Privacy Policy

Last updated: 1 October 2026

Futur3 Board ("the app", "we") is a visual board app that runs in your web browser at board.futur3.app. It's operated by Futur3. This policy explains what information the app uses, where it goes, and the choices you have. The short version: your boards are stored in your own Google Drive or on your own computer, not on our servers.

See it as a board: Your information: Where it's stored maps out what lives on your computer, on our server and at Google, for free and paid users. What happens when you… walks through each thing you do in the app and where it's stored. Both are read-only boards, with no sign-in needed.

1. Information we store

When you sign in with Google, our server receives and stores the following, so that you stay signed in and connected to Google Drive:

This record is linked to a random session cookie in your browser. If your account isn't on the beta access list, we don't store anything and we cancel the authorisation immediately.

If you make share links, we also keep one small record per link: your Google account ID, the Drive ID of the board it shows, and whether the link and its comments are switched on. Nothing else, not even the link's label, which stays in your board file. This lets a link be switched off for good, from any device. Deleting a link deletes its record.

2. Information we don't store

3. Google Drive access

The app asks for Google's drive.file permission, the narrowest Drive permission available. It only lets the app see and change files the app itself created (your boards and the images and files you add to them). It can't list, read or change anything else in your Drive. The app also asks for your basic profile (name, email and picture) to show who's signed in.

Futur3 Board's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the app's features to you. We don't sell it, use it for advertising, or let people read it, except where you ask us to (for example, for support), where it's needed for security, or where the law requires it.

4. Share links

If you share a board, the app gives the board file (and the images and files it uses, and optionally its linked boards) Google Drive's "anyone with the link can view" setting. Anyone with the link can then view those files. When you switch off your last link, or stop sharing, the app removes that setting.

5. Comments and visits on share links

A board's owner can let people with a share link add comments. To comment, a visitor signs in with Google. We receive the visitor's Google account ID and name (not their email address), which are used to label the comment and to limit how many comments one person can send.

Visitors can't write to the owner's Drive, so a visitor's comment (its text, its position on the board, the visitor's name and the time) is held on our server until the owner next opens the board. The owner's app then copies it into the board file in the owner's Drive, and we delete it from our server. The same applies to a note that someone opened the link (their name if they signed in, otherwise "Visitor", and the time), which the owner can choose to log. We also keep a small counter per visitor per link to prevent abuse; it's deleted along with the link.

6. Comments and activity logs inside boards

Comments, replies and the board's activity log (who opened, commented on, shared or, if switched on, edited the board, and when) are saved inside the board file in your Drive or on your computer, like the rest of the board. Anyone who can open the board file can read them. The board's creator can switch logging off or delete the log at any time from Board activity in the app.

7. Data kept in your browser

The app keeps some data in your own browser: your preferences (such as your default save location), the folder you picked on your computer, and a backup copy of the board you have open, so work isn't lost if the tab closes. This stays on your device. Clearing your browser's site data removes it.

8. Cookies

The app uses one cookie, __session, which keeps you signed in. It's essential, contains only a random identifier, and isn't used for tracking.

9. Service providers

10. Keeping and deleting your data

Your sign-in record is kept until you disconnect, your session expires (180 days at most), or Google tells us the authorisation was withdrawn. Choosing Disconnect or Log out in the app revokes the Google authorisation and deletes the record straight away. You can also remove the app's access at any time from your Google Account permissions.

Your boards are yours: delete them from your Drive or your computer whenever you like. We have no copy to delete.

Visitors' comments and visits waiting on our server are deleted as soon as the board's owner opens the board, or when the owner deletes the link. If you commented on someone's board and want your comment removed afterwards, ask the board's owner; it lives in their file.

11. Security

All connections use HTTPS. Stored Google tokens are encrypted, the encryption key is kept separately in Google Secret Manager, and the database can't be read from browsers.

12. Children

The app isn't directed at children under 13, and we don't knowingly collect information from them.

13. Your rights

Depending on where you live, you may have the right to access, correct or delete the information we hold about you, or to object to how it's used. Contact us and we'll help. Disconnecting in the app deletes everything we store about you. California residents have these rights under the California Consumer Privacy Act; we don't sell or share personal information.

14. Changes

If we change this policy, we'll update the date at the top. For significant changes, we'll let you know in the app.

15. Contact

Questions about privacy: privacy@futur3.app. Help with the app: support@futur3.app.