Privacy Policy
Last updated June 16, 2026
Summary
1. Who this policy applies to
This Privacy Policy describes how Fearless Future ("we," "us," or "our") collects, uses, and shares information when you use Cinch at https://app.cinch.work (the "Service"). It applies to account holders and people invited into organizations on the Service.
2. Information we collect
Account information. When you register or sign in, we collect information such as your name, email address, password (stored in hashed form), profile details (for example avatar and pronouns), and authentication data if you use a third-party sign-in provider (such as Google or Apple).
Workspace content. We store the data you and your organization create in Cinch, including organizations, projects, tasks, comments, tags, custom fields, attachments, notifications, and activity history. This may include information about other people if you add them as assignees, mention them, or invite them to a workspace.
Files and attachments. If you upload files to tasks, we store them in our file storage infrastructure (cloud object storage or, in local development, on-disk storage).
Usage and analytics. When you are signed in, we may collect product analytics such as pages viewed, actions taken (for example creating a task), session identifiers, browser user agent, referrer URL, and IP address. We use this to understand how the Service is used and to improve reliability and features.
API and automation access. If you create a Personal Access Token (PAT) or connect an MCP client such as ChatGPT, we process the tool inputs and API requests needed to perform actions associated with your account, according to the scopes you grant. Hosted MCP connections route those requests through Cinch's MCP endpoint. If you instead use optional local bridge software, that software runs on your device, while its requests are still processed byCinch.
Cookies and session data. We use cookies and similar technologies to keep you signed in, remember preferences, and protect the Service.
3. How we use information
- Provide, operate, and maintain the Service
- Authenticate users and enforce organization access controls
- Send transactional messages (for example invites, password reset, email verification, and notification digests you opt into)
- Deliver in-app and email notifications based on your settings
- Monitor performance, debug issues, and prevent abuse
- Improve features and plan product development
- Comply with legal obligations
4. How we share information
We do not sell your personal information. We may share information in these situations:
- Within your workspace. Content you add to an organization is visible to members of that organization according to their roles and permissions.
- Service providers. We use trusted vendors to host the Service, send email, store files, provide authentication, and (if enabled) realtime updates. These providers process data on our behalf under contractual safeguards.
- Integrations you configure. If you connect ChatGPT or another MCP client, requested account and workspace data is returned to that client according to the scopes you grant. If your organization configures webhooks or other third-party integrations (for example Slack), data needed for those integrations is sent according to your settings.
- Legal and safety. We may disclose information if required by law or if we believe disclosure is necessary to protect rights, safety, or the integrity of the Service.
- Business transfers. If we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction.
5. Data retention
We retain account and workspace data while your account is active and as needed to provide the Service. If you delete your account or an organization, we delete or anonymize associated data within a reasonable period, subject to backups, legal requirements, and data that other members still need for shared workspaces.
6. Your choices and rights
You can update profile information in Settings. Organization administrators can manage members, projects, and organization settings. You may delete your account from account settings, which initiates removal of data associated with your user profile subject to the retention notes above.
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Contact us to make a request.
7. Security
We use administrative, technical, and organizational measures designed to protect information, including encryption in transit, access controls, and hashed credentials. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. International users
If you access the Service from outside the country where our infrastructure is located, your information may be processed in the United States or other countries where we or our service providers operate. Those countries may have different data protection laws than your jurisdiction.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us so we can delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the "Last updated" date. Material changes may also be communicated through the Service or by email where appropriate.
11. Contact us
Questions about this Privacy Policy or our data practices? Contact Fearless Future at privacy@fearless-future.com.