Privacy Policy

Last updated: August 9, 2026

This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.

We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to Complexus LLC.
  • Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
  • Country refers to: Delaware, United States
  • Device means any device that can access the Service such as a computer, a cellphone or a digital tablet.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to FortyOne, the project management platform provided by Complexus LLC.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service or to assist the Company in analyzing how the Service is used.
  • Third-party Social Media Service refers to any website or any social network website through which a User can log in or create an account to use the Service.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
  • You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Company name and job title
  • Profile picture (optional)

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.

Information from Third-Party Social Media Services

The Company allows You to create an account and log in to use the Service through the following Third-party Social Media Services:

  • Google

If You decide to register through or otherwise grant us access to a Third-Party Social Media Service, We may collect Personal data that is already associated with Your Third-Party Social Media Service's account, such as Your name, Your email address, Your activities or Your contact list associated with that account.

Connected Services and Integrations

You may choose to connect FortyOne to third-party services. We access and use data from a connected service only after an authorized user grants the requested permissions and only to provide, secure, support, and improve the user-facing integration. We do not sell connected-service data or use it for advertising.

Slack

When a workspace administrator connects Slack, We may collect and store Slack workspace and installation identifiers, workspace name and domain, authorized scopes, encrypted access credentials, channel identifiers and names, channel privacy and membership status, and identifiers used to link a Slack user to a FortyOne account.

We process message content and related metadata when a person deliberately uses a supported FortyOne feature, including the /fortyone command, the Create a story message shortcut, a direct message or mention to Maya, a reply in a subscribed FortyOne thread, or a shared FortyOne link. Slack's event subscriptions may deliver unrelated message events to Our endpoint; FortyOne rejects unsupported root messages, bot messages, edits, and unsubscribed thread messages before storing their content in the durable message system.

We use Slack data to create and link project work, answer requested questions, maintain short-term thread context, provide permission-aware story previews, synchronize supported request discussions, deliver replies, prevent duplicate processing, and diagnose integration failures. FortyOne does not use Slack API data to train general-purpose artificial intelligence models.

Accepted inbound Slack payloads are encrypted at rest. Conversation and assistant message content in the messaging system is retained for up to 30 days for short-term continuity and operational recovery. Installation, linked-account, and channel metadata is retained while the integration is connected. When an administrator disconnects Slack, We revoke or remove the active credentials and associated connection records. Limited security, abuse-prevention, diagnostic, backup, and legal records may be retained for as long as reasonably necessary for those purposes.

Google Calendar

When You connect Google Calendar, We may collect and store Your Google account identifier, connected email address, timezone, authorized scopes, encrypted OAuth credentials, primary-calendar availability, and synchronization status. If You grant event-detail access, We may also cache event titles, descriptions, locations, meeting links, organizers, attendees, visibility, and start and end times for Your primary calendar. Private and confidential events are stored as Busy without their descriptive details.

We use Google Calendar data to show Your meetings beside FortyOne work, calculate availability, avoid obvious schedule conflicts, and provide schedule-aware planning features. Detailed calendar events are visible only to the connected calendar owner. Teammates, managers, Maya, and capacity-planning features receive title-free availability windows rather than event content. The integration is read-only and does not create, edit, or delete Google Calendar events.

FortyOne keeps a rolling calendar snapshot that currently covers seven days before and ninety days after the sync date. When You disconnect Google Calendar, We clear the connection credentials and scopes and delete the cached calendar events and availability windows for that connection. FortyOne's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

GitHub

When a workspace administrator installs the FortyOne GitHub App, We may collect and store installation and organization identifiers, account name and avatar, the repositories selected during installation, repository metadata, granted permissions, webhook subscriptions, and identifiers used to associate a GitHub user with a FortyOne account.

For connected repositories, We process the issue, comment, branch, commit, pull request, review, check, label, assignee, and repository event data needed to synchronize linked work, show development progress, and run the workflow rules configured by the workspace. GitHub displays the permissions requested by the FortyOne GitHub App and allows the installer to choose which repositories the app may access.

Connection metadata is retained while the GitHub App is installed or while needed to preserve the integrity of linked workspace records. Content copied into FortyOne stories, comments, activity history, or audit records may remain after the GitHub App is disconnected so the workspace does not lose its project history. An authorized workspace administrator can unlink a repository or uninstall the GitHub App, and You may contact Us to request deletion as described below.

The third-party services You connect process information under their own terms and privacy policies. You should review the permissions shown during authorization and the applicable provider policies before connecting an integration.

Tracking Technologies and Cookies

We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:

  • Cookies or Browser Cookies. A cookie is a small file placed on Your Device. You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
  • Web Beacons. Certain sections of our Service and our emails may contain small electronic files known as web beacons that permit the Company to count users who have visited those pages or opened an email and for other related website statistics.

We use both Session and Persistent Cookies for the purposes set out below:

  • Necessary / Essential Cookies

    • Type: Session Cookies
    • Purpose: These Cookies are essential to provide You with services available through the Website and to enable You to use some of its features.
  • Cookies Policy / Notice Acceptance Cookies

    • Type: Persistent Cookies
    • Purpose: These Cookies identify if users have accepted the use of cookies on the Website.
  • Functionality Cookies

    • Type: Persistent Cookies
    • Purpose: These Cookies allow us to remember choices You make when You use the Website, such as remembering your login details or language preference.

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service
  • To manage Your Account
  • For the performance of a contract
  • To contact You
  • To provide You with news, special offers and general information
  • To manage Your requests
  • For business transfers
  • For other purposes: We may use Your information for other purposes, such as data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Service.

Email Communication

After signing up, we may send you onboarding and support emails to help you get started and use FortyOne. These emails are necessary for providing our service and do not require additional consent.

You may also choose to receive product updates, newsletters, and promotional offers by opting in during signup. We will only send marketing or promotional emails to users who have provided explicit consent. You can unsubscribe from marketing emails at any time by following the link in the email or contacting us.

Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.

Delete Your Personal Data

You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.

You may update, amend, or delete Your information at any time by signing in to Your Account, if you have one, and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred.

Law enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities.

Other legal requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of Users of the Service or the public
  • Protect against legal liability

Security of Your Personal Data

The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.

Children's Privacy

Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us.

Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.

Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.

We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, You can contact us:

By email: info@complexus.app

For data protection inquiries: Data Protection Officer: hello@complexus.tech

For general support: Support: hello@complexus.tech