◦ Legal
Privacy Policy
Last updated July 20, 2026
This policy explains how AccessExit, operated by Eastbase Studio, collects, uses, stores, and protects your data. It is written to match how the product actually works. For processor commitments covering workspace content, see our Data Processing Terms.
1. Who controls your data
AccessExit, operated by Eastbase Studio, is the data controller for account data and the marketing site. For the content inside a workspace (your people, apps, cases, and evidence), your organization is the controller and AccessExit acts as a processor on your behalf, as set out in our Data Processing Terms.
2. What we collect
- Account data — your name, email, and a hashed password (handled by our authentication library; we never store plaintext passwords). If you choose to sign in with Google or GitHub, we receive your basic profile and email from them.
- Workspace content — the people, app inventory, account mappings, offboarding cases, tasks, evidence (notes, links, files), and receipts you create.
- Integration data — when you connect Google Workspace, the directory data you sync. OAuth tokens are encrypted at rest.
- Usage & diagnostics — only when the optional analytics and error-monitoring tools below are enabled. We do not use ad tracking, session replay, or autocapture.
3. Responsibility for people and third-party data
AccessExit stores information about employees, contractors, vendors, and other third parties. As the controller of your workspace content, you are responsible for having the necessary rights, notices, consents, and lawful basis to process that people, app, access, and evidence data through AccessExit.
Please don’t upload sensitive material as evidence. Do not upload secrets, credentials, API keys, access tokens, private keys, payment card data, government IDs, health data, highly sensitive HR records, confidential customer data, or personal data unrelated to offboarding. Redact screenshots and files before uploading unless you have a clear reason and the authority to store the material. AccessExit is not designed to hold secrets or regulated data.
4. How we use your data
- To provide the service — generate checklists, track tasks, produce receipts, and run access reviews.
- To operate accounts, workspaces, and billing.
- To send transactional and notification email (assignments, reminders, ready receipts).
- To keep the service secure and reliable, and to understand aggregate product usage where telemetry is enabled.
We do not sell your data and we do not use your workspace content to train AI models — the product has no AI features.
5. Google Workspace data
When you connect Google Workspace, AccessExit may process the authorized directory data you sync — such as user accounts, names, email addresses, account status (including suspension), admin/role flags, and group memberships — for directory sync, access mapping, and account-suspension verification. We request read-only, least-privilege scopes (today, read-only Directory user data), and OAuth tokens are encrypted at rest.
AccessExit’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data is used only for the user-facing AccessExit features you authorize.
6. Cookies and analytics
AccessExit uses a small, essential session cookie to keep you signed in. We take a conservative approach to analytics:
- Product analytics (PostHog) record explicitly named events only — no autocapture, no session replay, and no personal data. Identification uses an opaque id.
- Vercel Web Analytics and Speed Insights measure aggregate traffic and performance.
- Error monitoring (Sentry) captures diagnostics when something breaks.
- URLs sent to any of these tools are stripped of ids and tokens first, and the public receipt page is never tracked.
Every telemetry tool is off unless configured, so self-hosted and development environments run with no third-party tracking.
7. Subprocessors
We rely on the following providers to operate AccessExit. Providers marked Optional are inert unless their keys are configured, so they process data only when you enable the related feature.
| Vendor | Purpose | Data processed | Required | Region / hosting | Privacy / DPA |
|---|---|---|---|---|---|
| Vercel | Application hosting, web analytics & speed insights | Request metadata, aggregate traffic and performance | Required | US provider; global edge network | Policy |
| Neon | PostgreSQL database hosting | Your workspace records (people, apps, cases, receipts) | Required | Serverless Postgres; region set at provisioning | Policy |
| Vercel Blob | Private file storage | Evidence files you upload | Required | US provider; global object storage | Policy |
| Lemon Squeezy | Payments — merchant of record | Billing details, plan and subscription status | Required | US provider | Policy |
| Resend | Transactional & notification email | Recipient email, message metadata | Optional | US provider | Policy |
| Upstash | Rate limiting (Redis) | Hashed IP-based request counters | Optional | Region set at provisioning | Policy |
| PostHog | Product analytics (named events only) | Opaque workspace/user id, event names — no PII | Optional | US or EU Cloud (set at setup) | Policy |
| Sentry | Error & performance monitoring | Error reports with ids/tokens scrubbed | Optional | US or EU (set at setup) | Policy |
| Directory integration & optional sign-in | Directory data you sync; OAuth account email | Optional | Global (Google LLC) | Policy |
8. Data retention
We keep your workspace content for as long as your workspace is active. When you delete your workspace, we aim to delete or anonymize active-system workspace content within 30 days.
- Backups, security logs, audit logs, email-delivery logs, and diagnostic records may persist up to about 90 days before they are deleted or overwritten.
- Billing, legal, and accounting records may be retained for longer where we are required to keep them.
9. Audit events and deleted evidence
Audit events may remain append-only to preserve the integrity of the record. When you delete a piece of evidence, AccessExit may retain the deletion event itself, but removes or makes inaccessible the underlying file in line with the retention rules above. If you need something permanently purged sooner, contact us.
10. How we protect your data
- Integration tokens are encrypted at rest (AES-256-GCM); passwords are hashed, never stored in plaintext.
- Evidence files are stored private and served only through an authenticated, access-checked download route.
- Integrations request least-privilege, read-only scopes where possible.
- Public auth endpoints are rate-limited, and receipts are reachable only via an unguessable 256-bit token.
11. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Within the product you can export receipts and access reviews to CSV (on paid plans) and delete people, apps, and evidence. To exercise any other right, or to request deletion of your whole workspace, email support@eastbase.studio.
12. International processing
AccessExit is operated from Vietnam, and the providers listed above may process data in the United States and other countries. Where such transfers require additional protection, we rely on the appropriate safeguards those providers make available (such as standard contractual clauses offered under their data-processing terms). We don’t claim safeguards or regions we haven’t confirmed with a provider.
13. Children
AccessExit is a workplace tool and is not intended for users under 16. We do not knowingly collect personal data from anyone under 16.
14. Changes and contact
We’ll update this policy as the product evolves and revise the date above. For any privacy question or request, email support@eastbase.studio.