Privacy Policy
This privacy policy outlines how Just Another Power-Up, owned and operated by Rokas Ulickas through MB “Kodas nuo nulio”, registered in Lithuania with company code 305146439 (“we”, “us”, or “our”), collects and uses your personal data when you use our website and our Trello Power-Ups: Just Another Label Sync, Email Inbox for Trello and Time Tracking for Trello (together, the “Services”).
1. Our commitment to your privacy
Our core philosophy is built on the GDPR principles of data minimization and purpose limitation. We collect only the essential information required for specific, stated purposes to provide you with a functional and reliable service. We believe that a clear understanding of what information we collect, why we collect it, and how it is used is fundamental to building trust. This approach is consistent with regulatory requirements, such as the EU's General Data Protection Regulation (GDPR), which mandate that information related to data processing be provided in a concise, transparent, and easily accessible format, using clear and plain language.
2. Data we collect and how we use it
We never store the contents of your Trello cards — including descriptions, comments, or attachments — on our servers, and we do not keep a copy of your mailbox: an email shown on a card or in the Power-Up is loaded from Gmail each time, from a stored reference. There are five narrow exceptions, each listed in the table below and created only by something you do: a message you schedule to send later (held until it is sent), files you attach to an outgoing message (held until it is sent or cancelled), an AI summary you ask for, the card title recorded for reporting, which is usually the email's subject line, and — when you track time — the name of the card and the list the entry belongs to, so a report stays readable after a card is renamed or moved. The information we collect is strictly limited to the following categories:
| Data type | Purpose of collection |
|---|---|
| Trello member IDs, workspace IDs, board IDs, and board names | To associate your Trello account with our Power-Ups, enable core service functionality (such as syncing labels between boards or creating cards from emails), manage your subscription, and facilitate customer support. |
| Trello API token | Granted by you via Trello's OAuth flow and used only to perform actions you authorize (read boards, sync labels, create cards, etc.). The token is stored in our database so that automatic, webhook-triggered functionality can run even while you are not actively using the Power-Up. Using Disconnect Account revokes the token with Trello so it can no longer be used; you may also request erasure of the stored record by contacting us. |
| Google account connection (Email Inbox only) | When you connect Gmail to Email Inbox, we receive your email address and an OAuth grant used to show your mail inside Trello, send the replies you write, and archive, flag or mark messages when you ask. The connection credentials are stored securely and used only for these features. See section 3 for the full Gmail data commitments. |
| Email-to-card references (Email Inbox only) | Turning an email into a card stores a reference (link) to that email, the list of people you have chosen to share it with and what they may do (read, reply, or compose), and the card's own state — whether it is snoozed until a chosen time, and whether you marked it as needing no reply. The email's contents are not stored; they are loaded from Gmail when an authorized person opens the card. |
| Messages you schedule to send later (Email Inbox only) | Choosing “send later” stores the message you wrote — recipients, subject, body and any files you attached — so that it can be sent at the time you picked without your browser being open. Attached files are deleted as soon as the message is sent or cancelled, and unused ones are removed automatically after 48 hours. |
| AI drafts and thread summaries (Email Inbox only) | When you press “Suggest reply” or ask for a summary, the relevant part of that email thread is sent to Google's Gemini API to produce the text, and the resulting summary is stored so the same recap is shown on the card and in the reader. This happens only when you ask; nothing is drafted, summarized or sent on its own. See section 3. |
| Contact suggestions (Email Inbox only) | The names and email addresses of people your connected mailbox has written to or heard from, taken from the headers of mail the Power-Up already loads for you, so that addressing a new message can offer suggestions. No additional Google permission is used to obtain them, and they are never used to contact anyone. |
| Text you write into the Power-Up (Email Inbox only) | Your reply templates, the auto-reply message you configure, and the company context and reply guidelines you give the AI are stored as part of your configuration, so they are available on every board and mailbox you use. |
| Time entries (Time Tracking only) | When you start a timer or add time by hand, we record who tracked it, the card, list and board it belongs to, the date and duration, and any note you typed. The name of the card and of the list are stored alongside the identifiers so that a report you run months later still reads correctly after a card has been renamed, moved or archived. This is the record the reports, the timesheet and the CSV export are built from. |
| Estimates and workspace settings (Time Tracking only) | An estimate you set on a card, and the workspace's own preferences — time format, date format, first day of the week, CSV separator, and how long a forgotten timer may run before it is closed automatically. |
| Your timezone (Time Tracking only) | Read once from your browser's own setting so that a day and a week start when they start for you, rather than asking you to pick from a list. It is used for nothing else. |
| Reporting data (Email Inbox only) | For each conversation turned into a card: the card, board and list identifiers, the list's name, the card's title as it was created (which is usually the email's subject line), the Trello member who replied, and the times the first message arrived, the first reply was sent, and the card was archived. This is what the Reports tab is built from; it contains no message bodies. |
| Automation and sync configuration | Trello webhook identifiers created on your behalf, your configured source and target boards and sync preferences (Label Sync), and your Gmail search queries and destination lists (Email Inbox automations), to run the automatic features you set up. Some client-side display preferences are kept in Trello's private member storage. |
| Email address, Stripe customer ID, and subscription ID | To process subscription payments, manage your account, send billing-related emails (trial reminders, payment confirmations, failed payment notices), and prevent fraudulent transactions. We use a third-party payment processor and do not store credit card numbers on our servers. |
| Product usage events and feedback | Records of which features were used and when (for example “a card was created” or “a reply was sent”), stored with your Trello member and board identifiers so we can see whether the Power-Ups work as intended. They never contain email or card content. These events are kept in our own database and also sent to PostHog, our product-analytics processor, on servers in the European Union (section 5). If you send feedback through the Power-Up, we store your message and, if you provide it, an address to reply to. |
When you add one of our Power-Ups to your Trello board, we receive a unique, alphanumeric Trello member ID along with board and workspace identifiers. This data is essential for the Power-Up to function as intended.
For subscription payments, we use the third-party payment processor Stripe. When you provide your payment details, that information is sent directly to Stripe for processing. Stripe securely stores and manages your full payment information; it is never stored on our servers.
We do not use advertising trackers or tracking cookies, and we do not collect your name, avatar, username, or any Trello or Gmail content beyond what is strictly needed to perform the Power-Ups' operations. The usage events described above are product analytics: they tell us which features are used, they carry your Trello member and board identifiers but never message or card content, and they are processed by PostHog in the European Union on our behalf. They are never sold, never shared for marketing, and never used to build advertising profiles.
3. How we use your Gmail data (Email Inbox)
Email Inbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
What we access. With your permission, and only in the mailbox you connect, the Power-Up reads: message headers (sender, recipients, subject, date), message bodies, attachments, labels and thread identifiers, and your account's own email address. It writes in two ways only: it changes three labels — UNREAD when you open a conversation, INBOX when you archive one, SPAM when you mark one as spam — and it sends messages you have written. It never deletes a message, never moves one to Trash, never applies your own labels, and never changes Gmail settings or filters.
What we keep. Message bodies and attachments are never stored on our servers. What we derive from your mail and do store is limited to: a reference (identifier) to the email a card was made from, a thread summary if you asked for one, the names and email addresses of people your mailbox has corresponded with (so the composer can suggest addresses), the card's title as created (usually the subject line), and the timestamps the Reports tab is built from. Section 2 lists each of these with its purpose, and section 8 says how long each is kept.
We use your Gmail access only to run the features you ask for — showing your mail inside Trello, sending the replies and messages you write, tidying messages (archive, spam, flags) when you ask, and creating the cards and automations you set up. We never sell your Gmail data, never use it for advertising, and never use it to train any AI model of ours. Your messages are sent through your own Gmail account — we do not operate our own mail service.
Messages sent without you pressing send: the Power-Up sends mail on its own in exactly two cases, both of which you switch on yourself: a message you scheduled with “send later”, and the auto-reply template you configured for a mailbox (first contact only, after the delay you set, and only to the senders you allow). You can cancel a scheduled message and turn auto-reply off at any time.
AI drafting and summaries: when you press “Suggest reply” or ask for a thread summary, we send the relevant messages from that thread — together with the company context and reply guidelines you configured — to Google's Gemini API, which generates the text and returns it to us. Google acts as our processor for that call; its handling of the content is governed by the Gemini API terms. We use the Gemini API on a paid tier, under which Google does not use the prompts we send or the responses it returns to improve or train its products, and does not have them reviewed by humans for that purpose. Google retains this content for a limited period solely to detect abuse of its API, as described in those terms. Your mail is never used to develop, improve or train any AI or ML model — ours, Google's, or anyone else's. This happens only on your explicit request, never in the background and never for automations or auto-replies. The generated draft is shown to you to edit and is not stored; a generated summary is stored so the same recap appears on the card and in the reader, and it is deleted when you disconnect that mailbox.
Who can see an email on a card: an email you turn into a card is visible only to you by default — its contents sit in a private part of the card, not the description, so other board members can't see it or even know it's there. You can open it up per card, or for a whole mailbox, to specific teammates or to the board, and choose whether they may only read it, also reply to it, or also compose new mail from that mailbox. Any of this can be revoked at any time.
You can disconnect a Gmail account at any time in the Power-Up's settings. This removes its connection immediately, along with the AI summaries built from that mailbox and any permission you gave others to send from it; you can also choose to delete its automations, pending scheduled messages and auto-reply settings in the same step. You can also revoke access from your Google account's security settings.
4. Our legal basis for processing your data
Under the GDPR, every instance of processing personal data must have a clear and established legal justification. We rely on the following lawful bases for our data processing activities:
Our primary legal basis for processing your Trello member ID, Google account connection, and payment information is contractual necessity. Processing this information is essential to deliver the subscription service you purchase from us. For example, without your Trello ID, we cannot link the Power-Ups to your account, and without processing your payment information, we cannot deliver the paid subscription service.
We may also process limited operational data — such as webhook delivery records, error logs, and the usage events described in section 2 — for our legitimate interests in keeping the service reliable and secure, detecting abuse, diagnosing issues, and understanding which features are actually used, in a form that does not build profiles of individual users.
5. Data sharing and disclosure
A core aspect of our privacy commitment is that we do not sell or share your personal information with third parties for their marketing or advertising purposes. Your data is not a product; it is a tool used solely to provide our service to you.
We only share your information with trusted third-party service providers when it is necessary for the operation of our business. These service providers act as data processors on our behalf and are bound by their own data privacy obligations:
- Trello / Atlassian — hosts the Power-Ups and provides the Trello API. See Atlassian's privacy policy.
- Google — the Gmail account you connect to Email Inbox, and the Gemini API that generates a reply draft or thread summary when you ask for one (section 3). See Google's privacy policy.
- Stripe — processes subscription payments. We never see your payment card details. See Stripe's privacy policy.
- PostHog — product analytics, hosted in the European Union. Receives the usage events described in section 2 (feature used, Trello member and board identifiers), never email or card content. See PostHog’s privacy policy.
- Amazon Web Services (AWS SES) — delivers transactional email. See AWS privacy notice.
No Gmail content leaves us except to Google. Message headers, bodies and attachments are sent only between your mailbox and the Power-Up, and — when you press “Suggest reply” or ask for a summary — to Google's Gemini API. Stripe, PostHog and AWS never receive Gmail content of any kind, raw or derived; Stripe receives billing identifiers, PostHog receives feature-usage events with Trello identifiers only, and AWS delivers transactional email we send you.
In addition, we may be required to disclose your personal information in limited, legally mandated circumstances. This includes responding to valid court orders, subpoenas, or other lawful government requests. We may also disclose information to protect our rights, property, or safety, or those of our users, as permitted by law.
6. Your privacy rights (GDPR & CCPA)
Both the GDPR and CCPA provide you with significant rights regarding your personal information. To exercise any of the rights detailed below, please contact us at the email address provided in the “Contact us” section.
- Right to Know / Access: You have the right to request information about the personal data we have collected about you.
- Right to Deletion: You have the right to request the deletion of your personal data from our systems.
- Right to Correction: You have the right to request the correction of any inaccurate personal information we hold about you.
- Right to Data Portability (GDPR): You have the right to request a copy of your personal data in a machine-readable format.
- Right to Object & Restriction of Processing (GDPR): You have the right to object to our processing of your personal data under certain conditions.
- Right to Withdraw Consent and to lodge a complaint with a supervisory authority (in Lithuania, the State Data Protection Inspectorate).
Clicking Disconnect Account in a Power-Up's settings revokes your Trello token (and, for Email Inbox, disconnecting a Gmail account removes that connection); to have your stored records fully erased, email us and we will delete them. As we do not sell your personal information or collect sensitive personal data, certain rights under the CCPA (such as the Right to Opt-Out of Sale) are not applicable to our services. We will not discriminate against you for exercising any of your privacy rights.
7. Data storage and security
Data, including your Trello API token, Google account connection, and configuration, is stored in a PostgreSQL database hosted on infrastructure we operate in the European Union. We use industry-standard encryption (TLS 1.2+) for data in transit and standard database access controls, and connection credentials — including Gmail refresh tokens — are encrypted at rest with AES-256-GCM, under a key held outside the database. An email on a card is not stored — we keep only a reference that loads it from Gmail when an authorized person opens the card — and the five exceptions named in section 2 (a scheduled message and its attachments, an AI summary you asked for, the card title kept for reporting, and the card and list names kept on a time entry) live in the same database, under the same controls — as do time entries, estimates and workspace settings. Access to production data is restricted to the operator of the Services.
8. Data retention
We retain your personal data only for as long as is necessary to provide our services and for a reasonable period thereafter to comply with our legal and financial obligations.
- Subscription records are retained for the duration of your active subscription, and for up to 7 years afterwards to comply with applicable tax and accounting laws.
- Your Trello token, Google connection, webhook IDs, and configuration (sync groups, automations, email-to-card references, templates, auto-reply and AI settings, contact suggestions) are retained for as long as you use the Power-Ups, and are deleted on request.
- Files attached to an outgoing message are deleted as soon as that message is sent or cancelled; anything staged and then abandoned is removed automatically after 48 hours.
- A scheduled message is kept until it sends or you cancel it. Its record, including the text you wrote, then remains until you disconnect the mailbox with the delete option or ask us to erase it.
- AI summaries are kept until the mailbox they were built from is disconnected, or until you ask us to erase them.
- Time entries, estimates, Time Tracking settings and the timezone read from your browser are kept for as long as the workspace uses the Power-Up, so that historical reports and timesheets stay accurate, and are deleted on request. Ending a subscription does not delete them — the records stay readable and exportable — so ask us if you want them erased.
- Reporting data and usage events are kept while you use the Power-Up so that historical reports stay accurate, and are deleted on request. The copy of the usage events held by PostHog follows that provider’s own retention, and is deleted on request too.
Once the applicable retention period has passed, the data will be deleted.
9. International transfers
Our primary infrastructure is located in the European Union. Some third-party providers (Stripe, AWS, Google) may process data in other regions, including the United States, under standard contractual clauses or equivalent safeguards.
10. Children
The Services are not intended for anyone under 16. We do not knowingly collect information from children.
11. Contact us
For any questions about this privacy policy or to exercise your privacy rights, please contact our support at rokas@justanotherpowerup.com. When submitting a request, please provide sufficient information to allow us to verify your identity and understand the nature of your request.
12. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or to comply with new legal requirements. When we make changes, we will post the updated policy on this page with a revised effective date. Material changes will be communicated via email to subscribed users where applicable.
just another power-up