Back to home

Privacy Policy

How Cutline OS collects, uses, shares and protects information — written to be read, not skimmed past.

Last updated: August 4, 2026

1. Information we collect

We collect information you give us directly, and a limited amount generated automatically when you use the service.

  • Account information — your name, email address and workspace details, provided when you sign up or update your profile.
  • Workspace content — the clients, projects, invoices, files, messages and notes you create. This is your data; we store and process it on your behalf.
  • Client-submitted content — briefs, feedback and files sent by your clients through the secure links you share with them.
  • Technical data — IP address, browser type and timestamps, recorded in server and security logs.

We do not collect or store full payment card numbers. Where payments are processed, they are handled by the payment provider, not by us.

2. How we use your information

We use the information we collect to:

  • Provide, operate and maintain the service and the features you enable.
  • Generate and deliver invoices, receipts and other documents you create.
  • Send technical notices, security alerts, and support and administrative messages.
  • Respond to your questions and support requests.
  • Detect, investigate and prevent abuse, fraud and activity that threatens the security of the service.
  • Understand aggregate usage patterns so we can improve the product. This analysis is performed on aggregated data and is not used to profile individuals.

We do not sell your personal information, and we do not use your workspace content to advertise to you or to anyone else.

4. Service providers we share data with

We use a small number of infrastructure providers to run the service. They process data only on our instructions and only as needed to perform their function:

  • Clerk — user authentication and workspace membership.
  • Supabase — the primary database where workspace data is stored.
  • Vercel — application hosting and file storage.
  • Resend — delivery of transactional email such as invoices and feedback requests.
  • Ably — realtime delivery of messages and notifications.
  • OneSignal — browser push notifications, where you have enabled them.
  • Upstash — rate limiting and scheduled background jobs.

We may also disclose information where we are legally required to do so, or where it is necessary to protect our rights or the safety of users. If the service is ever involved in a merger or acquisition, we will give notice before your information becomes subject to a different privacy policy.

5. Data security

Data is encrypted in transit using TLS and encrypted at rest by our database and storage providers. Access to production systems is restricted to those who need it.

Each workspace is isolated: server-side queries are scoped to your workspace, and realtime channels are authorised per user, so members of your organisation can only reach the conversations and projects they have been granted access to.

No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you without undue delay.

6. How long we keep it

We keep your workspace data for as long as your account is active. If you close your account, we delete or anonymise your data within 90 days, except where we are required to retain records — billing and tax records, for example — for longer.

Downgrading a plan does not delete anything. Content beyond your new plan's limits becomes read-only rather than being removed.

Backups are retained on a rolling basis and expire automatically.

7. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent you previously gave.

You can update most account information directly in your dashboard settings. For anything else — including a full export or deletion of your workspace — email support@cutlin.tech and we will respond within 30 days.

8. Cookies and local storage

We use cookies and browser storage only for functional purposes: keeping you signed in, remembering your workspace and theme preference, and protecting forms against abuse. We do not use advertising or cross-site tracking cookies.

Blocking these cookies in your browser will prevent you from staying signed in to the service.

9. Children's privacy

The service is intended for business use and is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

10. Changes to this policy

We may update this policy as the service evolves. When we make material changes, we will revise the date at the top of this page and, where the change significantly affects your rights, notify you by email or in the dashboard before it takes effect.

11. Contact us

Questions about this policy or how your data is handled? Email support@cutlin.tech and we will get back to you during support hours (Sunday – Thursday, 10:00 – 18:00, GMT+6).