Privacy Policy
This privacy policy outlines how Just Another Power-Up, owned and operated by Rokas Ulickas through MB “Kodas nuo nulio”, registered in Lithuania with company code 305146439 (“we”, “us”, or “our”), collects and uses your personal data when you use our website and our Trello Power-Ups: Just Another Label Sync and Email Inbox for Trello (together, the “Services”).
1. Our commitment to your privacy
Our core philosophy is built on the GDPR principles of data minimization and purpose limitation. We collect only the essential information required for specific, stated purposes to provide you with a functional and reliable service. We believe that a clear understanding of what information we collect, why we collect it, and how it is used is fundamental to building trust. This approach is consistent with regulatory requirements, such as the EU's General Data Protection Regulation (GDPR), which mandate that information related to data processing be provided in a concise, transparent, and easily accessible format, using clear and plain language.
2. Data we collect and how we use it
We never store the contents of your Trello cards — including titles, descriptions, comments, or attachments — on our servers, and we never store the contents of your emails. The information we do collect is strictly limited to the following categories:
| Data type | Purpose of collection |
|---|---|
| Trello member IDs, workspace IDs, board IDs, and board names | To associate your Trello account with our Power-Ups, enable core service functionality (such as syncing labels between boards or creating cards from emails), manage your subscription, and facilitate customer support. |
| Trello API token | Granted by you via Trello's OAuth flow and used only to perform actions you authorize (read boards, sync labels, create cards, etc.). The token is stored in our database so that automatic, webhook-triggered functionality can run even while you are not actively using the Power-Up. Using Disconnect Account revokes the token with Trello so it can no longer be used; you may also request erasure of the stored record by contacting us. |
| Google account connection (Email Inbox only) | When you connect Gmail to Email Inbox, we receive your email address and an OAuth grant used to show your mail inside Trello, send the replies you write, and archive, flag or mark messages when you ask. The connection credentials are stored securely and used only for these features. See section 3 for the full Gmail data commitments. |
| Email-to-card references (Email Inbox only) | Turning an email into a card stores a reference (link) to that email and the list of people you have chosen to share it with — never the email's contents, which are loaded from Gmail when an authorized person opens the card. |
| Automation and sync configuration | Trello webhook identifiers created on your behalf, your configured source and target boards and sync preferences (Label Sync), and your Gmail search queries and destination lists (Email Inbox automations), to run the automatic features you set up. Some client-side display preferences are kept in Trello's private member storage. |
| Email address, Stripe customer ID, and subscription ID | To process subscription payments, manage your account, send billing-related emails (trial reminders, payment confirmations, failed payment notices), and prevent fraudulent transactions. We use a third-party payment processor and do not store credit card numbers on our servers. |
When you add one of our Power-Ups to your Trello board, we receive a unique, alphanumeric Trello member ID along with board and workspace identifiers. This data is essential for the Power-Up to function as intended.
For subscription payments, we use the third-party payment processor Stripe. When you provide your payment details, that information is sent directly to Stripe for processing. Stripe securely stores and manages your full payment information; it is never stored on our servers.
We do not use website analytics, advertising trackers, or cookies for tracking, and we do not collect your name, avatar, username, or any Trello or Gmail content beyond what is strictly needed to perform the Power-Ups' operations.
3. How we use your Gmail data (Email Inbox)
Email Inbox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We use your Gmail access only to run the features you ask for — showing your mail inside Trello, sending the replies you write, tidying messages (archive, spam, flags) when you ask, and creating the cards and automations you set up. We never sell your Gmail data, never use it for advertising, and never use it to train AI models. Your replies are sent through your own Gmail account — we do not operate our own mail service.
Who can see an email on a card: an email you turn into a card is visible only to you by default — its contents sit in a private part of the card, not the description, so other board members can't see it or even know it's there. You can grant specific teammates read or read + write access per card, and revoke that at any time.
You can disconnect a Gmail account at any time in the Power-Up's settings, which removes its connection immediately. You can also revoke access from your Google account's security settings.
4. Our legal basis for processing your data
Under the GDPR, every instance of processing personal data must have a clear and established legal justification. We rely on the following lawful bases for our data processing activities:
Our primary legal basis for processing your Trello member ID, Google account connection, and payment information is contractual necessity. Processing this information is essential to deliver the subscription service you purchase from us. For example, without your Trello ID, we cannot link the Power-Ups to your account, and without processing your payment information, we cannot deliver the paid subscription service.
We may also process limited operational data — such as webhook delivery records and error logs — for our legitimate interests in keeping the service reliable and secure, detecting abuse, and diagnosing issues, in a form that does not build profiles of individual users.
5. Data sharing and disclosure
A core aspect of our privacy commitment is that we do not sell or share your personal information with third parties for their marketing or advertising purposes. Your data is not a product; it is a tool used solely to provide our service to you.
We only share your information with trusted third-party service providers when it is necessary for the operation of our business. These service providers act as data processors on our behalf and are bound by their own data privacy obligations:
- Trello / Atlassian — hosts the Power-Ups and provides the Trello API. See Atlassian's privacy policy.
- Google — the Gmail account you connect to Email Inbox. See Google's privacy policy.
- Stripe — processes subscription payments. We never see your payment card details. See Stripe's privacy policy.
- Amazon Web Services (AWS SES) — delivers transactional email. See AWS privacy notice.
In addition, we may be required to disclose your personal information in limited, legally mandated circumstances. This includes responding to valid court orders, subpoenas, or other lawful government requests. We may also disclose information to protect our rights, property, or safety, or those of our users, as permitted by law.
6. Your privacy rights (GDPR & CCPA)
Both the GDPR and CCPA provide you with significant rights regarding your personal information. To exercise any of the rights detailed below, please contact us at the email address provided in the “Contact us” section.
- Right to Know / Access: You have the right to request information about the personal data we have collected about you.
- Right to Deletion: You have the right to request the deletion of your personal data from our systems.
- Right to Correction: You have the right to request the correction of any inaccurate personal information we hold about you.
- Right to Data Portability (GDPR): You have the right to request a copy of your personal data in a machine-readable format.
- Right to Object & Restriction of Processing (GDPR): You have the right to object to our processing of your personal data under certain conditions.
- Right to Withdraw Consent and to lodge a complaint with a supervisory authority (in Lithuania, the State Data Protection Inspectorate).
Clicking Disconnect Account in a Power-Up's settings revokes your Trello token (and, for Email Inbox, disconnecting a Gmail account removes that connection); to have your stored records fully erased, email us and we will delete them. As we do not sell your personal information or collect sensitive personal data, certain rights under the CCPA (such as the Right to Opt-Out of Sale) are not applicable to our services. We will not discriminate against you for exercising any of your privacy rights.
7. Data storage and security
Data, including your Trello API token, Google account connection, and configuration, is stored in a PostgreSQL database hosted on infrastructure we operate in the European Union. We use industry-standard encryption (TLS 1.2+) for data in transit and standard database access controls, and connection credentials are stored encrypted. We never store the contents of your emails — only a reference that loads them from Gmail when an authorized person opens the card. Access to production data is restricted to the operator of the Services.
8. Data retention
We retain your personal data only for as long as is necessary to provide our services and for a reasonable period thereafter to comply with our legal and financial obligations.
- Subscription records are retained for the duration of your active subscription, and for up to 7 years afterwards to comply with applicable tax and accounting laws.
- Your Trello token, Google connection, webhook IDs, and configuration (sync groups, automations, email-to-card references) are retained for as long as you use the Power-Ups, and are deleted on request.
Once the applicable retention period has passed, the data will be deleted.
9. International transfers
Our primary infrastructure is located in the European Union. Some third-party providers (Stripe, AWS, Google) may process data in other regions, including the United States, under standard contractual clauses or equivalent safeguards.
10. Children
The Services are not intended for anyone under 16. We do not knowingly collect information from children.
11. Contact us
For any questions about this privacy policy or to exercise your privacy rights, please contact our support at rokas@justanotherpowerup.com. When submitting a request, please provide sufficient information to allow us to verify your identity and understand the nature of your request.
12. Changes to this policy
We may update this privacy policy from time to time to reflect changes in our practices or to comply with new legal requirements. When we make changes, we will post the updated policy on this page with a revised effective date. Material changes will be communicated via email to subscribed users where applicable.
just another power-up