Saung
Privacy Policy
Saung is a personal work tracker. This policy explains what it stores, who it shares data with, and what you can do about it.
Last updated: 2026-08-26
Who runs Saung
Saung is operated by Dzul (designbydzul@gmail.com). It is a small, independently run service. Contact that address for any privacy question or request in this policy.
What Saung stores
- Account: your name, email address, password hash, and sign-in records. If you sign in with Google, Saung stores your Google account identifier, email, name, and profile image URL — never your Google password.
- Workspace: projects, tasks, tags, board sections, goals, clients, time entries, notes, sticky notes, comments, and the context documents you keep on a project or a team.
- Billing records you enter yourself: invoices, line items, milestones, and your business profile. Saung does not process payments and never sees card details.
- Files you upload into notes — images and PDFs — stored in Cloudflare R2 and served only to your signed-in account.
- Preferences that sync across your devices: timer mode and sounds, working hours, widget layout, sidebar width, pinned projects, and theme.
- Sharing records: the projects you share and who you share them with, the teams you create or join, invitations you send (including the recipient’s email address), and the public share links you switch on.
- Integration credentials: hashed MCP access tokens, OAuth client authorizations, and — if you connect it — an encrypted Google Calendar token.
- Operational records: sessions, email verification tokens, and a suppression list of addresses that unsubscribed from announcements.
What stays on your device
Some state is never uploaded: per-day task ordering, board section collapse state, dismissed suggestions, and custom timer sound files above the sync size limit. Clearing your browser storage clears these.
How your data is used
To authenticate you, render your workspace, sync it between your devices, calculate your tracked time and capacity, and run the integrations you explicitly connect.
Saung does not sell your data, does not use it for advertising, and does not use your workspace content to train AI or machine-learning models.
Who can see your content
Your workspace is private to your account. Other people can see something only when you explicitly share it: a project you invite them to, a project you add to a team, or a public share link you switch on. Each of those can be revoked at any time, and revoking it removes the access.
No one reads your workspace content in the normal course of operating Saung. Your data is encrypted at rest on Cloudflare’s infrastructure, but Saung is not end-to-end encrypted — the same model as most work tools — so operator access to the database exists in order to run, debug, and back up the service. That access is not used to browse your content. The only time a human looks inside your workspace is when you ask for help with a problem in your account, and then only as far as needed to resolve it.
Google Calendar
Connecting Google Calendar is optional and off by default. If you connect it, Saung requests read-only access (calendar.readonly) and uses it for one purpose: to show your own events for the day you are viewing, next to your tasks.
Saung reads events from your primary calendar for the day in view: the title, start and end time, colour, location, description, video-call link, and a count of how many guests are invited. Guest names and email addresses are never requested or received. It never creates, changes, or deletes anything in your calendar. Event details are fetched fresh each time, displayed to you in the app, and are not stored in Saung’s database. Saung stores your Google authorization token, encrypted, so the connection keeps working — nothing else from Google is retained. No human reads your calendar data.
You can disconnect Google Calendar at any time from the Connectors page. Disconnecting deletes the stored token immediately.
Saung’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI assistants and MCP
Saung can expose your workspace to an AI client you connect yourself — for example Claude, ChatGPT, or a command-line agent — through the Model Context Protocol. This only happens when you issue an access token or complete a sign-in for that client, and only that client can then read and write your workspace.
These connections are human-driven: nothing runs on a schedule and no assistant reaches your data unless you invoke it. Anything you send to an AI client is then handled under that provider’s own privacy policy, not this one. You can revoke access at any time from Settings and the Connectors page.
Who else processes your data
- Cloudflare — hosting, application database, file storage, and email delivery. All Saung data is stored on Cloudflare infrastructure.
- PostHog — product analytics, as described below.
- Google — only if you use Google sign-in or connect Google Calendar.
- AI providers — only for assistants you connect yourself, as described above.
- When you paste a link into a note, Saung fetches that page once to build a preview card. That request reveals your server’s access to the linked site, in the same way opening the link would.
Product analytics
Saung uses PostHog to understand how the product is used: which pages are opened, which controls are clicked, and where people get stuck. Analytics requests are proxied through saung.app rather than sent to PostHog directly.
Your content is not part of this. Before any event leaves the app, the text of whatever you clicked is removed, and addresses are reduced to a route shape with every query string dropped — so task titles, note bodies, client names, share links, and one-time sign-in codes are not collected. Session recording is switched off, so no replay of your screen is captured.
When the app hits an error, the error message, the stack trace, and the page it happened on are reported to PostHog so the bug can be found and fixed. These reports describe the code that failed, not the content you were working on.
Once you sign in, events are associated with your account identifier so usage can be counted per person rather than per browser. Your email address and name are not sent to PostHog.
Saung sends transactional email: a welcome message when you sign up, and a link when you ask to reset your password. These are part of the service, so there is nothing to unsubscribe from while your account is open.
When you invite someone to a project, a team, or a single item, Saung emails the address you type in and names you as the sender. You choose those addresses, and the invitation says what the person will be able to see.
Saung also sends occasional product announcements to the address on your account. Every announcement carries an unsubscribe link. Unsubscribing adds your address to a suppression list that stops announcements. It does not affect transactional email, so you still receive a password reset when you ask for one.
Feedback you send from inside the app is emailed to Saung support along with your name and email address, so a reply can reach you.
How long data is kept
Workspace data is kept until you delete it or delete your account. Sessions and verification tokens expire on their own. Deleting your account removes the account and the workspace data it owns; this is destructive and cannot be undone.
Your controls
- Export your data from Settings › Account.
- Delete your account and its workspace data from Settings › Security.
- Revoke MCP tokens and connected AI clients from Settings and the Connectors page.
- Disconnect Google Calendar from the Connectors page.
- Ask for a copy of, correction of, or deletion of your data by emailing designbydzul@gmail.com.
Security
Every workspace request is authenticated and scoped to your account. Passwords are hashed, MCP tokens are stored as hashes rather than readable values, and Google Calendar tokens are encrypted at rest. Uploaded files are served only through an authenticated route, not from a public bucket URL.
No online service is risk-free. Use a strong, unique password and revoke integration credentials you no longer need.
Children
Saung is not intended for children under 13, and accounts should not be created for them.
Changes to this policy
If this policy changes in a way that affects how your data is handled, the date at the top of this page changes and, for significant changes, Saung will tell you by email.
Contact
For privacy questions, data requests, or anything in this policy, contact designbydzul@gmail.com.