Stickyboard

Privacy Policy

Last updated: August 21, 2026

Stickyboard is a sticky-note kanban app available as a web app at stickyboard.dev and as a Chrome extension that replaces the new-tab page. This policy explains exactly what data we collect, why, who processes it on our behalf, and the rights you have over it.

  1. Who runs Stickyboard
  2. What data we collect
  3. How we use it
  4. Boards you publish
  5. Who we share it with
  6. Cookies and local storage
  7. Retention and deletion
  8. Your rights (GDPR / CCPA)
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact

1. Who runs Stickyboard

Stickyboard is operated by an independent developer (the "operator," "we," "us"). It is a personal project, not a registered company. Contact details are at the bottom of this page.

2. What data we collect

2.1 Account data

2.2 Board content

If you use Stickyboard without an account, none of this reaches us at all: your boards, notes, and notebook pages are stored only in your own browser (IndexedDB) and are never sent to our servers. They are sent to us only if you later create an account and choose to bring them with you.

2.3 Technical data

We do not collect: your browsing history, your location beyond country level, mouse/keystroke telemetry, advertising identifiers, or any cross-site fingerprint. The Chrome extension requests no permissions other than chrome_url_overrides (replacing the new-tab page).

3. How we use it

We use the data above strictly to:

We do not sell your data, use it for advertising, train AI models on it, or share it with any party not listed in Section 5.

4. Boards you publish

You can publish a board so that anyone with its address can read it, without an account. This is off for every board until you switch it on, and you choose which boards it applies to.

When a board is published, a published board's page shows its name, its colours, and the notes on it — titles, descriptions, checklists and sketches — alongside the username you picked. Anyone who has the link can see it, and search engines can index it.

Some things are never published, even on a published board:

You can unpublish a board at any time from the same menu, and the address stops working immediately. Copies already made by other people or by search engines are outside our control, so treat publishing as permanent for anything sensitive.

You may also allow anyone with the link to add and move notes on a published board. We do not ask those visitors for an account or an email address, and we do not record who they are, so notes they add are not attributable to anyone. Only you can move notes to the bin.

A separate setting controls whether stickyboard.dev/your-username lists your published boards. It is off unless you turn it on; publishing a single board never adds it to a public index on its own.

5. Who we share it with

We use the following sub-processors to operate the service. Each receives only the data needed for its specific job:

We do not transfer data to third parties for their own purposes, do not use data for credit / lending decisions, and do not share data outside the approved use cases above.

6. Cookies and local storage

Stickyboard uses no advertising cookies. The hosted web app at stickyboard.dev sets Google Analytics cookies (_ga, _ga_*) to measure aggregate usage as described in Section 2.3. These cookies are first-party, last up to two years, and are not set inside the Chrome extension.

Beyond that, the only client-side storage is your browser's localStorage, which holds:

Stickyboard also uses your browser's IndexedDB to keep a local copy of your boards, notes, and notebook pages. This is what lets the app open instantly and keep working offline. If you use Stickyboard without an account, this local copy is the only copy — it never leaves your browser, and clearing your browser data deletes it permanently.

Signing out, or clearing site data in your browser, removes all of these. To opt out of Google Analytics on the web app, you can install Google's official opt-out browser add-on or block third-party cookies. PostHog is configured to respect your browser's "Do Not Track" setting: with it enabled, no product events are sent at all. Using the Chrome extension avoids both Google Analytics and PostHog entirely, and using Stickyboard without an account means no board content ever reaches our servers. In every case the rest of Stickyboard continues to work normally.

7. Retention and deletion

To delete your account and all associated boards, email us at the address in Section 12. We will remove your data within 30 days, except where retention is required by law.

8. Your rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) gives you the right to:

If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what we collect, to delete it, and to opt out of sale of personal information. Stickyboard does not sell personal information.

To exercise any of these rights, email us — see Section 12.

9. Security

No system is perfectly secure. If you discover a vulnerability, please report it to the contact email below before disclosing it publicly.

10. Children

Stickyboard is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the service evolves. Material changes will be announced in-app or by email to the address on your account. The "Last updated" date at the top reflects the most recent revision. Continued use after a change indicates acceptance.

12. Contact

Questions, data requests, or security reports — email petritavd@gmail.com.