RoadSnap turns strategy into a structured roadmap or issue tree. We collect as little personal information as we can, do not sell it, and do not track you across the web. This page explains what we hold, why, and your choices and rights.
1. Who we are
RoadSnap ("RoadSnap", "we", "us", "our") is operated by Loon Island Group, inc., which runs the website at roadsnap.app and the RoadSnap application. Our postal address is 349 Av. Kensington, Westmount, Québec, Canada, H3Z 2H2.
Our "Privacy Officer" is the person responsible for the protection of personal information under Québec's Law 25. Reach them at privacy@roadsnap.app, or by post at the address above.
2. The personal information we collect
| What | Why | Where it lives |
|---|---|---|
| Your email address | To create your account and sign you in with a one-time code (we do not use passwords). | Our authentication provider's database. |
| Your roadmap content — the titles, notes, dates, owners and fields you type | It is your work; storing it is the service. | In your browser, and — when you are signed in — synced to our database so it is available on your other devices. |
| A session cookie | To keep you signed in securely. It is strictly necessary and is not used for advertising or tracking. | Your browser (an HttpOnly, Secure cookie). |
| Feedback you send us | To learn what is and is not working. Sent only when you write a message and press send — never in the background. Feedback you send by email, or in a group we run, may be copied into the same place by a person. That copy carries your address and who copied it. | Emailed to us and kept, so what people tell us can be read together. It carries what you wrote, and your email address if you are signed in, so we can reply. It also carries a short technical list of what you were doing. The list has the version, which view you were in, how many items and levels the roadmap has, and how long you had been working. It also says whether you were signed in, your plan, window and screen size, platform, language, and the page you were on. The panel shows you that exact list before you send it. The list is built from the code that sends it; a release check fails if the two disagree. It contains nothing from inside your roadmap: no item titles, no notes, not the roadmap’s own name. Only what you send is stored; an abandoned draft never leaves your browser. |
| A search that found nothing, if you choose to send it | So a word you looked for can be added to what the product understands. | Kept with the feedback above. Only the terms you were shown and agreed to send; the panel lists them first and you can decline. Searches you do not send stay on your device. The asking can be switched off in Settings → Privacy. |
| Product usage counts | To understand whether the product works — see "Analytics" below. | Counted on your device; most of that count is also sent to us de-identified and in aggregate, once per browsing session per kind of action. Widened on 30 August 2026 — see "Analytics" below. |
| The site you arrived from, your country, and any campaign tag on the link | To see how people find RoadSnap, and where they are. Added 26 August 2026, and campaign tags on 13 September 2026 — see section 4. | Attached to the de-identified counts above, in our own database in Canada. We store the sending site's address, and on public discussion and social sites the page as well. The country is two letters, resolved before the request reaches us — we do not see or store your IP address. A campaign tag is something we wrote into the link, identical for everyone who followed it. |
| How many items are in the plan you open | To see what size of plan people build. Added 13 September 2026 — see section 4. | A number, attached to the same de-identified counts. Not the items, not which plan. |
| Your email choices, and the IP address a change came from | We must be able to show that you agreed to receive marketing email, and a date alone is weak evidence. This is a deliberate exception to how little we otherwise collect — see section 5. | Our database. Never joined to the usage counts above, never used to build a profile or work out where you are. |
| A record of which emails we sent you, and when | So we can answer “how often did you email me” accurately, and trace a suppression to the message that caused it. It never contains the content of a message. | Our database, for about 400 days. |
We do not see or store your payment card details. Stripe collects them on its own hosted pages. What reaches us is a customer reference, your plan and its status, which account it belongs to, and the billing email you gave Stripe. We do not ask for your name, phone number, address, or any special-category / sensitive information.
3. Why we use it, and our legal basis
- To provide the service — creating your account, signing you in, saving and syncing your roadmaps. (GDPR basis: performance of a contract with you.)
- To keep the service secure and working — session management, preventing abuse, fixing faults. (GDPR basis: our legitimate interests in running a secure service.)
- To understand and improve the product — de-identified, aggregate usage measurement. (GDPR basis: legitimate interests; the measurement does not identify you.)
- To send you email you ask for — your sign-in code, and, if you use review mode, the summary you choose to email to yourself. (GDPR basis: performance of a contract / your request.)
- To tell you about your own work — the weekly summary of your roadmaps, a plan that has gone quiet, a trial about to end. These are about work already in your account, not about RoadSnap, so they are on by default. Every one can be refused in one click. (GDPR basis: legitimate interests in keeping you informed about the service you use.)
- To send you marketing, only if you asked for it — product news, tips and offers. (GDPR basis: your consent, recorded as described in section 5.)
We do not use your personal information for advertising, and build no advertising or cross-site profiles.
4. Analytics — what we measure and how
We measure whether sign-up, and then what people do with RoadSnap, is working. This is deliberately de-identified and aggregate. Each event carries only the name of the action and a random identifier made fresh for that browsing session. An action name is, for example, "a sign-in code was requested" or "a branch was moved". It carries no email, no account or workspace identifier, no IP address, and never a word of your roadmap content. So it cannot be tied back to you.
What changed on 30 August 2026, said plainly. Until then most of what the app counted stayed on your device and only a narrow slice reached us. We could see how many people opened a panel, but not whether anyone restructured a plan. The list we receive is now close to the whole list. No new kind of information is collected. These are the same action names, already counted on your device and shown in Settings → What RoadSnap records about you. The same control switches them off. What changed is where the total is added up.
Each name is sent at most once per browsing session, deliberately. That answers "what share of sessions did this" and cannot answer "how many times did this person do it". That shape keeps the record impossible to attach to a human.
- We do not use third-party advertising or tracking pixels.
- We do not use session-replay tools (which record the screen).
- You can turn off usage counting entirely in the app under Settings → Privacy. The exact list of events, and the usage record held on this device, are under Settings → What RoadSnap records about you.
From 24 August 2026 that list includes how RoadSnap behaves when you are not connected. It records a session going offline, an edit made offline, and queued work sent when the connection returned. In team workspaces it also records that the single-editor lease was taken, was held by somebody else, was taken over, or was handed back. These are names and nothing else. They do not record which roadmap, how long anyone worked, what was typed, or who a lease passed between. We added them because "you can work on a plane" is a claim we would rather test than assume.
The list in the app is generated from the code that sends the events, not kept alongside it. A list kept by hand goes out of date silently. A release check fails if the two ever disagree.
Where people stop on our home page — added 26 August 2026
We could see how many people arrived at roadsnap.app and whether they signed up, and nothing in between. So four more names travel with the counts above, and they are names and nothing else. They record a button clicked, a scroll past halfway, the pricing section coming into view, and somebody staying thirty seconds.
What that is not. Not what you read, not where your pointer went, not how far you scrolled in pixels, not a recording of anything. There is still no session replay and never will be. The thirty-second timer stops while the tab is in the background: a page left open behind other work is not attention.
Why we added it: three people reached the page and left without opening the signup form. We could not tell whether they had read it and decided against us, or clicked a button that did nothing. The same switch in Settings → Privacy turns these off with everything else.
How you found us, and roughly where you are — added 26 August 2026
These events could tell us how many people arrived, and nothing about how they found us. Three kinds of field now travel with them, and the shape of each is a deliberate limit:
| What | What it is, exactly | What it is not |
|---|---|---|
| The site you came from | Its address — news.ycombinator.com, google.com. On public
discussion and social sites — Reddit, Hacker News, X, LinkedIn, Facebook, Instagram,
YouTube, Product Hunt, Medium, Substack, GitHub, Stack Overflow and a few like them — the
page as well: reddit.com/r/productmanagement/comments/abc123, so we can tell
one thread from another. |
Anywhere else, the address alone. No search terms, no query strings, nothing after a
#, on any site. Arriving from inside RoadSnap records nothing. |
| Your country | Two letters, worked out at the edge of the network before the request reaches our code. | Not your IP address, which we never see or store; not a city, region or coordinates. |
| A campaign tag on the link added 13 September 2026 |
Three short words we put into a link ourselves when we advertise or post somewhere:
a source, a medium and a campaign name — instagram, cpc,
launch-sep26. They tell an advertisement apart from somebody sharing us. |
Nothing about you. A campaign tag describes the link, not the person who followed it: everyone who clicks the same advertisement sends the identical three words. We choose them; they are not derived from anything you did. Anything that is not a short plain tag — a sentence, an address, anything with a space in it — is discarded before it is stored. |
All of them are blank more often than not. A direct visit, a bookmark, an app opened from your home screen, or a site that strips its referrer all record nothing — and a campaign tag exists only on links we tagged ourselves, which is a small minority of them. We leave blanks blank rather than guess, and we do not relabel an untagged arrival as “direct”.
They are attached to the same de-identified events. Those still carry no email, no account or workspace identifier, no IP address, and never a word of your roadmap. Country is two letters and nothing finer. The same switch in Settings → Privacy turns all of it off.
How big the plans are — added 13 September 2026
One more number travels with these events: how many items the plan you opened has. It is sent once per browsing session, as the count itself — 40, 180 — so we can see what size of plan people build and whether the product keeps working well as plans grow. It is a number and nothing else: not the items, not their titles, not which plan. The public sample roadmap is left out, and so is a plan you are reading through somebody else's share link. The same switch turns it off.
Your plan's history
When signed in, RoadSnap keeps one reading a day of each roadmap's shape: how many items it has, how many complete, how many flagged. That is so History and its trend lines survive a change of computer. These counts contain no titles, notes, names or dates from within the plan, so they add no new category to this policy. Snapshots do contain your plan's structure and field values. They are kept in your account under the same terms as the roadmap and deleted with it.
Analytics that would identify a person (for example, following one account's activity over time) are not in use. They will not be introduced without first updating this policy and, where required, obtaining your consent.
5. Email we send you, and how to stop it
You control what RoadSnap sends you in one place, and you do not need to sign in to change it. Every email we send carries a link straight to your email preferences. That matters because some of our email goes to people with no RoadSnap account, when a colleague shares a roadmap with them.
| What | Default | Why |
|---|---|---|
| Your roadmaps and your account | On | About work already in your account: a weekly reading of your own plans, a roadmap gone quiet, a trial ending. See the limits below. |
| When somebody shares something with you | On | A colleague invites you to a workspace, shares a roadmap, or mentions you in a comment. Without it the share would not reach you. |
| Tips on getting more out of RoadSnap | Off | Only if you ask for it. |
| What is new in RoadSnap | Off | Only if you ask for it. |
| Pricing and offers | Off | Only if you ask for it. Kept separate from product news, so you can follow what changes without being sold to. |
The three marked Off are sent only if you tick an unticked box. We do not pre-tick it, and we do not treat signing up as agreement to be marketed to.
One thing we cannot switch off: a sign-in code when you ask for one. Withholding it would lock you out, so it is sent whatever your preferences say. It never carries anything else.
Every email except that one carries an unsubscribe link and supports your mail app's own one-click Unsubscribe button. If your address permanently bounces, or you report one of our emails as spam, we stop sending to it and do not resume.
The weekly reading of your own plans
From 31 August 2026, if you belong to a workspace with roadmaps, we send a short summary of them on a Monday. It sits under “your roadmaps and your account” above and can be switched off there.
It is built from your own plan, and it reaches only people already in that workspace. It carries the workspace name, each roadmap’s name, and counts of what finished and what is still open. It also carries the titles of items marked blocked, together with the owner named on them. So, unlike the diagnostic list attached to feedback, it does contain words from inside your roadmap. Everyone who gets it can already open those roadmaps by signing in, so it tells them nothing new. It is composed when sent and not stored afterwards.
A week with nothing to report is skipped rather than sent. If nothing finished and nothing is blocked, no email goes out at all.
How often
Each kind has its own limit, enforced when we send rather than merely promised here. The weekly summary goes at most once in six days. The “this roadmap has gone quiet” nudge goes at most once in 25 days, and an ending-trial notice once. A busy week is a summary and one notice.
What we record about your choices, and why
When you change these settings we record what changed, when, the policy version in force, and the IP address the change came from. We must be able to show that you agreed to receive marketing email, and a date alone is weak evidence.
This is a deliberate exception to how little we otherwise collect. Our usage analytics carry no IP address. These consent records are never joined to them, never used to build a profile, and never used to work out where you are. We also record which emails we sent you and when, so we can answer "how often did you email me". Neither record contains the content of any message.
Both records are kept for about 400 days. Your preferences themselves are kept for as long as we might otherwise email you — a suppression list that forgets would start sending again.
6. Cookies
We use one cookie: a strictly necessary session cookie that keeps you signed in. We use no advertising, analytics or third-party cookies, so there is no cookie banner. The session cookie is essential, so it cannot be switched off while you are signed in. Sign out to remove it.
7. Who we share it with
We do not sell personal information or share it for anyone else's marketing. A small number of service providers ("processors") handle data only on our instructions to run RoadSnap:
| Provider | Role |
|---|---|
| Vercel | Website and application hosting, and our serverless functions. |
| Supabase | Database (your account and synced roadmaps), authentication, and sign-in code emails. |
| Resend | Delivery of our other email — the weekly summary of your roadmaps, share and invitation notices, a review summary you send to your own address. Resend receives the recipient address and that message's content. It tells us when a message hard-bounces or is reported as spam, so we can stop sending to it. |
| Stripe | Payments and subscriptions. Stripe collects your card details on its own hosted pages, and we never see or store them. We hold a customer reference, your plan and its status, and your billing email. |
The Security page lists one further supplier, HetrixTools, which checks from four cities every minute whether roadsnap.app is answering. It is not in the table above because it does not process your personal information: it never signs in and holds no account data.
Anthropic is engaged, as of 29 August 2026. It was named here in advance, while it still received nothing. So the 30 days’ notice our Data Processing Agreement owes you ran before the feature existed.
| Who | What they get, and when |
|---|---|
| Anthropic | When somebody uses it, we send Anthropic the question, and an outline of that roadmap: item ids, titles and field values. Notes are not sent with it. If answering needs the detail in a branch, the AI Assistant asks for that branch, and its notes are sent then. It can also run a web search, in which case a search phrase it composes leaves too. It also runs once when you open a roadmap, at most once a day and only on Pro and Team, to offer two short suggestions. That is a setting — Settings → Suggestions, daily, weekly or never — and turning it off stops those calls entirely. Nothing is sent for anyone on Free, or for a workspace that has switched it off. |
What we keep. For a question you ask we record when, who asked, which workspace and roadmap, token counts, cost, the outcome and how many changes it proposed. Not the question and not the answer. For its unasked suggestions we also keep the text of the two suggestions, which items they were about, who saw them and how you reacted. That is so the same suggestion is never made twice. Anthropic’s own retention is governed by our agreement with them, and we do not permit your plans to be used to train models.
The suggestions the product makes without the AI Assistant are computed in your browser and go nowhere. That covers an inherited value, a suggested priority and the critique in Insights.
Services you connect yourself
If you connect Jira or Slack, information moves between RoadSnap and that service at the instruction of someone in that workspace. It moves only for the workspace it was connected in. A Jira connection carries the Jira permissions of the person who authorised it, shared by every editor in the workspace. So connect it as somebody whose access you are content to share.
| Service | What we hold | What moves |
|---|---|---|
| Atlassian (Jira) | An access and refresh token for the site you authorised, the site name, and the address of the person who connected it. Also a table of assignee account ids and display names for that workspace. | In: issue summary, status, due date, release, parent, and who an issue is assigned to. The roadmap stores only the assignee’s Atlassian account id. The display name is held in a table of ours for that workspace. It is reported to Atlassian every seven days, as their user-privacy rules require. It is deleted the moment Atlassian says the account was closed or changed. Disconnecting Jira or closing the workspace deletes those names. Out (Team only): status and target. Automatically, that goes only for issues linked to your roadmap. Or, when somebody reviews and confirms a push by hand, for the issues in that review, including the summary if they tick it. If the workspace switches it on, the order of linked issues also goes out, as Jira’s backlog rank. |
| Slack | A webhook for the single channel you chose while installing. | Out only: the weekly digest — roadmap names, counts, and the titles of blocked items. RoadSnap cannot read your messages or see who is in your Slack workspace. |
Disconnecting either one deletes our copy of its credentials at once. An Atlassian authorisation also belongs to the account that granted it, and can be revoked from your Atlassian account settings.
We may also disclose information if required by law, or to protect the rights, safety and security of RoadSnap and its users.
8. Where your information is processed
Your account and roadmaps are stored in a database hosted in Eastern Canada (our infrastructure provider's Canada Central region). Some processing by our hosting provider — for example serving the application and routing requests — may take place elsewhere, including outside Canada. Where information is transferred outside your jurisdiction, we take reasonable steps to ensure it gets an equivalent level of protection. That includes a privacy assessment of the transfer, as Law 25 requires, and appropriate safeguards for transfers subject to the GDPR.
9. How long we keep it
The whole schedule, in one place. It is the same table our Data Processing Agreement commits to, so a lawyer and a curious reader see the same numbers.
| What | How long |
|---|---|
| A roadmap you delete | 30 days, then destroyed permanently by a scheduled job |
| Feedback and search terms you sent us | Kept while they are useful. Removed on request — ask at privacy@roadsnap.app and say roughly when you sent it |
| Usage counts (see section 4) | 400 days, then purged automatically |
| Consent records, and the log of what we sent you | 400 days |
| Backups | 7 days, then they age out |
| Your account and its content | For as long as the account is open |
| After you ask us to close your account | 30 days, then destroyed by the same scheduled job (our DPA commits to 90 as a ceiling), unless a law requires us to keep something |
| Jira assignee names (see section 7) | Until Atlassian reports the account closed or changed, or you disconnect Jira or delete the workspace |
| The AI Assistant’s metering rows and unprompted suggestions | For the life of the workspace; no fixed period, and we say so rather than imply one |
| The record of who changed which item in a roadmap, and when | 400 days, then purged automatically |
| The support console’s log of who looked at an account, and why | 400 days |
Backups are not selectively edited, and we would rather say so than imply a precision we do not have. When you delete something it goes from the live service at once. A copy may persist in a backup until that backup expires on the schedule above, protected by the same terms until it does.
- Your account and roadmaps — for as long as your account is active.
- A roadmap you delete — removed from your account and every device you sign in on at once. It is then kept for 30 days, marked deleted and unreadable through the app. An accidental deletion can be reversed by writing to us. After 30 days a scheduled job destroys it. If you were not signed in, the copy in that browser was the only copy and deleting it is final.
- Your account — close it yourself from Plan & billing → Close my account. Access and billing end at once. Everything you have is destroyed 30 days later by the same scheduled job. Inside those 30 days it can be reopened, so a mis-click costs an email rather than everything. Closing is refused while you still own a team workspace other people are working in, so one person leaving cannot delete a colleague’s work. privacy@roadsnap.app works if you would rather a person did it.
- Consent records and the log of what we sent you — about 400 days, as in section 5. Your preferences are kept for as long as we might otherwise email you: a suppression list that forgets would start sending again.
- Roadmaps stored in your browser — stay on your device until you delete them or clear your browser storage.
- De-identified analytics — kept in aggregate; as it does not identify you, it may be retained to understand trends over time.
10. How we protect it
What our own staff can see. Nobody at RoadSnap can read your plans. Our support console signs in to the database as a role that is not granted the table they live in. To help with your account, a member of staff looks you up by your sign-in address. That lookup writes a log entry — the address, a reason, who looked and when — before it returns anything. It returns metadata: when the account was made and last signed in, your workspaces, how many roadmaps and items each holds, and the plan. Never a roadmap’s name, an item, a note or a field value. The log is kept for 400 days.
Passwordless sign-in, encrypted transport, database-level isolation between accounts, a strict content-security policy, and no third-party trackers. Our Security page has the detail.
If you are a business customer putting other people's personal information into RoadSnap, you are its controller and we process it on your instructions. A completed CAIQ-Lite security questionnaire is available from security@roadsnap.app. Our Data Processing Agreement is published in full, to read, print or save as a PDF without asking us. To sign it, write to privacy@roadsnap.app.
If there is a breach, this is what we will do
- We will tell you within 72 hours of establishing that a breach affecting your personal information has occurred. Not 72 hours from finishing the investigation, which could take any length of time.
- By email, to the address on your account, and on this site if we cannot reach you. We will not wait for you to notice a notice.
- We will tell you what we know: what happened, what information was involved, what we have done, and what you may want to do. If parts are still unknown, we will say which and when we expect to know more, rather than delay the whole message.
- We will notify the regulators the law requires — in Québec the Commission d'accès à l'information, and any supervisory authority with jurisdiction where you live. We keep a record of incidents whether or not they meet a reporting threshold.
- We will tell you even when we are not obliged to, if we think you would want to know. The legal test is a floor, not our standard.
If you believe your account has been compromised, email security@roadsnap.app and we will treat it as urgent.
11. Your rights and choices
Depending on where you live, you have some or all of the following rights. Under Québec's Law 25 and Canadian privacy law, and under the GDPR for individuals in the European Economic Area and the UK:
- Access a copy of the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your account and content, and withdraw consent.
- Portability — you can export any roadmap yourself at any time from the app (spreadsheet, Markdown, or the native file format). You do not need to ask us.
- Restrict or object to certain processing, and (GDPR) not be subject to solely automated decisions — we do not make any.
- Withdraw consent to usage counting at any time in Settings → Privacy.
To exercise any of these, email privacy@roadsnap.app. We will respond within the time applicable law requires (generally 30 days under Law 25).
12. Automated decision-making
RoadSnap does not make automated decisions that produce legal or similarly significant effects about you.
13. Children
RoadSnap is a tool for work and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to this policy
We will update this page when our practices change and revise the "last updated" date above. For material changes we will take reasonable steps to bring them to your attention.
15. Contact and complaints
Questions or requests: privacy@roadsnap.app.
If you are not satisfied with our response, you may lodge a complaint with your privacy regulator. In Québec, this is the Commission d'accès à l'information (CAI). In the EEA or UK, you may complain to your local data protection supervisory authority.