Last updated: August 9, 2026
This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal data to provide and improve the Service. By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.
The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
For the purposes of this Privacy Policy:
While using Our Service, We may ask You to provide Us with certain personally identifiable information that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:
Usage Data is collected automatically when using the Service.
Usage Data may include information such as Your Device's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When You access the Service by or through a mobile device, We may collect certain information automatically, including, but not limited to, the type of mobile device You use, Your mobile device unique ID, the IP address of Your mobile device, Your mobile operating system, the type of mobile Internet browser You use, unique device identifiers and other diagnostic data.
The Company allows You to create an account and log in to use the Service through the following Third-party Social Media Services:
If You decide to register through or otherwise grant us access to a Third-Party Social Media Service, We may collect Personal data that is already associated with Your Third-Party Social Media Service's account, such as Your name, Your email address, Your activities or Your contact list associated with that account.
You may choose to connect FortyOne to third-party services. We access and use data from a connected service only after an authorized user grants the requested permissions and only to provide, secure, support, and improve the user-facing integration. We do not sell connected-service data or use it for advertising.
When a workspace administrator connects Slack, We may collect and store Slack workspace and installation identifiers, workspace name and domain, authorized scopes, encrypted access credentials, channel identifiers and names, channel privacy and membership status, and identifiers used to link a Slack user to a FortyOne account.
We process message content and related metadata when a person deliberately uses a supported FortyOne feature, including the /fortyone command, the Create a story message shortcut, a direct message or mention to Maya, a reply in a subscribed FortyOne thread, or a shared FortyOne link. Slack's event subscriptions may deliver unrelated message events to Our endpoint; FortyOne rejects unsupported root messages, bot messages, edits, and unsubscribed thread messages before storing their content in the durable message system.
We use Slack data to create and link project work, answer requested questions, maintain short-term thread context, provide permission-aware story previews, synchronize supported request discussions, deliver replies, prevent duplicate processing, and diagnose integration failures. FortyOne does not use Slack API data to train general-purpose artificial intelligence models.
Accepted inbound Slack payloads are encrypted at rest. Conversation and assistant message content in the messaging system is retained for up to 30 days for short-term continuity and operational recovery. Installation, linked-account, and channel metadata is retained while the integration is connected. When an administrator disconnects Slack, We revoke or remove the active credentials and associated connection records. Limited security, abuse-prevention, diagnostic, backup, and legal records may be retained for as long as reasonably necessary for those purposes.
When You connect Google Calendar, We may collect and store Your Google account identifier, connected email address, timezone, authorized scopes, encrypted OAuth credentials, primary-calendar availability, and synchronization status. If You grant event-detail access, We may also cache event titles, descriptions, locations, meeting links, organizers, attendees, visibility, and start and end times for Your primary calendar. Private and confidential events are stored as Busy without their descriptive details.
We use Google Calendar data to show Your meetings beside FortyOne work, calculate availability, avoid obvious schedule conflicts, and provide schedule-aware planning features. Detailed calendar events are visible only to the connected calendar owner. Teammates, managers, Maya, and capacity-planning features receive title-free availability windows rather than event content. The integration is read-only and does not create, edit, or delete Google Calendar events.
FortyOne keeps a rolling calendar snapshot that currently covers seven days before and ninety days after the sync date. When You disconnect Google Calendar, We clear the connection credentials and scopes and delete the cached calendar events and availability windows for that connection. FortyOne's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
When a workspace administrator installs the FortyOne GitHub App, We may collect and store installation and organization identifiers, account name and avatar, the repositories selected during installation, repository metadata, granted permissions, webhook subscriptions, and identifiers used to associate a GitHub user with a FortyOne account.
For connected repositories, We process the issue, comment, branch, commit, pull request, review, check, label, assignee, and repository event data needed to synchronize linked work, show development progress, and run the workflow rules configured by the workspace. GitHub displays the permissions requested by the FortyOne GitHub App and allows the installer to choose which repositories the app may access.
Connection metadata is retained while the GitHub App is installed or while needed to preserve the integrity of linked workspace records. Content copied into FortyOne stories, comments, activity history, or audit records may remain after the GitHub App is disconnected so the workspace does not lose its project history. An authorized workspace administrator can unlink a repository or uninstall the GitHub App, and You may contact Us to request deletion as described below.
The third-party services You connect process information under their own terms and privacy policies. You should review the permissions shown during authorization and the applicable provider policies before connecting an integration.
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
We use both Session and Persistent Cookies for the purposes set out below:
Necessary / Essential Cookies
Cookies Policy / Notice Acceptance Cookies
Functionality Cookies
The Company may use Personal Data for the following purposes:
After signing up, we may send you onboarding and support emails to help you get started and use FortyOne. These emails are necessary for providing our service and do not require additional consent.
You may also choose to receive product updates, newsletters, and promotional offers by opting in during signup. We will only send marketing or promotional emails to users who have provided explicit consent. You can unsubscribe from marketing emails at any time by following the link in the email or contacting us.
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.
Your information, including Personal Data, is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
You may update, amend, or delete Your information at any time by signing in to Your Account, if you have one, and visiting the account settings section that allows you to manage Your personal information. You may also contact Us to request access to, correct, or delete any personal information that You have provided to Us.
If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred.
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities.
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
The security of Your Personal Data is important to Us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.
Our Service does not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us.
Our Service may contain links to other websites that are not operated by Us. If You click on a third party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page.
We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy, You can contact us:
By email: info@complexus.app
For data protection inquiries: Data Protection Officer: hello@complexus.tech
For general support: Support: hello@complexus.tech