Privacy Policy
Effective September 2, 2026 · version 2026-09-02
The short version: we collect what the product needs (your email, name, and the work your team puts into Roost) and the technical logs any web service has. We host it in the United States with Vercel and Neon and send email through Microsoft 365. We don’t run ads, trackers, or sell data. Your organization owns its content and can have it exported or deleted.
The full policy below is what applies. It forms part of our Terms of Service.
- 1. Who we are and what this covers
- 2. What we collect
- 3. How we use it
- 4. Who we share it with
- 5. Cookies and local storage
- 6. How long we keep it
- 7. Security
- 8. Your choices and rights
- 9. International transfers
- 10. Children
- 11. Changes to this policy
- 12. Contact
1. Who we are and what this covers
Roost is operated by Castline Dev (“Castline,” “we”). This policy explains how we handle information when you visit roostboard.com, request access, or use the Roost application (the “Service”).
We play two roles. For the information you and your teammates put into the Service (boards, cards, change requests, incidents, files, comments — “Customer Data”), your organization decides what is collected and why, and we process it only to run the Service on its behalf. For account details, access requests, and technical logs, we decide how the data is used and are responsible for it directly.
2. What we collect
Account information
Your email address (used to sign in), your name, your role and module permissions, the organization you belong to, your manager if your admin sets one, and preferences such as the daily-digest toggle, out-of-office delegation, and default board. Sign-in itself is by a one-time code emailed to you; we never store a password.
Customer Data
Whatever you and your teammates enter: board and card content, checklists, labels, attachments, change requests and their approvals and comments, workflows, incidents and their timelines, and post-incident reviews. The Service also records who did what and when (card history, change-request audit trails, incident events). These records can contain personal information about the people your team writes about; your organization is responsible for that content.
Access requests
If you use the request-access form we collect the name, work email, company name and website, expected seat count, modules of interest, and any notes you choose to add.
Technical information
Our hosting provider records standard request logs (IP address, browser user agent, the page or API requested, timestamps, and errors) for security and troubleshooting. We do not use third-party analytics, advertising pixels, or tracking scripts.
Email interaction
We send transactional email only: sign-in codes, invitations, approval and incident notifications, and the optional daily digest. We do not track opens or clicks.
3. How we use it
- To provide the Service: sign you in, show your boards and requests, route approvals, notify responders, and keep audit records that the product is designed around.
- To respond to access requests and set up your workspace.
- To secure the Service: detect abuse, investigate incidents, and enforce our Terms.
- To improve the Service using aggregate, de-identified usage statistics.
- To comply with law and respond to lawful requests.
We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data to train machine-learning models.
Where the GDPR or UK GDPR applies, our legal bases are performance of a contract (running the Service for you), our legitimate interests in securing and improving it, consent where we ask for it, and legal obligations.
6. How long we keep it
- Account information is kept while your account exists. Deactivated users are retained so their history stays attributed; deleted users are scrubbed (see below).
- Customer Data is kept until your organization deletes it or asks us to delete the organization. Change-request audit trails and incident timelines are append-only by design and cannot be edited or removed inside the Service.
- Access requests are kept while we evaluate them and for a reasonable period afterwards so we can follow up, and are deleted sooner on request.
- Request logs are retained by our hosting provider for a short period (typically days to weeks) and then expire.
- Backups expire on the database provider’s normal schedule.
When a user is deleted, we erase their name and email, remove every session, invitation, membership, and notification, and keep an anonymous placeholder so approvals, comments, and incident events they were part of remain intact for their organization’s records.
7. Security
All traffic is encrypted in transit (TLS). Data is encrypted at rest by our database and storage providers. Each organization’s data is isolated at the application layer so members of one organization cannot reach another’s. Attachments are stored privately and served through expiring links. Sign-in codes are short-lived and rate-limited. Administrative actions and workflow changes are written to append-only audit records.
No method of transmission or storage is completely secure. If you believe your account has been compromised, contact [email protected]. If we learn of a breach affecting your personal information we will notify affected organizations without undue delay and as the law requires.
8. Your choices and rights
Depending on where you live you may have the right to access, correct, delete, export, or restrict the use of your personal information, to object to certain processing, and to lodge a complaint with a supervisory authority. We honor these rights regardless of location where we reasonably can.
- Users: your name and email can be seen and corrected by your organization’s admin, who can also deactivate or delete your account. You can turn the daily digest off in the account menu at any time.
- Organizations: administrators can export or ask us to delete the organization’s data by emailing [email protected].
- Anyone: email [email protected] to exercise a right or ask a question. We will verify your identity and respond within 30 days, or sooner if the law requires. We will not discriminate against you for exercising a right.
Because Customer Data belongs to your organization, requests about content your team entered may be referred to that organization, which decides how to respond.
California residents: the categories of personal information we collect are identifiers, professional information, internet activity (request logs), and the content you provide. We do not sell or share personal information as those terms are defined in the CCPA, and we have not done so in the past 12 months.
9. International transfers
The Service is hosted in the United States. If you use it from elsewhere, your information is transferred to and processed in the US. Where required, we rely on standard contractual clauses or other lawful transfer mechanisms, available on request.
10. Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
11. Changes to this policy
We will post updates here with a new effective date and, for material changes, notify your organization’s administrators and ask users to re-accept in the Service. The version number at the top identifies the current text.
12. Contact
Privacy questions and rights requests: [email protected]. Everything else: [email protected].