Privacy Policy

Effective 13 September 2026

The Dashboard is a personal dashboard run by Carl Frankenfeld ("we", "us"). It shows the things you choose to keep on it: notes and tasks, documents, unread counts for your mailboxes, the weather where you are, prices, and whether the sites you watch are up. This policy says what information the dashboard holds about you, why, and what you can do about it.

What we hold

Your account. A username, and if you gave them, an email address, your name and a phone number. The email address is used to send you a password reset or an invitation and for nothing else.

What you put on the dashboard. Notes and tasks, the files you attach to them, documents you store, places you record for the weather or against an entry, the sites you monitor, the currency pairs and instruments you follow, and the arrangement of your pages. All of it is there because you added it, and it is shown only to you.

Mailbox access. To show unread counts, the dashboard holds the details it needs to reach each mailbox you add: the server, your username, and either a password you typed or the sign-in tokens a provider issued when you signed in. See Google and Microsoft accounts below.

Technical records. The server keeps ordinary request logs, including the address a request came from and when it was made, and counts recent sign-in attempts per address to slow down password guessing. There is no analytics, no advertising and no tracking of any kind.

Cookies and browser storage. A cookie keeps you signed in, another remembers which page of the dashboard you last viewed, and your choice of light or dark theme is kept in your browser. Nothing else is stored in your browser and no third-party cookies are set.

Why we hold it

To run the dashboard for you, and for no other reason. We do not sell information, share it with advertisers, build profiles from it, or use it to train anything. The administrator of the dashboard sees the account details needed to manage accounts (your username, contact details and how much storage you use) and not the content you keep.

Google and Microsoft accounts

When you connect a Gmail or Microsoft mailbox with "Sign in with Google" or "Sign in with Microsoft", the dashboard asks the provider for permission to read your mailbox over IMAP and for the email address of the account that signed in. It uses that access for exactly one thing: to count the unread messages in your inbox and show that count on your dashboard. It does not read, store, forward, search or analyse the content of your messages, and it never sends mail on your behalf.

The tokens the provider issues are stored encrypted and used only by this dashboard. You can withdraw the permission at any time, either by removing the mailbox from the Email widget, which deletes the stored tokens, or from your account's own permissions page (Google, Microsoft), after which the dashboard can no longer reach the mailbox.

The Dashboard's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Other services the dashboard talks to

Some widgets fetch what they show from elsewhere, and send only what that takes: the coordinates of a place you add go to the weather service that provides the forecast; a place name you look up goes to OpenStreetMap's search service; sites you monitor are visited to see whether they answer; and public price feeds are read without any information about you. Each of those services has a privacy policy of its own.

Where it is kept and how it is protected

Everything is stored on the server that runs this dashboard, which you reach over an encrypted connection. Your notes, tasks, attachment names, recorded places, mailbox passwords and sign-in tokens are encrypted at rest with a key of your own. Encrypted at rest is not the same as unreadable by the operator: the server holds what it needs to show you your content and to check your mailboxes while you are signed out, so treat the dashboard as private, not as a vault.

How long it is kept

Until you delete it. Deleting an entry removes its attachments; deleting a mailbox removes its credentials and tokens; and deleting an account removes everything it held. Routine server backups are kept for a limited time and then overwritten. A backup you download from Settings is yours, and holds everything the dashboard holds for you.

Your rights

You can see and change your account details in Settings, take a complete copy of your data from the Backup tab, delete anything you added, and ask the administrator to delete your account. Whatever rights the law where you live gives you over your personal information, including access, correction and deletion, we will honour. Questions and requests go to the administrator of this dashboard.

Children

The Dashboard is not directed at children and is not knowingly used to hold information about anyone under 13.

Changes

If this policy changes, the new version will be published here with a new date. Using the dashboard after that date means you accept the change.