Private work should stay private.
Wispboard separates private canvas data from the small amount of information needed to run accounts, collaboration, recovery, and first-party statistics.
Boards are not public by default
Saved boards require an authenticated owner or collaborator. Sharing creates a revocable invitation. Search engines are instructed not to index board, invite, workspace, testing, or administration URLs.
Local drafts and recovery
Anonymous work is stored primarily in the current browser. A pseudonymous server recovery copy is updated periodically and expires according to the retention setting; it is not published as a searchable board.
Accounts and email
Account records contain the information needed for sign-in, ownership, verification, and password recovery. Passwords are stored as cryptographic hashes. Google sign-in is optional and can be linked or disconnected with lockout protection.
First-party analytics
Optional analytics records pseudonymous visits, approximate country or region, device category, browser, referrer, and page activity. Raw IP addresses are not retained in analytics, and optional measurement remains disabled until consent.
Administrative access
The administrator can manage accounts and boards and generate read-only board previews. Administrative preview does not join collaborator presence or appear as another user on the board.
Your controls
You can reject optional analytics, revoke board invitations, disconnect collaborators, delete owned boards, export important work, and change recovery or Google-account settings from your profile.