Skip to content
Privacy & LegalPrivacy Policy

Privacy Policy

Last Updated: September 23, 2026Effective Date: September 23, 2026Version: 2026.210 min read

1. Introduction

ExactlyHow, Inc. ("ExactlyHow", "we", "our", or "us") operates exactlyhow.io and the ExactlyHow application (together, the "Services"). This Privacy Policy explains how we collect, use, and share personal information when you visit our marketing site or use the Services.

2. Scope

This policy covers personal information we collect as a business: account details, billing records, support messages, and usage of our websites and application.

The organization that opens an ExactlyHow workspace (the "Customer") decides what operational knowledge, files, comments, and other workspace content to put in the Services ("Customer Content"). For that Customer Content, the Customer is the controller and ExactlyHow is the processor. That processing is governed by our Data Processing Addendum and the Customer's own policies, not the rest of this Privacy Policy.

This policy does not apply to third-party sites or services that link to or from ExactlyHow.

3. Information We Collect

We collect the following categories of information:

  • Account information: name, email address, and optional profile details such as job title, avatar, and organization name.
  • Workspace access: the access assigned in an organization (Owner, Editor, or Viewer, plus Admin as a Business add-on).
  • Customer Content: process titles, steps, owners, departments, teams, job titles, attachments, comments, and similar operational knowledge the Customer uploads. We process this on the Customer's behalf.
  • Usage and log data: pages and features used, search queries inside a workspace, ownership-transfer activity, IP address, browser type, approximate timestamps, and diagnostic events needed to operate and secure the Services.
  • Device and preference data: theme preference and similar settings stored locally in your browser, and a record that you accepted our Terms (with the date and the version you accepted) when you create an account.
  • Support and communications: messages you send us through email or our demo and question forms, including name, work email, organization, role, and what you asked to see or needed help with.
  • Billing information: subscription plan, prepaid creator-seat count, billing cycle, Stripe customer and subscription identifiers, and invoice status. Card and bank details are collected and processed by Stripe. ExactlyHow does not store full card numbers.
  • Cookies and similar technologies: see our Cookie Policy.

ExactlyHow does not ask you for tax identification numbers, and we do not collect mobile-network identifiers or advertising profiles or run third-party advertising pixels on the Services. If Stripe asks for a billing address or tax details at checkout, Stripe collects and processes them under its own policies.

4. How We Use Information

We use personal information to:

  • Provide, maintain, and improve the Services, including search and ownership transfer.
  • Authenticate users and enforce role-based permissions.
  • Detect, investigate, and prevent abuse, fraud, and security incidents.
  • Process subscriptions and send billing receipts.
  • Respond to support, privacy, legal, demo, and product questions.
  • Send service messages such as security alerts, invites, and product notices.
  • Diagnose errors (including through Sentry) and understand aggregate product usage.
  • Comply with law and enforce our Terms of Service.

We may use de-identified or aggregated information that cannot reasonably identify you to improve the Services.

6. Sharing Information

We do not sell personal information and we do not share it for cross-context behavioral advertising. We disclose personal information only:

  • Service providers: companies that host, authenticate, bill, email, or monitor the Services for us, including Supabase, Cloudflare, Stripe (and the wallets it supports, such as Apple Pay and Google Pay), Resend, Sentry, and, if you choose Google or Microsoft sign-in, Google or Microsoft. We also use Google Workspace for our support and legal inbox. They may process data only to provide those services. A current list is on our Privacy & Legal page.
  • Legal requirements: if we believe disclosure is required by law, court order, or to protect ExactlyHow, our customers, or the public.
  • Business transfers: in connection with a merger, financing, or sale of assets, subject to appropriate confidentiality.
  • Customer-directed sharing: when an organization administrator invites users or otherwise instructs us to disclose workspace information.

7. International Transfers

ExactlyHow is based in the United States. Personal information may be processed in the United States and in other countries where our providers operate. Those countries may not provide the same legal protections as your home country. Where required, we rely on approved transfer mechanisms used by us or our providers, such as Standard Contractual Clauses, and we will enter additional transfer terms when legally necessary.

8. Data Retention

We keep account and billing information for as long as the account is active and as needed for tax, accounting, and legal obligations. Customer Content is retained until the Customer deletes it or the workspace is closed, after which we delete it from active systems within a commercially reasonable period, subject to backup cycles and any legal hold. Support records are kept as long as reasonably needed to resolve the request and maintain the Service.

We also apply these specific periods:

  • Invitations: expired or revoked invitations are deleted after 30 days, and accepted invitations after 90 days.
  • Notifications: in-app notifications are deleted after 180 days.
  • Join requests: resolved requests to join an organization are deleted after 180 days.
  • Billing event records: the technical records we keep to process Stripe events once are deleted after 90 days. Invoices and subscription history stay with Stripe and in our accounting records as the law requires.
  • Audit logs: an organization's audit log is kept while the organization is active and is deleted when the organization is deleted. When a person deletes their account, their name and email address are removed from audit entries. The entries themselves stay for the organization's records.
  • Demo and question requests: forms are delivered to our support inbox by email. We keep them as long as needed to respond and for reasonable business records.

You can delete your account in the application (Profile), which removes your login, profile, and avatar and erases your name and email from audit entries and from billing records we control. Deleting an organization also cancels its Stripe subscription and deletes the Stripe customer record, except for records Stripe or the law requires us to keep. Copies in encrypted backups age out on our infrastructure vendors' backup cycle.

9. Security Practices

We use commercially reasonable safeguards, including encryption in transit (TLS) and encryption at rest and backups provided by our infrastructure vendors (Supabase and Cloudflare), role-based access controls, and application monitoring. Paid checkout is handled by Stripe. No method of transmission or storage is completely secure. You are responsible for protecting your credentials and for the content you choose to store.

10. Customer Responsibilities

Customers control who they invite and which roles they assign. Customers must not upload content they are not allowed to share. The Services are not designed for protected health information, cardholder data (other than payment details handled by Stripe), government-classified information, or other specially regulated data, and we do not offer a Business Associate Agreement unless we sign one in a separate written contract.

11. User Rights

Depending on your location, you may have the right to:

  • Access personal information we hold about you.
  • Correct inaccurate personal information.
  • Delete personal information, subject to legal exceptions.
  • Export a copy of personal information you provided to us, where technically feasible.
  • Restrict or object to certain processing.
  • Appeal a denial of a privacy request, where the law provides that right.

You can download a copy of your personal data and delete your account yourself from Profile in the application, or submit a request through our Privacy & Legal page. For other requests about information ExactlyHow controls (your account and billing), email exactlyhowsaas@gmail.com. For Customer Content, contact your organization's administrator first. We will verify requests before acting on them.

12. California Privacy Rights

If you are a California resident, you have the rights described above under the CCPA / CPRA, including the right to know, delete, correct, and opt out of sale or sharing of personal information. ExactlyHow does not sell personal information and does not share it for cross-context behavioral advertising. We do not offer financial incentives for personal information. We will not discriminate against you for exercising your rights. Authorized agents may submit requests with proof of authority.

13. GDPR Rights

If you are in the EEA, UK, or Switzerland, you may also lodge a complaint with your local supervisory authority. For Customer Content, your organization's administrator is the right first contact. For account data we control, contact exactlyhowsaas@gmail.com.

14. Children's Privacy

The Services are for business use by adults. You must be at least 18 to create an account. We do not knowingly collect personal information from children under 18. If we learn that we have, we will delete it.

15. Third Party Services

Links or integrations to third-party services are governed by those parties' policies. We are not responsible for their practices.

16. Cookies

We use cookies and similar technologies that are needed to run the Services, keep you signed in, remember preferences, and diagnose errors. In the signed-in application, Sentry may record masked session replays (all text is masked and media is blocked) to help us fix bugs. Details are in our Cookie Policy.

17. Policy Updates

We may update this Privacy Policy. We will post the new version on this page and change the "Last Updated" date. For material changes, we will also email the account owner or show an in-app notice when reasonably possible. Continued use after the effective date means you accept the updated policy.

18. Contact Information

Questions about this policy or privacy requests:
ExactlyHow, Inc.
Attn: Legal / Privacy
Austin, Texas, USA
Email: exactlyhowsaas@gmail.com

Questions about our legal policies?

If you have questions regarding our privacy practices, legal terms, data processing, or enterprise procurement requirements, contact the ExactlyHow team at exactlyhowsaas@gmail.com.