Privacy policy

This policy explains how the Pekan website and the free local Pekan Desktop application handle personal data. Pekan Cloud is a separate private alpha and is not part of the public desktop offering described here.

1. Who is responsible

Pekan is currently provided under the trading name Ejstrup Development by Martin Ejstrup, an individual operator based in Denmark. The verified contact details are available on the Legal & contact page. For privacy questions or requests, email hello@ejstrup.dev.

No Data Protection Officer or EU representative has been appointed because neither role is currently required. This statement must be reassessed if the product, organization, or processing changes.

2. The public website

The public website does not have accounts, contact forms, a waitlist, advertising, analytics, session replay, or third-party tracking. It sets no cookies and uses no browser storage. Fonts and other page assets are served from the same site.

The website host, Vercel, processes delivery, request, and security information such as IP address, approximate location derived from IP, request time, requested URL, user-agent, system configuration, and error information. Vercel makes runtime logs available to the operator for up to one hour on the Hobby plan. Vercel may retain other service-generated information for longer where needed to operate, secure, and improve its services; its privacy notice does not state one fixed deletion period for all such information.

Cloudflare provides authoritative DNS for the domain. Its Free plan provides up to eight days of historical DNS analytics. Cloudflare is not currently intended to proxy the website's HTTP traffic; this statement must be rechecked against the live DNS proxy setting before publication.

External sites receive information only after you choose to follow an outbound link. Their own privacy policies then apply.

3. Data in Pekan Desktop

Pekan Desktop is a local application. It does not require a Pekan account. The desktop application does not make Pekan Cloud registration, hosted boards, billing, or entitlements available.

The application can access and store the information you choose to manage with it, including:

  • projects, boards, columns, tasks, comments, plans, workflows, notifications, and activity history;
  • attachments, linked project folders, repository paths, worktrees, and file metadata;
  • application settings, recovery snapshots, backups, agent-run records, terminal sessions, and local usage aggregates; and
  • provider settings and secrets that you choose to configure.

This information is stored on your Windows device in Pekan's application-data and user-selected project locations. It is not uploaded to or accessible by the Pekan operator. Secrets that Pekan persists, such as an optional OpenAI API key, use operating-system-backed encryption when it is available. Pekan disables storage of that key when secure storage is unavailable.

4. Local integrations and AI providers

Pekan includes a loopback HTTP and MCP server so software on your computer can work with your board. When you explicitly connect a coding agent or another local tool, that tool can read or change the board and project information allowed by the integration. Local access should be granted only to software you trust.

Pekan can launch separately installed third-party coding-agent command-line tools. Before a provider run, Pekan identifies the selected provider and the relevant context or files. The provider may process prompts, project information, file contents, account identifiers, and generated output under its own terms and privacy policy. These are user-selected services, not services the Pekan operator uses to receive or analyse your project data. Pekan does not receive their prompts or responses.

You use those providers under your own account and your own agreement with them. For that flow the Pekan operator is neither a data processor nor a joint controller: it runs no server that receives your prompts, files, audio, or the responses, and it has no access to your provider account. Deciding what to send, and on what legal basis, is yours.

This matters most when a project contains other people's personal data. Sending a folder to a coding agent can send the file contents with it, including customer records, colleagues' details, or anything else that happens to sit in the repository. Before you do that, satisfy yourself that your agreement with that provider allows it, including any data-retention or training terms, and that you have a basis for the transfer. If you handle such data professionally, check your own organisation's rules first.

The optional Voice feature is disabled until you configure it. If you enable it and provide your own OpenAI API key, recorded audio is sent directly from the application to OpenAI for transcription. Pekan keeps the audio in memory for the transcription request and does not write the audio to disk. The resulting text can be stored locally when you insert, confirm, or save it. OpenAI processes the request under the terms associated with your API account. See the OpenAI privacy policy.

AI-generated material is labelled in the application. If you choose to report AI output, Pekan processes the contact details, description, provider and feature metadata that you submit. Generated output or project information is included only when you explicitly choose to include it.

5. How the application is distributed

Pekan Desktop is currently a public alpha distributed as a direct download from GitHub Releases. It is not distributed through Microsoft Store or any other app store.

When you download a build, GitHub processes the request under its own terms and privacy statement. This ordinarily includes your IP address, the time of the request, and the file requested. The operator can see aggregate download counts per release. No Pekan account is involved in the download, and the operator does not receive your GitHub identity from a download.

The application does not update itself during the alpha, so it does not contact a release server after installation. Alpha builds are not code signed, and each release publishes SHA-256 checksums you can use to verify a download before running it.

6. Information the operator receives

The operator receives personal data only through the limited channels below:

PurposeInformationLegal basis
Deliver and secure the websiteHosting and security logsLegitimate interests, GDPR Art. 6(1)(f)
Respond to support, privacy, or legal messagesYour contact details, message, and related correspondenceLegitimate interests or steps requested before a contract, Art. 6(1)(f) or (b)
Investigate an AI-output or safety reportThe report and any optional material you choose to attachLegitimate interests, Art. 6(1)(f)
Maintain and distribute the desktop releaseAggregate download counts per release, made available by GitHubLegitimate interests, Art. 6(1)(f)

Pekan does not sell personal data, build advertising profiles, or use local desktop content for product analytics or AI-model training.

7. Recipients and international transfers

Website delivery and service-generated request data is processed by Vercel, and authoritative DNS queries are processed by Cloudflare. Support and privacy correspondence is routed through Cloudflare Email Routing and stored using Google's Gmail service. GitHub acts under its own terms for the distribution of desktop downloads.

User-selected coding-agent providers and OpenAI voice transcription receive information only following the choices described in section 4. Their locations, retention, and transfer safeguards are governed by the provider and your account agreement with that provider.

The operator-selected services above include providers established in the United States, so some personal data is transferred outside the EU/EEA. Those transfers rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the Commission's standard contractual clauses together with the provider's data processing agreement. You can ask which basis applies to a given provider using the contact details above.

8. Retention

  • Local desktop data remains on your device until you delete it. Backups and exported copies remain where you placed them until you remove them.
  • Vercel Hobby runtime logs are available to the operator for up to one hour. Vercel retains other service-generated request information for as long as it considers necessary for the purposes described in its privacy notice, without publishing one fixed duration for every category.
  • Cloudflare Free authoritative DNS analytics provide up to eight days of historical data. If Cloudflare's HTTP proxy is enabled later, this retention statement will be reviewed before the change goes live.
  • Routine support, privacy, legal, and AI-report correspondence may be deleted earlier and is deleted no later than 24 months after the matter is closed. It is kept longer only where needed for an active dispute or legal obligation.
  • Pekan does not retain voice audio. The retention applied by OpenAI is governed by your OpenAI API arrangement.

9. Your controls

You decide what to put in Pekan, which folders to link, which local tools to connect, and whether to configure an AI or voice provider. You can cancel a proposed sharing action, disable Voice, remove provider credentials, delete board content, create backups, export data, and remove Pekan's application data from Windows.

Because local desktop content is not held by the operator, the operator cannot inspect, export, correct, or recover it for you. Your own backups are the recovery mechanism.

10. Your data-protection rights

For personal data held by the operator, you may have rights to access, correction, erasure, restriction, objection, and portability. Where processing relies on consent, you can withdraw it without affecting earlier processing. Contact hello@ejstrup.dev. We normally respond within one month.

You may complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, or to the supervisory authority where you live or work. See datatilsynet.dk.

11. Security

Pekan Desktop keeps your work in local storage and binds its API and MCP servers to the loopback interface, so they are not reachable from your network. It uses operating-system protection for persisted secrets where available, and requires an explicit action from you before any optional provider transfer. You remain responsible for securing your Windows account, device, repositories, backups, API accounts, and connected local software.

12. Pekan Cloud private alpha

Pekan Cloud is not included in the desktop release and is not generally available. Any invited private-alpha processing must be covered by an alpha-specific notice before participant data is collected. This policy will be updated before a public hosted service or paid cloud storage launches.

13. Changes

This policy will be updated when Pekan's processing changes. The date at the top will show the latest revision. Material changes will be communicated where required.