⚖ Not legal advice.
This guide explains the protections we've built into Vitae Dux and the rights we believe apply to you under current U.S. federal and state law as of July 2026. The Service is intended for businesses located in the United States. It is educational, not legal advice. Privacy law changes constantly. If you need a compliance decision for your own business, consult a licensed privacy attorney. For our binding legal terms, see our Privacy Policy and Terms of Service.
What's in this guide
- Our Security & Privacy Commitments — what we built to protect you
- Your Rights as a Vitae Dux User — what you can do, anytime
- U.S. State Privacy Laws — the 19 comprehensive laws by 2026
- U.S. Federal Laws — FTC Act, COPPA, GLBA, HIPAA scope
- International Users — our U.S.-only scope
- How to Exercise Your Rights — concrete steps
- Mutual Protections — how the law protects you and us
- Contact & Questions
1. Our Security & Privacy Commitments
Vitae Dux is a leadership accountability tool. Your workspace contains tasks, projects, goals, comments — sometimes sensitive operational and people-related data. We treat it accordingly. Here are the concrete technical controls we've built, not promises:
🔒 Defense-in-depth architecture
- Row-Level Security (RLS) on every multi-tenant table. Our database physically cannot return your data to another customer's session — the rule is enforced by Postgres itself, not by application code that can be bypassed. We verified this with three separate isolation tests in May 2026: anonymous attackers blocked at the function permission layer, cross-org reads return zero rows, cross-org writes are rejected with policy violation.
- Organization-scoped queries. Every read and write is filtered by the
org_idderived from your authenticated session token. There is no API endpoint that accepts an arbitraryorg_idas input — making it cryptographically impossible to access another organization's data even with full client-side access to our code. - Owner + Admin gating on destructive actions. Reset and delete operations check your
memberships.roleat the database layer. Workers and viewers are blocked. Account deletion is owner-only — admins cannot drop the workspace. - Type-to-confirm UX. Every irreversible action requires you to type the exact word ("RESET" or "DELETE") before the button enables. Misclicks alone cannot destroy your data.
- Automatic pre-destruction snapshots. Before any workspace reset, we create a Restore Point holding the complete state. You can roll back within minutes. Restore Points are preserved even by the wipe itself.
- Defense-in-depth on auth tokens. Our bootstrap is rate-limit aware: if Supabase Auth throttles a refresh, we hold the page open and retry instead of bouncing you to the login screen.
📂 Data portability — your data is yours
- One-click JSON export. From About → Data → 📥 Download backup, you get a complete, re-importable file of your workspace. No format lock-in.
- Spreadsheet export for tasks, projects, goals, and team data via the Export workflow — readable in Excel, Google Sheets, Numbers.
- Restore Points auto-save every 10 minutes and before any bulk operation. Up to the storage limit, you can roll the entire workspace back to any prior state.
🛡 What we never do
- ✗Sell your data to advertisers or data brokers.
- ✗Use your workspace content to train AI models.
- ✗Email your workspace data to anyone other than you.
- ✗Share your data with team members outside your organization.
- ✗Retain deleted accounts longer than disclosed in our Privacy Policy.
🔐 Hosting & encryption
- Application: hosted on Vercel with automatic TLS 1.3, static-site sandboxing, and Cloudflare WAF protection in front of the application layer.
- Database: Supabase Postgres with encryption at rest (AES-256) and in transit (TLS 1.3). Daily automatic backups retained for 7 days at the infrastructure level, plus our own application-level Restore Points retained indefinitely up to the storage cap.
- Off-site disaster recovery: separately from our application-level Restore Points and our provider's managed database backups, a full JSON snapshot of every workspace is written nightly to a private, encrypted off-site storage area, retained for the last 14 days per workspace, so a bad change, mass-delete, or corruption can be recovered.
- Authentication: Supabase Auth — JWTs are short-lived (1 hour), refresh tokens rotate on every use, all auth traffic is TLS-only.
- Email delivery: SPF, DKIM, and DMARC configured. We do not include workspace data in email bodies — only download links.
2. Your Rights as a Vitae Dux User
Regardless of which U.S. state you live in, these rights apply to you:
You can download a complete copy of your data anytime via About → Data → Download backup. No request needed, no review window, no fee.
You can edit any field of any record at any time directly in the app. We do not maintain frozen "official" copies that you'd need to ask us to amend.
From About → Data, you can wipe your workspace data ("Reset workspace") or delete your account entirely ("Delete account"). Account deletion is immediate — a synchronous server-side hard-delete of your workspace and account (organization, memberships, restore points, and profile), and your active sessions are revoked. Before the delete runs, the app automatically generates a full export and emails it to you, and it blocks the deletion if that backup cannot be saved. (Separately, encrypted operational backups may persist up to 30 days before they rotate out.) For fraud-prevention, legal, tax, and audit purposes we retain a minimal record of the deletion itself — the account email, the account holder's name, the workspace name, the role, and the date it was deleted — and payment records (invoices) are retained by our payment processor as required by law. We do not retain your workspace content.
Your exported JSON is structured, machine-readable, and re-importable into any account. No proprietary lock-in.
Not applicable in the negative sense — we do not sell, share, or transfer your workspace data to third parties for advertising, profiling, or any purpose other than delivering the service you signed up for.
We collect: your email (for sign-in), the workspace content you create (tasks, projects, goals, comments, blockers, time blocks), your interaction patterns (which features you use, how often), and technical info (browser, IP at the edge for security only). See the Privacy Policy for the exhaustive list.
Exercising any of the rights above will never trigger account restriction, price changes, or feature downgrades. You exercise your rights → we comply. Nothing changes about your service.
3. U.S. State Privacy Laws
By May 2026, 19 U.S. states have comprehensive consumer-data-privacy laws in force or coming into force. We've built Vitae Dux to honor the union of these protections — meaning even if your state hasn't passed a law yet, you get the same rights as a Californian.
The pragmatic truth:
Rather than tier rights state by state, we apply the strongest common floor to every user. This is the same approach taken by most reputable SaaS — it's simpler, fairer, and avoids the "if you live in California you matter more" optics.
CCPA / CPRA
The California Consumer Privacy Act, expanded by the California Privacy Rights Act (effective Jan 2023). The foundational U.S. state privacy law. Grants rights to access, delete, correct, opt-out of sale/sharing, and limit use of sensitive personal information.
Enforced by: California Privacy Protection Agency (CPPA) + AG
VCDPA
The Virginia Consumer Data Protection Act (Jan 2023). First state law after CCPA. Mirrors most CCPA rights with a notable opt-IN for sensitive categories.
Enforced by: Virginia Attorney General
CPA
The Colorado Privacy Act (July 2023). Universal opt-out signal (Global Privacy Control) recognized.
Enforced by: Colorado Attorney General
CTDPA
Connecticut Data Privacy Act (July 2023). Strong opt-in for sensitive data, broad consumer rights.
Enforced by: Connecticut Attorney General
UCPA
Utah Consumer Privacy Act (Dec 2023). Slightly narrower than VCDPA — opt-out only model, higher business-size threshold.
Enforced by: Utah Attorney General
TDPSA
Texas Data Privacy and Security Act (July 2024). Applies regardless of business size if you target Texas residents.
Enforced by: Texas Attorney General
OCPA
Oregon Consumer Privacy Act (July 2024). Extended deletion rights — must propagate to processors.
Enforced by: Oregon Attorney General
MTCDPA
Montana Consumer Data Privacy Act (Oct 2024). Smallest-state model — low population threshold.
Enforced by: Montana Attorney General
DPDPA
Delaware Personal Data Privacy Act (Jan 2025). Mirrors Connecticut closely.
Enforced by: Delaware Department of Justice
ICDPA
Iowa Consumer Data Protection Act (Jan 2025). Lighter-touch — opt-out only, no profiling rights.
Enforced by: Iowa Attorney General
NHDPA
New Hampshire Data Privacy Act (Jan 2025). Strong rights including profiling opt-out.
Enforced by: NH Department of Justice
NJDPA
New Jersey Data Privacy Act (Jan 2025). Notable: applies to financial information beyond GLBA scope.
Enforced by: NJ Attorney General + Division of Consumer Affairs
TIPA
Tennessee Information Protection Act (July 2025). Includes a safe-harbor for businesses with documented privacy programs aligned with NIST.
Enforced by: Tennessee Attorney General
MCDPA
Minnesota Consumer Data Privacy Act (July 2025). Strong rights to question and contest profiling decisions.
Enforced by: Minnesota Attorney General
MODPA
Maryland Online Data Privacy Act (Oct 2025). Notably restrictive on selling and sharing sensitive personal data.
Enforced by: Maryland Attorney General
INCDPA
Indiana Consumer Data Protection Act (Jan 2026). Aligned with Virginia model.
Enforced by: Indiana Attorney General
KCDPA
Kentucky Consumer Data Protection Act (Jan 2026). Virginia-style framework.
Enforced by: Kentucky Attorney General
RIDTPPA
Rhode Island Data Transparency and Privacy Protection Act (Jan 2026). Adds transparency requirements for data brokers.
Enforced by: Rhode Island Attorney General
FDBR
Florida Digital Bill of Rights (July 2024). Narrower scope ($1B+ revenue threshold) but includes specific protections for minors and biometric data.
Enforced by: Florida Department of Legal Affairs
Illinois — separate but critical
Illinois doesn't have a general consumer privacy statute, but it has two laws that significantly affect SaaS:
- BIPA — Biometric Information Privacy Act. Vitae Dux collects no biometric data, so BIPA does not apply to our service.
- PIPA — Personal Information Protection Act. Requires breach notification within 45 days for any state resident affected. We honor this.
4. U.S. Federal Laws
FTC Act, Section 5
The Federal Trade Commission can pursue companies that engage in "unfair or deceptive" data practices, regardless of which state the consumer lives in. This is the primary federal enforcement tool against bad privacy actors. We take care that every privacy claim in our Privacy Policy, terms, and this guide is accurate — because misrepresenting our practices would create FTC exposure for us and harm for you.
HIPAA
HIPAA does not apply to Vitae Dux. We are not a healthcare provider, insurance plan, or business associate of one. Do not enter Protected Health Information (PHI) into Vitae Dux — we have no HIPAA-compliant data handling, no Business Associate Agreement (BAA) capability, and no breach-notification path for HIPAA-covered data.
COPPA — Children's Online Privacy
Vitae Dux is a B2B leadership tool intended for adult workplace use. We do not knowingly collect data from anyone under 13. If you believe a minor has signed up, contact [email protected] and we will delete the account immediately.
GLBA — Financial Privacy
The Gramm-Leach-Bliley Act covers financial institutions and their service providers. Vitae Dux is neither, so GLBA's specific safeguards do not govern our service. However, we voluntarily apply the safeguards that would be required under GLBA — encryption in transit (HTTPS/TLS), encryption at rest through our database provider, access controls, audit logging — because they are best practices regardless of whether they are legally required.
FERPA — Educational Records
FERPA applies to educational institutions receiving federal funding. If your organization plans to enter student-identifiable records into Vitae Dux, we should sign a Data Processing Agreement first — contact [email protected] before doing so.
Stored Communications Act (SCA)
Under the SCA, your stored data on our service is legally protected against disclosure to anyone (including law enforcement) without a court order or warrant. We do not voluntarily disclose customer data to government agencies. Subpoenas and warrants are reviewed by counsel and, where legally permitted, we notify you before any disclosure.
5. International Users
The Service is intended for businesses located in the United States. We do not currently offer it to, or target, individuals or organizations in the European Union, United Kingdom, or European Economic Area, and we do not rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses at this time.
We do not represent that Vitae Dux complies with the EU or UK General Data Protection Regulation (GDPR / UK GDPR), Canada's PIPEDA, Brazil's LGPD, or other non-U.S. data-protection laws. If we expand into those markets in the future, we will update this guide and our Privacy Policy before doing so.
Our infrastructure runs primarily in U.S. data centers. If you access the Service from outside the United States, you do so on your own initiative and consent to your information being transferred to and processed in the United States, whose data-protection laws may differ from those of your home jurisdiction. The access, correction, export, and deletion controls described in Section 2 are available to every user regardless of location.
6. How to Exercise Your Rights
The fastest path is always the in-app controls. For anything those don't cover, email us.
| What you want | How to do it | How long it takes |
|---|---|---|
| 📥 Get a copy of my data | About → Data → 📥 Download backup (.json) | Instant |
| ✏️ Correct something | Edit the field directly in the app | Instant |
| 🧹 Wipe my workspace, keep account | About → Data → Reset workspace (type RESET) | ~5 seconds |
| 🗑 Delete my account entirely | About → Data → Delete account (type DELETE) | ~10 seconds |
| 📜 Know exactly what we collect | Read Privacy Policy, Section 2 | 5 min read |
| 📨 Data subject request (formal) | Email [email protected] with "Data Subject Request" subject | Within 30 days (45 if complex) |
| 🚨 Report a privacy concern | Email [email protected] with "Privacy Concern" | Within 24 hours acknowledgment |
Verification — why we ask
For formal data subject requests submitted by email, we may ask you to confirm details that prove account ownership (last sign-in date, organization name, etc.). This is to protect you from someone impersonating you to extract your data. We do not retain those verification details after the request is fulfilled.
7. Mutual Protections — How the Law Works for Both of Us
Privacy law isn't just about restricting us. It also defines the rules we both rely on. Here's the honest two-sided view:
How these laws protect you:
- You can demand we delete your data and we must comply within a set window (typically 30–45 days).
- You can sue for damages if we misuse your data in a way that causes you measurable harm (varies by state — California allows private right of action for some breaches).
- State Attorneys General can fine us if we deceive you about what we do with your data.
- You're not required to give up your rights to use the service. Any clickthrough that purports to waive your statutory rights is unenforceable.
- If we suffer a breach affecting your data, we are legally required to notify you within the timeframe set by your state's breach-notification law.
How these laws protect us:
- The Stored Communications Act protects us from being compelled to disclose your data to law enforcement without a warrant — which means we can't easily be deputized against you.
- The DMCA Safe Harbor protects us from copyright liability for user-uploaded content, provided we respond to legitimate takedown notices.
- Section 230 of the Communications Decency Act protects us from being treated as the publisher of your content — your tasks, your projects, your responsibility.
- Our Terms of Service include a limitation of liability clause that's standard for SaaS and enforceable in most U.S. jurisdictions.
- Privacy laws set a clear ceiling on what we must do, so we can plan compliance instead of guessing.
Where the law protects us together:
- Encryption-in-transit requirements (most state laws) mean that if your ISP or coffee shop wifi tries to eavesdrop on your session, the data is unreadable.
- Breach-notification rules force us to tell you fast — so you can change passwords, alert your team, mitigate harm.
- The right to data portability means if a better product comes along, you can leave us with your data intact. That keeps us honest about delivering value.
8. Contact & Questions
If anything in this guide is unclear, contradicts what you see in the app, or you have a specific situation we haven't covered:
- General questions: [email protected]
- Privacy concerns: [email protected] with subject "Privacy Concern"
- Data subject requests: [email protected] with subject "Data Subject Request"
- Security vulnerability disclosure: [email protected] with subject "Security Disclosure" — we acknowledge within 24 hours and credit researchers who report responsibly.
- Legal notices: [email protected] with subject "Legal Notice"
For binding legal terms, see: