Legal
Privacy Policy
Last updated: 28th August 2026
This Privacy Policy explains what data Kanbedu (“we”, “us”, or “our”) collects, why we collect it, how it is used, and how long we keep it. It covers your account, the content you create, and the class information an educator provides about you. We do not sell your personal data; Section 10 sets out the only circumstances in which we share it.
1. What We Collect
We collect only what’s necessary to run the service:
Account information
- Your name and email address, provided when you sign up.
- A hashed version of your password. We never store your password in plaintext.
- Your chosen avatar colour and display preferences.
Content you create
- Boards, columns, tasks, comments, and any other content you add to the platform.
- Task metadata: titles, descriptions, deadlines, priority, assignees, and column history.
- Files you attach to tasks. These are stored separately from the database (see Section 9) and are served over links that expire after one hour. Please avoid attaching personal data that the other members of your board don’t need to see.
Class roster information
- When an educator sets up a class, they may upload a roster listing each student’s name, email address, and assigned group. We hold this so that students are placed in the right group when they join.
- This means we may hold your name and email address before you have created an account, because your educator provided them. If you never join, the entry is removed when the class is deleted. The institution that uploaded the roster is responsible for having the right to share it with us.
Pro waitlist
- If you join the Lecturer Pro early-access list from our pricing page, we store the email address you provide, whether or not you have a Kanbedu account. We use it only to tell you when Lecturer Pro becomes available to buy.
Support and notifications
- If you send us a bug report from within the app, we store what you wrote along with your browser details and a link to your account, so we can reproduce the problem and reply.
- If you turn on push notifications, we store the subscription details your browser gives us so we can deliver them. This is off unless you enable it, and turning it off removes the subscription.
Usage data
- Basic activity data used for analytics features (e.g. task completion times, workflow phase durations), used only to power in-app analytics visible to your board members.
- Separately, we log which features you use and the kind of device you use them on (e.g. opening a class panel, viewing analytics), tied to your account. This is self-hosted and never leaves our own database. We use it internally to understand which parts of Kanbedu people actually rely on, never to build an advertising profile or sell to anyone, and it’s deleted when your account is.
Activity indicators shown to educators
- In a class, Kanbedu derives activity indicators from task history and shows them to your educator. These include how quickly a task was completed, whether it passed through every column, and whether it was moved by someone other than an assignee, alongside counts such as comments posted and description edits.
- These are indicators of activity, not assessments of you, and they are generated by simple automated rules that have ordinary innocent explanations. They are intended as a prompt for an educator to ask a question, not as evidence on their own. No decision about you is made automatically by Kanbedu.
Diagnostic data
- If the app encounters an error, we automatically collect diagnostic information including the error details, your browser and operating system type, and a session identifier. This is processed by our error monitoring provider (Sentry) and used solely to identify and fix bugs.
- Standard server logs, including IP addresses, browser type, and request timestamps, are collected automatically by our hosting infrastructure.
2. What We Don't Collect
We don’t collect:
- Payment information (Kanbedu is currently free).
- Device fingerprints or advertising identifiers.
- Any record of what you do outside Kanbedu. We don’t track you across other websites, we don’t build advertising or marketing profiles, and we don’t share behavioural data with third parties. The in-app usage log described in Section 1 stays in our own database and is used only to improve Kanbedu.
- Any data beyond what is necessary to operate the service.
3. Why We Collect It
We use the data we collect to:
- Create and manage your account.
- Provide the core features of Kanbedu (boards, tasks, collaboration).
- Power the analytics dashboard so you and your team can review progress.
- Send transactional emails (e.g. invite links, password resets). We don’t send marketing emails without your consent.
- Let you know when Lecturer Pro becomes available, if you joined the waitlist.
- Debug issues and improve the service, including understanding which features are actually used.
4. Legal Basis for Processing
We process your personal data in accordance with Malaysia’s Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024 (together, the “PDPA”), and the data protection principles it sets out, including the General Principle, the Notice and Choice Principle, the Security Principle, and the Retention Principle. By creating an account and providing your data, you consent to us processing it for the purposes described in this policy. You can withdraw your consent at any time as described in Section 11.
Where Kanbedu is provided to you through a school, university, or other institution, that institution decides what the tool is used for and is the controller of the class data it puts into it, including any roster it uploads. In that setting we act on the institution’s instructions, and the institution is responsible for having a lawful basis for the processing and for telling you about it. If you were asked to use Kanbedu as part of a course, direct questions about why your data is being processed to your institution in the first instance. This does not change how we handle any personal board you create for yourself.
Where other data protection laws also apply to you, we rely on the following grounds to process your data:
- Performance of a contract: processing your account information and content is necessary to provide the service you signed up for.
- Legitimate interests: we process usage data to operate, secure, and improve the platform. We only do this where our interests don’t override your rights.
- Legal obligation: we may process or retain data where the law requires it.
- Consent: where we rely on your consent (e.g. marketing communications), you can withdraw it at any time. That won’t affect anything we processed before you withdrew.
5. Authentication and Sessions
When you create an account, we send a verification email to confirm your address. Your account will have limited access until your email is verified. Verification links are single-use and expire within 24 hours.
When you log in, Kanbedu issues a signed session token stored as an HTTP-only cookie. This token is used to authenticate your requests and expires 30 days after you log in. Logging out clears it immediately, and changing your password ends every session on every device.
We do not use third-party OAuth (e.g. Google, GitHub) at this time. All authentication is handled directly by Kanbedu.
6. Cookies and Local Storage
Kanbedu uses a small number of cookies and browser storage mechanisms:
- Session cookie: an HTTP-only cookie used to keep you logged in securely.
- Default landing preference: a cookie storing which board or class you’ve chosen to open on login, set from Settings > Boards. Unlike the session cookie, our server reads this one to decide where to send you, and it lasts up to a year unless you change or clear it.
- Theme preference: stored in
localStorageto remember your light/dark mode setting. - Interface preferences: stored in
localStorageto remember small things like which product announcements you have already dismissed and the name to put on a comment. These never leave your browser.
We do not use advertising cookies, third-party tracking cookies, or analytics platforms like Google Analytics.
7. Data Storage and Security
Your data is stored using third-party infrastructure providers (see Section 9). We use industry-standard practices to protect it:
- Passwords are hashed using bcrypt before storage.
- Communication between your browser and our servers is encrypted over HTTPS.
- Access to production data is restricted to authorised personnel only.
No system is perfectly secure. While we take reasonable precautions, we cannot guarantee absolute security. If you suspect unauthorised access to your account, contact us immediately through Support & Feedback in Settings.
In the event of a personal data breach that is likely to cause significant harm, we will notify the Personal Data Protection Commissioner, and affected users where required, in accordance with the PDPA.
8. International Data Transfers
As Kanbedu relies on infrastructure providers that operate servers globally (see Section 9), your personal data may be transferred to, stored, and processed outside Malaysia. Consistent with the PDPA, we take reasonable steps to ensure that any party we transfer your data to provides a standard of protection comparable to that required under Malaysian law, for example by relying on providers that maintain standard contractual clauses or equivalent safeguards recognised under applicable law.
By using Kanbedu, you consent to your personal data being transferred to and processed in countries other than Malaysia as described in this policy.
9. Third-Party Services
We rely on the following providers to operate Kanbedu. Each is contractually bound to handle your data securely and only as instructed by us.
- Supabase: database hosting, in Singapore. Stores account data, content, and usage data.
- Google Cloud Storage: file storage. Holds the files you attach to tasks. Older attachments may still sit on Vercel Blob storage from before we moved.
- Vercel: hosting and deployment. Processes all web requests and server logs including IP addresses.
- Brevo: email delivery. Receives your email address to send transactional emails (verification links, password resets, and board invites).
- Sentry: error monitoring. Receives diagnostic data including session identifiers and browser information when errors occur.
We do not integrate with advertising networks, social media trackers, or data brokers. If we add new providers in the future, we will update this section.
10. Sharing Your Data
We do not sell, rent, or trade your personal data. We only share it in these limited circumstances:
- With your team: your name and avatar are visible to members of boards you belong to.
- Legal requirements: if required by law or a valid legal process, we may disclose information. Where permitted, we will notify you before complying.
- Service providers: limited data may be shared with infrastructure providers strictly to operate the service, under confidentiality obligations.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred to a successor entity, subject to equivalent privacy protections.
11. Your Rights
Under the PDPA, you have the right to access and correct your personal data, and to withdraw your consent to our processing of it. To exercise these rights, use Support & Feedback in Settings within the app, or email us at kanbeduapp@gmail.com.
Depending on where you live, you may also have some or all of the following rights over your data:
- Access: request a copy of the data we hold about you.
- Correction: update inaccurate information (most can be changed directly in the app).
- Deletion: delete your account yourself at any time under Settings, in the Account section. This removes your account, your personal boards, your activity history, and your uploaded files straight away. Some content on boards you shared with other people is kept, and Section 12 explains exactly what and why. If you own a class you will be asked to delete the class first, since deleting it also removes the boards your students are working on.
- Portability: request a copy of your data in a structured, machine-readable format. We put these together by hand at present, so please allow us the 30 days noted below.
- Restriction: ask us to limit how we process your data in certain circumstances.
- Objection: object to processing based on our legitimate interests, including any profiling.
- Withdraw consent: if we’re relying on your consent, you can withdraw it at any time. This won’t affect anything we processed before you withdrew.
- Lodge a complaint: if you think we’ve mishandled your data, you can complain to your local data protection authority.
We aim to respond to all data requests within 30 days. We may need to verify your identity before fulfilling a request.
12. Data Retention
We retain your account and content data for as long as your account is active. If you delete your account from Settings, your personal data is removed immediately. Where a deletion has to be handled by us rather than by you, we complete it within 30 days. Either way, we may keep the small amount of data the law requires us to keep, or that we need in order to investigate a security incident.
Two things outlive your account, and we would rather say so plainly. Content you contributed to a shared board, such as a comment or a task you wrote, stays on that board so your teammates’ work still makes sense. It is unlinked from your account, but the display name shown against a comment at the time you posted it remains visible to that board’s members. And if an educator listed you on a class roster, that entry belongs to the class rather than to you, so it stays until the educator deletes the class or removes the row. If you want a comment or a roster entry taken out, ask your educator or board owner, or contact us and we will arrange it.
The feature-usage log described in Section 1 is deleted automatically after 180 days, whether or not your account is still open, and is removed in full if you delete your account.
If you asked us to tell you when Lecturer Pro launches, we keep the email address you gave us until Lecturer Pro launches or you ask us to remove it, whichever comes first. You don’t need a Kanbedu account to ask: email us at kanbeduapp@gmail.comand we’ll take it off the list.
Anonymised, aggregated data (e.g. aggregate usage patterns) may be retained indefinitely, as it cannot reasonably be linked back to you.
13. Children
Kanbedu is intended for users aged 18 and over. If you are under 18, you may use Kanbedu only with the consent of a parent, guardian or other person with parental responsibility, or where your institution has obtained that consent on your behalf.
Under the Malaysian Personal Data Protection Regulations 2013, where a user is under 18 we are required to obtain consent from a parent, guardian or person with parental responsibility. We do not collect date of birth, so we rely on you and on your institution to tell us where this applies.
If a parent or guardian believes a person under 18 has created an account without the required consent, email us at kanbeduapp@gmail.com and we will promptly delete the account and associated data. You do not need a Kanbedu account to make this request.
Where Kanbedu is used in an institutional or educational setting, the institution is responsible for ensuring that appropriate consents and authorisations are in place for all users, including those under the digital age of consent in their jurisdiction.
14. Changes to This Policy
We may update this Privacy Policy as the service evolves. When we do, we’ll update the “Last updated” date at the top. For material changes, we’ll notify you via email or an in-app notice at least 14 days before the changes take effect, where reasonably practicable.
15. Contact
If you have questions or concerns about this policy or how we handle your data, use Support & Feedback in Settings within the app, or email us at kanbeduapp@gmail.com.
Data protection matters, including access, correction, portability and deletion requests, questions from a parent or guardian, and any breach concerns, are handled by our designated data protection contact. Reach them at kanbeduapp@gmail.com, or through Support & Feedback in Settings if you have an account. You do not need an account, and you do not need to still be a user, to contact us about your data.
If you are in Malaysia and believe we have not adequately addressed your concern, you may lodge a complaint with the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi).