Privacy policy
Last updated 5 October 2026. This instance of Conduit is operated by CoitusDev ("we").
What we store
- Account: your name, email address, a password hash only if you set a password before this instance switched to Discord sign-in (Argon2id; it can no longer be used to sign in, but it is still asked for when you change two-factor settings; it is deleted when an unverified account is taken over through Discord, and otherwise on request), optional two-factor secrets and recovery codes (encrypted), and the time you signed up.
- Discord sign-in: if you use "Continue with Discord", Discord sends us your Discord user id, username, avatar and email address. We store those plus the OAuth tokens Discord issues (encrypted) so the connection keeps working. We never receive your Discord password.
- Workspace content: projects, tasks, comments, labels, blockers, activity history, webhook configuration and API keys (hashed) that you or your team create.
- Discord server data: when a server is linked, the ids of that server and of the channels, threads and messages the bot creates, and the Discord ids and display names of members who use the bot. Messages posted in a task thread are stored as task comments.
- Technical: sessions, with the browser string and a shortened IP address (the last part is removed before it is stored, plus a one-way fingerprint so you can tell your own devices apart on your Security page); web server logs, also with shortened addresses, kept until they rotate out under a fixed size limit or the server is redeployed; and nightly database backups.
What we do with it
Only run the service: sign you in, show your team its work, post to the Discord channels your workspace configured, and deliver webhooks your workspace set up. We do not sell data, run advertising, or share anything with third parties except the providers needed to operate (hosting, Discord's API for sign-in and the bot).
How long
For as long as the account or workspace exists. Deleting a task or project removes it immediately; backups age out after 14 days. Sessions expire after 30 days of inactivity.
Your choices
- Revoke Conduit's Discord access at any time under Discord → User Settings → Authorized Apps.
- Change your name and two-factor settings and sign out other devices from your Account pages.
- Ask us to export or delete your account and data by emailing [email protected]. We answer within 30 days.
Cookies
One session cookie, strictly needed to keep you signed in, and (if you choose it) a "trust this device" cookie for two-factor sign-in. No analytics or advertising cookies.
Contact
CoitusDev, [email protected].