This policy describes how Lanes handles personal data in accordance with the General Data Protection Regulation (GDPR). We are committed to protecting the privacy and rights of our users and are actively working to align our practices with GDPR requirements.
1. Our Role
Lanes acts as a Data Controller for the personal data of our account holders (your name, email address and account information collected during sign-in).
Lanes does not act as a Data Processor for any code, terminal output, prompts or AI agent interactions from local workspaces. These remain entirely on your local machine and are never transmitted to our servers.
For remote workspaces, Lanes acts as a Data Processor for the issue and session data stored there. This data is held in Supabase with a data center in Europe and logical segregation at workspace level.
For optional integrations you connect (such as GitHub or Linear), Lanes acts neither as Controller nor as Processor of the issue and comment data exchanged with the third party. You authorise the third party directly via OAuth, and that data does not transit our servers. Only OAuth credentials are handled by the Lanes API during the initial handshake and, for Linear, during short-lived access token refresh; refresh tokens are not retained.
For Lanes Forms, you as the form owner determine what respondent data your forms collect and why, so you act as the Data Controller for that data and Lanes acts as your Data Processor, storing and forwarding it on your behalf. Lanes acts as Controller only for the limited technical data it collects to protect the Service: a salted hash of the submitter's IP address and the browser user-agent, used for spam prevention, rate limiting and abuse protection.
2. Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract performance (Article 6(1)(b)): Processing your account data is necessary to provide the Lanes service.
- Legitimate interest (Article 6(1)(f)): We process limited telemetry data (feature usage, performance metrics, crash reports) to maintain and improve service reliability and performance.
- Consent (Article 6(1)(a)): Analytics cookies are only activated with your explicit consent via our cookie banner.
For personal data submitted through Lanes Forms, the form owner determines the lawful basis for collecting it. Lanes relies on legitimate interest (Article 6(1)(f)) for the limited technical data it uses to prevent spam and abuse.
3. What Data We Collect
Account Data (Controller)
When you sign in with Google, we receive and store:
- Your name and email address
- A unique account identifier
We do not store your Google profile photo. It is only displayed in your browser session.
Telemetry and Analytics Data
We collect anonymous telemetry to optimise app performance:
- Feature usage patterns and session duration
- App version and operating system
- Crash reports and error diagnostics
With your consent, we also collect anonymous usage data through Google Analytics 4 using Consent Mode v2. When consent is not granted, no personal data is collected through analytics.
Lanes Forms Data
When someone submits one of your forms, we store the field values in that submission (which you define, and which may include personal data such as names, email addresses and messages), any extra fields submitted, the origin the submission was sent from, and the browser user-agent. We also store a salted, irreversible hash of the submitter's IP address. The raw IP address is never stored. Lanes Forms does not accept file uploads.
What We Do Not Collect
For local workspaces, your session activity is private and confidential to you. The following data stays entirely on your device and is never sent to our servers:
- Source code or repository contents
- Terminal input and output
- Prompts or responses exchanged with AI agents
- API keys or credentials for third-party tools
- File contents opened or modified through the app
- Task names, labels and descriptions
- Project names and workspace configurations
- Issue or comment content read from or written to optional integrations you have connected (such as GitHub or Linear)
For remote workspaces, issue and session data is stored via Supabase for collaboration purposes.
4. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
| Right | How to Exercise |
|---|---|
| Access (Article 15) | Contact us to request a copy of all personal data we hold about you. |
| Rectification (Article 16) | Update your account information through your Google account, which is reflected automatically. |
| Erasure (Article 17) | Contact us to request deletion of your account and associated data. We will process your request within 30 days. |
| Restriction (Article 18) | Contact us to request restricted processing of your data. |
| Portability (Article 20) | Contact us to receive your data in a structured, machine-readable format. |
| Objection (Article 21) | You may object to processing based on legitimate interest by contacting us. |
| Withdraw consent | Withdraw analytics consent at any time via the cookie settings button in the site footer. |
To exercise any of these rights, email us at hello@lanes.sh.
We are actively building self-serve tools for data export and account deletion directly within the dashboard to make exercising these rights easier.
5. Data Security
We implement appropriate technical measures to protect your data:
- All data is transmitted over HTTPS (TLS encryption in transit)
- Data at rest is encrypted via Google Cloud's built-in encryption
- Authentication tokens are validated on every request via Firebase Authentication
- Analytics data collection respects your consent preferences and defaults to denied
6. Data Retention
We apply the following retention periods:
| Data Type | Retention Period |
|---|---|
| Account data | Retained while your account is active; deleted within 30 days of account deletion request |
| Remote workspace data (Supabase) | Retained while remote workspace is active; deleted within 30 days of account deletion |
| Unclaimed Lanes Forms data | Frozen 7 days after the form is created; the form and its submissions are permanently deleted 30 days later |
| Claimed Lanes Forms submissions | Retained until you delete them, then purged within 30 days |
| Telemetry data | Retained in aggregate; cannot be linked to individual users |
| Analytics data | Subject to Google Analytics retention settings (default: 14 months) |
7. Sub-Processors
We use the following third-party services to operate Lanes. Each processes personal data as described:
| Sub-Processor | Purpose | Data Processed |
|---|---|---|
| Firebase Authentication | User sign-in and account profile storage | Name, email, profile photo, authentication tokens |
| Supabase | Remote workspace and Lanes Forms storage | Issue and session data, Lanes Forms submissions |
| Resend | Transactional email and Lanes Forms submission forwarding | Recipient email addresses, and, when forwarding is enabled, form submission content |
| Stripe | Payment processing | Email address, billing plan, usage data |
| Google Analytics 4 | Usage analytics (consent-based) | Anonymous usage data, device type, pages visited |
| Sentry | Crash log capture and error monitoring | Crash reports, error events, anonymous device and app metadata |
8. Cookie Consent
We implement Google Consent Mode v2 with all tracking signals defaulting to denied. Analytics cookies are only activated after you grant explicit consent through our cookie banner. You can review and change your preferences at any time using the cookie settings button in the footer. For full details, see our Cookie Policy.
9. Our Commitment
We take data protection seriously and are continuously improving our practices. Here is what we have in place today and what we are working on:
In place:
- Cookie consent with Google Consent Mode v2 (all signals denied by default)
- Comprehensive Privacy Policy, Terms of Service and Cookie Policy
- Encrypted data storage and transmission
- Minimal data collection (no code, terminal or AI interaction data collected; remote workspace issue and session data stored only when using remote workspaces)
- Anonymous telemetry for performance optimisation only
- Clear sub-processor disclosure
Coming soon:
- Self-serve data export in machine-readable format
- Data Processing Agreement (DPA) for enterprise customers
- Enhanced data breach notification procedures
10. Contact and Complaints
If you have questions about this policy or wish to exercise your rights, contact us at hello@lanes.sh.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities can be found at edpb.europa.eu.