1. Introduction
Vitae Dux ("we", "us", "our") respects your privacy. Vitae Dux is owned and operated by Kita Technology Support Inc., an Illinois corporation doing business as Vitae Dux, which is the entity responsible for the personal information described here. This Privacy Policy explains what information we collect, how we use it, how we share it, and the rights you have over your information.
This Policy applies to vitaedux.co and all related Vitae Dux services (collectively, the "Service"). It applies to all U.S. residents, with additional rights specified for residents of certain states (see Section 9).
By using the Service, you agree to the practices described in this Policy. If you disagree, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (required for authentication)
- Password (stored only as a one-way cryptographic hash using bcrypt; we never see your plaintext password)
- Display name, role, initials, color, and time zone (optional profile fields)
- Organization name (the workspace you create or join)
2.2 Content You Provide
You may create or upload content within the Service, including:
- Tasks, projects, goals, decisions, polls, blockers, and comments
- Team member entries and assignments
- Activity log entries (a record of actions you take)
- In-app notifications and read-state records (e.g., which comment threads you've opened, used to show unread counts)
- Preferences (theme, density, notification settings, avatar color, etc.)
This content belongs to you. We process it solely to provide the Service. We do not sell, share for advertising, or use it to train artificial intelligence models.
2.3 Usage Information
We automatically collect limited technical information when you use the Service:
- Browser type and version, operating system, screen resolution
- IP address (truncated for analytics; full IP retained briefly for security monitoring)
- Pages visited, features used, timestamps
- Diagnostic logs (errors, performance metrics)
2.4 Information We Do NOT Collect
- Government identifiers (Social Security numbers, driver's license numbers)
- Financial account numbers (handled exclusively by Stripe; see Subprocessors)
- Biometric identifiers or biometric information of any kind (including fingerprints, facial geometry, voiceprints, and retina/iris scans) as those terms are defined in the Illinois Biometric Information Privacy Act (740 ILCS 14) and similar laws
- Protected health information ("PHI" as defined under HIPAA)
- Precise geolocation
- Information about your race, religion, sexual orientation, or political affiliation
3. How We Use Your Information
We use the information we collect to:
- Operate, maintain, and improve the Service
- Authenticate you and protect your account
- Process payments (via Stripe) and send billing-related communications
- Respond to your support requests
- Send service-related notifications (e.g., password resets, account deletion confirmations)
- Detect, prevent, and address security incidents and abuse
- Comply with legal obligations
4. How We Share Information
We share your information only in these limited circumstances:
- With subprocessors who operate the underlying infrastructure (see Section 5). All subprocessors are contractually bound to protect your information.
- With your team members. Content you create inside an organization is visible to other authenticated members of that organization (governed by our row-level security policies). It is never visible to other organizations.
- When required by law, such as a valid subpoena, court order, or legal process. We will notify you when legally permitted to do so.
- To protect rights and safety: to enforce our Terms, protect against fraud, or protect the safety of any person.
- In a business transfer. If we are acquired, merged, or our assets are sold, your information may transfer to the acquiring party. We will notify you of any change in ownership at least 30 days in advance.
We do not sell your personal information for monetary consideration to third parties. We do not engage in "sharing" of personal information for cross-context behavioral advertising as defined under California, Colorado, Connecticut, Texas, Utah, or Virginia law.
5. Subprocessors
We rely on the following third-party services to operate Vitae Dux. Each is bound by data protection commitments and certified to industry standards.
| Subprocessor | Purpose | Data Region | Certifications |
|---|---|---|---|
| Supabase | Database, authentication, file storage | United States (us-east-1) | SOC 2 Type II |
| Vercel | Frontend hosting, CDN | Global edge (United States primary) | SOC 2 Type II |
| Cloudflare | DNS, security, email routing, DDoS protection | Global edge | SOC 2 Type II, ISO 27001 |
| Stripe | Payment processing | United States | PCI DSS Level 1, SOC 1 & 2 |
| Resend | Transactional email delivery (account, security, and billing notices) | United States | SOC 2 Type II |
| Optional Google sign-in (OAuth) and our own workspace email | United States | SOC 2 / SOC 3, ISO 27001 | |
| Sentry | Error & performance monitoring (diagnostic data) | United States | SOC 2 Type II |
| PostHog | Product analytics: first-party usage events tied to your account to improve the Service, with no session recording, no content capture, and Do Not Track honored | United States | SOC 2 Type II |
| UptimeRobot | Service availability monitoring | United States | — |
| Have I Been Pwned | Password breach screening (security / account protection): only k-anonymized password hash prefixes are sent; Vitae Dux never sends your password | Global edge | — |
A current list of subprocessors will be maintained on this page. We will give you at least 30 days' notice before adding any new subprocessor that materially affects how your data is processed.
6. Data Retention
We retain your information as follows:
- Account data: for as long as your account is active.
- Content: until you delete it or your account.
- Backups: up to 30 days after deletion.
- Diagnostic logs: up to 90 days.
- Billing records: as long as required by applicable tax and accounting law (typically 7 years in the United States).
When you delete your account via My Account > Danger zone > Delete my
account, we immediately and permanently delete your workspace content and account
on the server and revoke your sessions. (Separately, encrypted operational backups
may persist up to 30 days before they rotate out.) For fraud-prevention, legal, tax, and
audit purposes we retain a minimal record of the deletion itself (the account email, the
account holder's name, the workspace name, the role, and the date it was deleted), and
payment records (invoices) are retained by our payment processor as required by law.
7. Security
We use defense-in-depth security practices, including:
- HTTPS / TLS encryption for all communications
- Cryptographic password hashing (bcrypt)
- Two-factor authentication (an authenticator app / TOTP) is required to access your workspace; new accounts can defer setup a limited number of times during a short enrollment grace, but the workspace stays locked until 2FA is enabled
- Database-level row-level security to isolate organizations
- Force-RLS to prevent administrative bypass
- Cloudflare edge protection (DDoS, WAF, bot detection)
- Audit logging of administrative and security-relevant actions
- Regular automated security reviews
Despite our efforts, no security system is impenetrable. In the event of a confirmed breach of unencrypted personal information, we will notify affected users in the most expedient time possible and without unreasonable delay, consistent with applicable state breach-notification laws (including Illinois PIPA, California Civil Code §1798.82, and others).
8. Your Rights (All U.S. Residents)
We extend the rights below to every user, in every state, even where a state privacy law's applicability thresholds (such as minimum numbers of consumers processed) would not technically require it.
Regardless of your state of residence, you may at any time:
- Access your account data via
My Accountin the app. - Update or correct your profile information at any time.
- Delete your account and request server-side data purge.
- Export your workspace content (tasks, projects, goals, and more) to spreadsheet (XLSX) files at any time from within the app. A copy is also generated automatically before your account is deleted.
- Opt out of non-essential email and in-app notifications.
- Contact us with any privacy question at [email protected].
9. State-Specific Rights
The following U.S. states have enacted consumer privacy laws that grant additional rights. If you reside in one of these states, you may exercise the rights described. Submit requests to [email protected] with the subject line "Privacy Rights Request - [your state]". We respond within the legally required timeframe (typically 45 days, extendable by 45 additional days).
9.1 California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, and sell or share.
- Delete personal information we collected from you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising).
- Limit the use of sensitive personal information.
- Non-discrimination for exercising your privacy rights.
- Designate an authorized agent to make requests on your behalf.
9.2 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA)
If you reside in one of these states, you may:
- Confirm whether we are processing your personal data and access it.
- Correct inaccuracies in your personal data.
- Delete personal data we have collected about you.
- Obtain a portable copy of your personal data in a readily usable format.
- Opt out of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects (we do not engage in any of these).
- Appeal a denial of your privacy rights request.
9.3 Other States
Several other states (including Oregon, Montana, Iowa, Tennessee, Indiana, New Hampshire, Delaware, New Jersey, Minnesota, Maryland, and Rhode Island) have enacted or are enacting comprehensive privacy laws. We honor equivalent rights for residents of those states.
10. Illinois Residents
Vitae Dux is operated from the State of Illinois. If you are an Illinois resident, the following additional notices apply:
- Illinois Personal Information Protection Act (PIPA, 815 ILCS 530). In the event of a confirmed breach of unencrypted personal information, we will notify affected Illinois residents in the most expedient time possible and without unreasonable delay, consistent with PIPA.
- Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14). We do not collect, capture, purchase, receive through trade, or otherwise obtain biometric identifiers or biometric information from you. No facial recognition, fingerprint, voiceprint, retina scan, or hand/face geometry data is collected by Vitae Dux.
- Illinois Right to Privacy in the Workplace Act and related Illinois employment-privacy statutes do not impose obligations on Vitae Dux as a SaaS provider, but you (as our customer) may have separate obligations to your own team members. Consult counsel if you are using Vitae Dux to manage employee data in Illinois.
11. Cookies & Tracking
We use a minimal set of cookies and storage mechanisms:
- Authentication tokens (Supabase session): required for the Service to function. Stored in browser localStorage.
- User preferences (theme, density, notification opt-ins): stored locally on your device.
- Cloudflare security cookies: set by our edge provider to detect malicious traffic.
- Product-analytics cookies (PostHog): first-party cookies that record in-app usage events (pages viewed, features used) tied to your signed-in account so we can improve the Service. No screen/session recording and no content of your tasks, projects, or goals is captured, and we honor Do Not Track.
We do not use third-party advertising cookies, retargeting pixels, or cross-site behavioral tracking. Our product analytics stay within our own Service, and we honor your browser's "Do Not Track" signal: if it is enabled, analytics are suppressed.
12. Children's Privacy
The Service is not directed to children under 18 years of age, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. Contact us at [email protected] if you believe this has occurred.
13. International Transfers
Vitae Dux is operated in the United States. By using the Service, residents outside the United States understand and consent to the transfer of their information to the United States for processing. The Service is currently targeted at U.S. residents; non-U.S. users should be aware that U.S. data protection laws may differ from the laws of their home jurisdiction.
We do not currently target or market the Service to residents of Canada (including Québec), Mexico, the European Union, or the United Kingdom, and we make no representation of compliance with PIPEDA, Québec Law 25, the LFPDPPP, the GDPR, or the UK GDPR. If we expand into those markets, this Policy will be updated first.
14. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. Material changes that affect your rights or how we use your information will be communicated via email or in-app notice at least 30 days before they take effect.
15. Contact
For any privacy-related question, request, or complaint, contact:
Kita Technology Support Inc., d/b/a Vitae Dux, Privacy Team
930 E 162nd Street #1042
South Holland, IL 60473, USA
Email: [email protected]
Subject line for privacy requests: Privacy Rights Request
Website: https://vitaedux.co
CCPA Request. Authorized agents acting on your
behalf must provide proof of authorization and your written permission.

