via Settings > Controls > Save Project to File. No request to the operator is required.
  • Right to Erasure / Right to be Forgotten (GDPR Art. 17, CCPA §1798.105): Because the Application does not collect, store, or hold your project data on any remote server, we cannot delete it for you. You execute your right to complete erasure instantly by clearing your browser's cache, cookies, and local site data storage. This action is irreversible and immediate.
  • Right to Opt-Out of Sale and Targeted Advertising (CCPA §1798.120, CPRA §1798.185): The Application does not sell, rent, license, or share your personal information or project data with any third party for advertising, marketing, analytics, or any commercial purpose. There is nothing to opt out of; the data never leaves your device.
  • Right to Non-Discrimination (CCPA §1798.125): The Application provides identical functionality regardless of whether you exercise any privacy right. No service degradation, feature restriction, or pricing differential applies to users who exercise their data rights.
  • Right to Correct (CPRA §1798.106): You may correct any data at any time by editing it directly within the Application. No request to the operator is necessary.
  • Right to Know (CCPA §1798.100, GDPR Art. 15): This Privacy Policy constitutes the entirety of our data practices. We collect no project data. The only server-side data is account metadata (email, hashed password, subscription status) for users who voluntarily sign in for cloud sync features.

3. Account Data (Voluntary Cloud Sync Only)

If you voluntarily sign in and enable cloud sync, the following limited account metadata is processed server-side. The lawful basis for this processing is the performance of the service you request (sign-in, cloud backup, moving projects between devices) and, where required, your consent given when you enable the feature. Project data that never leaves your device is not processed by us at all; it remains under your exclusive control.

  • Account identifiers: Google account sub (opaque ID), email address, display name, or for email accounts: email + PBKDF2-SHA256 hashed password (100,000 iterations; plaintext never stored).
  • Project metadata: Project ID, project name/label, owner code hash (PBKDF2; plaintext never stored), editor/viewer code hashes, timestamps (created_at, last_owner_seen_at, deleted_at), and latest R2 storage key reference.
  • Encrypted state blobs (at rest): If you enable cloud backup, your project state is encrypted at rest before storage in Cloudflare R2 using an AES-256-GCM envelope applied server-side in the Worker. The encryption key is derived from your owner code's PBKDF2-SHA256 hash and a per-project salt held in the database; the raw owner code is never stored and cannot be recovered from the hash. A copy of the R2 bucket without database access would expose only ciphertext. Where encryption cannot be applied, a plaintext fallback is used (legacy blobs are also read as plaintext for compatibility). Decryption capability necessarily resides with the server infrastructure that operates cloud sync; if you require data that cannot be read by any server, do not enable cloud sync and keep the project fully local.
  • Local data is not encrypted: Project data stored on your device (in localStorage/IndexedDB) is stored in plaintext by the browser. If you share a device or are concerned about local access, use your operating system's or browser's own encryption and lock features. This is an architectural trade-off of the offline-first design.

3.1 Cookies & Local Storage

The Application places no advertising, marketing, or third-party tracking cookies. The only cookies and browser storage used are:

  • Session cookie (mmgr_session): A single HttpOnly, Secure, SameSite=Lax cookie issued when you sign in, used for authentication on cloud features. Expires after 7 days. Contains no project data.
  • Local site storage (localStorage/IndexedDB): Stores your project data and preferences (theme, palette, view mode, dock settings, project files). This data never leaves your device except through features you explicitly enable (cloud sync, export, sharing codes). You can clear it at any time through your browser's site-data controls.
  • No fingerprinting or cross-site identifiers: No device fingerprinting, tracking pixels, or identifiers shared across sites.

You may delete your account and all associated server-side data at any time via the Application's account settings. Account deletion is permanent and irreversible.

4. Cross-Border Data Flows & Third-Party APIs

  • No Cross-Border Leakage (Standard Operation): All standard application processes operate entirely client-side within your browser. No international cross-border data transfers occur during local calculations, local browser-embedded AI tasks, Monte Carlo simulations, or offline project management.
  • User-Authorized Third-Party Connections: If you explicitly elect to use external features, you establish a direct, unmediated communication pipeline between your local browser and those specific third-party providers. These features include:
    • Google Sign-In (Google LLC, terms at policies.google.com)
    • Google Drive backup sync (Google LLC)
    • Live weather forecasts (Open-Meteo, open source, no API key required)
    • BYO API key AI processing (OpenAI, Google Gemini, Anthropic Claude, or any compatible provider you configure)
    • Email authentication (Resend transactional email service)
    • Payment processing (LemonSqueezy, for optional paid plans only)
  • Infrastructure processors: The Application's cloud features are operated on Cloudflare's Workers, D1 database, R2 storage, and CDN edge. Cloudflare acts as an infrastructure processor: it handles and stores the limited account and project metadata described in Section 3 on servers it operates, and its edge servers may retain standard, short-lived request logs. Cloudflare's own privacy policy and data-processing terms apply to that handling.
  • User Assumes Third-Party Compliance Responsibility: You assume full legal responsibility for verifying that each external provider you connect to complies with your regional data protection mandates. The Application operator has no control over, and assumes no liability for, the data practices of third-party providers you voluntarily connect to.

5. Data Retention & Automatic Purging

  • Local data: Retained in your browser indefinitely until you clear it or the browser purges it. No server-side copy exists unless you enabled cloud sync.
  • Cloud projects (owner inactive): Projects with no owner activity for 180 days are automatically purged from all storage (D1 database, R2 blobs, editor codes, changelogs, adoptions, offline copies).
  • Soft-deleted projects: Projects you delete are held in a tombstone state for 7 days, then hard-purged from all storage permanently.
  • Account deletion: All server-side data (account record, sessions, cloud projects, editor codes, changelogs, adoptions) is permanently deleted immediately upon account deletion request.

6. Children's Online Privacy Protection

The Application does not collect, process, or aggregate information from any individual, including minors under any age threshold worldwide, natively satisfying the requirements of the United States COPPA, the United Kingdom Age Appropriate Design Code, and global equivalents. The Application is intended for use by licensed construction professionals and project managers of legal working age.

7. Do Not Track & Global Privacy Control

The Application honors Do Not Track (DNT) browser signals and Global Privacy Control (GPC) headers. When detected, all optional telemetry and analytics (if any are enabled in future versions) are automatically suppressed. Given the Application's local-first architecture, DNT/GPC compliance is inherent in the design.

8. Data Breach Notification

Because the Application does not store project data on any remote server, a data breach of our infrastructure cannot expose your project data. In the event of a breach affecting account metadata (email addresses, hashed passwords), we will notify affected users within 72 hours as required by GDPR Art. 33 and applicable breach notification laws. Account passwords are hashed with PBKDF2-SHA256 (100,000 iterations) and cannot be reverse-engineered from the hash.

9. Changes to This Policy

We may update this privacy policy from time to time. The "Last Revised" date at the top of this page will be updated. Material changes will be posted on this page. Continued use of the Application after changes constitutes acceptance of the updated policy. Your only remedy if you do not agree to changes is to stop using the Application and delete your data.

10. Contact & Data Protection Officer

This document was last revised on September 4, 2026. Use of My MaNaGeR is also governed by the Terms of Service.