G KanbanNo One Needs Another Kanban, OK?

Security

How G Kanban protects your data. This describes current practices; items marked Planned are not yet available.

The short version
  • Local-first. Your boards live in your browser and never leave your device unless you sign in and turn on sync.
  • Your data, your account only. Cloud data is isolated per account and only ever readable/writable by you.
  • EU-hosted when synced (Frankfurt, Germany). No trackers, no ads, no data sales.
  • You can leave anytime — one-click JSON export, and self-serve deletion of your account or this device.

1. Local-first by default

By default, everything you create stays in your browser's local storage on your own device. With no account and no sync, G Kanban makes no network calls for your data at all — there is nothing for us to see, lose, or leak.

2. Encryption in transit

The app and the standalone pages are served over HTTPS (TLS). When sync is enabled, all traffic between your browser and our cloud backend travels over encrypted connections.

3. Authentication

Sign-in is via OAuth with Google or GitHub, handled by our authentication provider (Supabase Auth). We never see or store your password — only your email, name, avatar, and a provider account ID, used to create and secure your account.

4. Access control & account isolation

5. Hosting & data location

When you enable sync, your data is stored with Supabase in the EU (Frankfurt, Germany). The app and static pages are delivered by Cloudflare's global edge network. We chose EU hosting deliberately for its strong data-protection regime.

6. Application hardening

7. Payments

Billing for paid plans is handled by our Merchant of Record, Polar. Card and payment details are entered on the provider's PCI-compliant checkout — we never receive or store your card data.

8. Your data is portable and deletable

9. End-to-end encrypted backup Planned

A future "sovereignty" option will let you encrypt your cloud backup with a passphrase only you hold, so even we cannot read it. Until it ships, cloud data is protected by the controls above but is readable by the service to provide sync.

10. Sub-processors

We rely on a small set of vetted providers: Supabase (database & authentication, EU), Cloudflare (hosting & CDN), the OAuth providers you choose (Google / GitHub), and Polar (payments, Merchant of Record). See the Privacy Policy for details.

11. Reporting a vulnerability

Found a security issue? Please email support@gkanban.com with the details. We welcome responsible disclosure and will work with you to resolve it.

セキュリティ

G Kanbanがデータをどのように保護するか。現在の運用について説明しています。予定と記載された項目は現時点では未提供です。

かんたんに言うと
  • ローカルファースト。ボードはブラウザ内に保存され、サインインして同期を有効にしない限りデバイスから送信されません。
  • データはあなたのアカウントだけのもの。クラウドデータはアカウントごとに分離され、読み書きできるのは本人のみです。
  • 同期時はEU内(ドイツ・フランクフルト)に保存。トラッキングなし・広告なし・データ販売なし。
  • いつでも持ち出し可能——ワンクリックのJSONエクスポートと、アカウント/デバイスのセルフ削除。

1. 既定でローカルファースト

既定では、作成した内容はすべてお使いのデバイスのブラウザ内ローカルストレージに保存されます。アカウントも同期もない状態では、G Kanbanはデータに関するネットワーク通信を一切行いません。当社が見る・失う・漏らす対象がそもそも存在しません。

2. 通信の暗号化

アプリおよび各ページはHTTPS(TLS)で配信されます。同期を有効にした場合、ブラウザとクラウド間の通信はすべて暗号化された接続を経由します。

3. 認証

サインインはGoogleまたはGitHubによるOAuthで、認証基盤(Supabase Auth)が処理します。当社がパスワードを見る・保存することはありません。取得するのはメールアドレス・氏名・アバター・プロバイダのアカウントIDのみで、アカウントの作成と保護にのみ使用します。

4. アクセス制御とアカウント分離

5. ホスティングとデータの所在

同期を有効にすると、データはSupabaseEU(ドイツ・フランクフルト)に保存されます。アプリと各ページはCloudflareのグローバルエッジネットワークで配信されます。強固なデータ保護法制を理由にEUホスティングを意図的に選択しています。

6. アプリケーションの堅牢化

7. 決済

有料プランの決済は、当社のMerchant of RecordであるPolarが処理します。カード情報は同社のPCI準拠の決済画面で入力され、当社がカード情報を受け取る・保存することはありません

8. データは持ち出し・削除が可能

9. エンドツーエンド暗号化バックアップ 予定

将来の「主権(ソブリンティ)」オプションでは、本人だけが保持するパスフレーズでクラウドバックアップを暗号化でき、当社でも読み取れなくなります。提供開始までは、クラウドデータは上記の対策で保護されますが、同期提供のためサービス側で読み取り可能です。

10. 副処理者(サブプロセッサー)

厳選した少数の事業者を利用します:Supabase(データベース・認証、EU)、Cloudflare(ホスティング・CDN)、選択したOAuthプロバイダ(Google/GitHub)、そしてPolar(決済・Merchant of Record)。詳細はプライバシーポリシーをご覧ください。

11. 脆弱性の報告

セキュリティ上の問題を発見された場合は、support@gkanban.com まで詳細をお送りください。責任ある開示を歓迎し、解決に向けて協力いたします。