Security and data
Last updated 2 October 2026
This page says what Done Calm does today and what is still coming. We only list what is true now.
Where your data lives
- Done Calm runs on Cloudflare's network. Each company has its own separate storage. Other companies on Done Calm can't see or reach it.
- Cloudflare places a workspace's storage in a data centre near where it is first used. We don't offer an EU-only storage option yet. It is on our list for new workspaces.
- Workspace storage keeps a 30-day change history on Cloudflare. Scheduled backups that you can download are coming.
How sign-in works
- No passwords. You log in with a 6-digit code sent to your work email. A code works for 10 minutes and stops after 5 wrong tries, and login attempts are rate-limited.
- Sessions are signed cookies that scripts can't read. You choose how long to stay signed in, from "until I close the browser" to 30 days. Logging out ends the session.
- Coming: two-step sign-in for everyone, and Google and Microsoft single sign-on on Pro.
Protection
- All traffic uses HTTPS (encrypted in transit), with strict browser security headers.
- Owners and admins decide who can see or edit each project. Assigning a task doesn't open up a project.
- The app only accepts changes made from the app itself.
Your data, your control
- Owners and admins can export tasks, projects, team and timeline to Excel at any time.
- When you close your account, we delete workspace content within 30 days, unless the law requires us to keep something (such as invoices).
- We don't sell personal data, and we don't use your workspace content for advertising.
GDPR and data processing
- Our data processing terms (GDPR Article 28) are part of our terms. Write to privacy@donecalm.com for a signed copy.
- You can ask to see, correct, export or delete your personal data. Write to privacy@donecalm.com.
- We tell affected customers about a personal data breach within 72 hours of becoming aware of it.
Who processes data for us
- Cloudflare, Inc.: hosting, storage and security.
- Resend: login codes, invitations and service emails.
- Paddle: payments and invoicing, once paid plans are active.
We tell customers about new sub-processors in advance.
Plugins you connect
- AI assistant: owners and admins can connect Claude, ChatGPT or Gemini through their own OpenRouter account. This runs under your own OpenRouter account and terms, and usage is billed to that account. You can disconnect at any time, and you can set a spending limit on the key in your OpenRouter account.
- When someone asks the Assistant, the open tasks, projects and team names it needs are sent to OpenRouter. OpenRouter passes them only to these hosts: for Claude, Anthropic, Amazon Bedrock or Google Vertex; for ChatGPT, OpenAI or Microsoft Azure; for Gemini, Google (Vertex or AI Studio). We ask OpenRouter to use only hosts that do not collect user data, so hosts that store or train on prompts are skipped.
- The Assistant only suggests changes to tasks and teams; a person reviews and applies them. It can’t change settings, access rights or connections, or delete anything.
- The OpenRouter key stays on our servers, is never sent to the browser, and is encrypted before it is stored.
Plugin status
- AI assistant (Claude, ChatGPT or Gemini through your own OpenRouter account): Working
- Your company’s own OpenAI or Anthropic API key: Coming soon
- Shopify (read-only): Coming soon
- Xero, Exact Online and NetSuite (read-only): Coming soon
Service status and reporting a problem
- A public status page is coming.
- Found a security issue? Write to hello@donecalm.com with "Security" in the subject.