Privacy Policy

This page explains what BoardUI collects when you use boardui.com or the BoardUI CLI, why, and what you can ask us to do about it.

Last updated 15 August 2026

Who is responsible

BoardUI operates this website and is the data controller for the processing described here. For anything in this policy — including access, correction or deletion requests — write to hi@boardui.com and we will respond within 30 days.

Website analytics, and why there is no cookie banner

We measure how the site is used — which pages are visited, which install and Pro buttons get clicked, which template previews get opened — so we know what to build next. This runs on PostHog, hosted in the EU.

It is deliberately configured to leave nothing behind on your device:

  • No cookies and no local storage. The identifier that groups your actions within a visit exists only in your browser tab's memory and is gone when you close or reload it.
  • No profiles. Events are recorded anonymously; we do not build a person record for you or attempt to recognise you across visits.
  • No session recording. We do not record your screen, your typing or your mouse movements. It is switched off in code, not merely unused.
  • No advertising and no data selling.Nothing here feeds ad networks or is shared for anyone else's marketing.

Consent banners exist because most analytics store or read something on your device. Ours does not, so there is nothing to ask you to accept. Vercel's audience and performance measurement, which runs alongside it, is likewise cookieless.

Waitlist

If you submit your email address to join the waitlist, we store that address, and we receive a private notification containing it so we know someone signed up. We use it only to tell you when BoardUI is available and about significant changes to it — no unrelated marketing, and no sharing with anyone else. Ask us at any time and we will delete it.

The BoardUI CLI

Installing components with npx boardui records an anonymous, randomly generated installation identifier, the CLI version, the package manager, and the names of the components installed. It exists to tell us which components people actually use.

The CLI never sends your source code, file paths, dependency lists, email address or anything else you have written. The identifier is not linked to your website visits or your purchase.

BoardUI Pro purchases

Pro is sold through Lemon Squeezy, which acts as the seller of record. They collect and hold the billing details, take the payment and issue the licence key; we receive the order and the email address attached to it so we can provide support and validate that key. We never see your full card details.

Server logs

Like any website, our host records requests — IP address, timestamp, page, browser — to serve pages, keep the site up and defend against abuse. These logs are short-lived and are not used to profile you.

Legal bases

Under the GDPR we rely on:

  • Legitimate interests for anonymous analytics, anonymous CLI counts and server logs — understanding and securing our own product, with no tracking across other sites and nothing stored on your device.
  • Consent for the waitlist: you give us your address by choosing to submit it, and you can withdraw at any time.
  • Contract for Pro purchases — we cannot deliver a licence without processing the order.

Who else processes this data

ServiceWhat forRegion
VercelHosting and delivery. Server logs, plus privacy-friendly audience and performance measurement.USA
PostHogProduct analytics for this website, configured to store nothing on your device.EU (Frankfurt)
NeonThe Postgres database holding waitlist email addresses and anonymous CLI counts.EU
TelegramA private message to us when someone joins the waitlist, containing that email address.Outside the EU
Lemon SqueezySeller of record for BoardUI Pro: checkout, payment, invoicing and licence keys.USA

Where a provider is outside the EU, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard in that provider's terms.

How long we keep things

  • Waitlist addresses — until we launch and have told you, or until you ask us to delete yours, whichever comes first.
  • Analytics events— retained by PostHog on our plan's standard schedule. They are anonymous, so they cannot be traced back to you.
  • Purchase records — as long as tax and accounting law requires.
  • Server logs — a short rolling window set by our host.

Your rights

If you are in the EU or UK you can ask us for a copy of the personal data we hold about you, have it corrected or deleted, object to or restrict how we use it, and take it elsewhere in a portable form. Email hi@boardui.com and we will action it within 30 days, free of charge.

One honest limitation: our website analytics are anonymous by design, so we have no way to find “your” events in them — there is nothing tying them to you. That protects you, but it does mean we cannot extract or delete them individually. Waitlist and purchase data we can, and will.

You also have the right to complain to your local data protection authority if you think we have got this wrong.

Changes to this policy

If we start collecting something new, we will update this page and move the date at the top. Material changes affecting waitlist subscribers will be emailed.

Questions? hi@boardui.com — or come and ask in the Discord. Back to boardui.com.