Privacy Policy
Last updated 12 August 2026.
Excubia is run by Thomas Løvring, CVR 33220510, A. F. Beyers Vej 3, 2. tv., 2720 Vanløse, Denmark. Write to hello@excubia.dk with anything on this page you want answered, corrected or acted on.
This page covers excubia.dk, the Excubia app and the emails we send. It says what we hold, why we hold it, and who else touches it on the way.
Which hat we are wearing
Excubia handles personal data in two different capacities, and which one applies decides who you should ask for what.
- We are the data controller for people who join the waiting list and people who hold an Excubia login. We chose to collect that data and we decide what it is for.
- We are a data processor for everything an agency puts into Excubia about its own clients — a contact name, an email address, a note on a task. The agency decides what goes in and why. We act on their instruction and nothing else.
If your details are in Excubia because an agency you work with put them there, that agency answers your request, not us. We will help them do it. What we owe the agency as a processor is written down in the data processing agreement, which applies without being signed.
The waiting list
The signup form on the front page asks for your email address. Name, agency and roughly how many sites you look after are optional, and they exist so we know who is asking.
We use it to send you one confirmation email, and later to tell you when there is a place for you. Nothing else. The basis is your consent, and you can withdraw it at any time by writing to hello@excubia.dk.
- The confirmation link is valid for seven days.
- A signup that is never confirmed and never touched by us is deleted after fourteen days.
- We may add an internal note to a signup — what we talked about, whether you are a fit. You can ask to see it.
Your account
An Excubia account holds your email address, your name if you give one, and which organisation you belong to. There is no password: you log in with a one-time code sent to your email, so there is no password for us to lose.
We use it to let you in, to show your colleagues who did what, and to send you the notifications you have turned on. The basis is the agreement between your agency and us.
What your agency puts in
Excubia is built to hold the work an agency does for its clients: clients and their contacts, sites, service agreements, tasks, comments, logged hours and file attachments. Some of that is personal data about people who never signed up for anything — a contact person at a client, for instance.
We do not decide what goes in there and we do not use it for anything of our own. We do not sell it, and we do not train anything on it. We look at it when we are asked to help with a problem, or when we have to in order to keep the service running.
The sites you connect
For each connected site we store the address and what our checks saw: HTTP status codes, response times, TLS certificate details, WordPress and plugin versions, and the result of updates we ran. Check history is deleted after 90 days.
Connecting a WordPress site stores a credential for that site. It is kept in Supabase Vault, which holds it encrypted, and it is deleted when the site is disconnected — the row and the secret both.
Cookies
We set cookies to keep you logged in. That is the whole list.
The public pages count visits with Plausible. It sets no cookies, writes nothing to your browser, and builds no profile that follows you from one site to the next. So there is still nothing to ask your consent for and no banner to click away.
There is no analytics inside the app itself, and no advertising anywhere.
Who else processes your data
Running Excubia means a handful of suppliers see some of it. They act on our instruction and may not use it for their own purposes.
- Vercel — hosting for the website and the app. Our code runs in Vercel's Dublin region. Static files — stylesheets, images, the front page — are cached on their global network.
- Supabase — database, login and background jobs. Our project runs in Ireland, region eu-west-1.
- Cloudflare R2 — storage for file attachments. The bucket sits in Cloudflare's EU jurisdiction, which keeps the files inside the EU rather than wherever is nearest.
- Resend — sending email. What reaches them is the recipient's address and name, and what the message is about: a task title, a project name, who did something. Never the contents of a comment. Our mail is sent from their Irish region, but Resend stores the send log in the United States under the standard contractual clauses in their data processing agreement. The log is kept for 30 days.
- Plausible — counting visits on the public pages. They see which page you asked for, the site you came from, and roughly where in the world you are. No cookies, and no identifier that survives the day. Nothing from inside the app reaches them. Plausible is an Estonian company and the data stays in the EU.
If you connect Dinero or Slack, those run on your own account with your own agreement, and we send data there because you told us to. Their terms and privacy policies apply to what happens at their end.
The full list — what each supplier sees, where it sits, and the basis for any transfer out of the EU — is at subprocessors. We tell you before a new one starts processing anything.
How long we keep it
- Waiting list: until you ask us to remove you, or until the beta is over and the list has done its job. Unconfirmed signups go after fourteen days.
- Account and agency data: while the account exists. When an agency leaves, the data is deleted within 30 days, apart from what we have to keep for accounting.
- Check history: 90 days.
- Email: 30 days at Resend, so we can tell whether a message arrived. Our own record of what we sent — the address, the subject and whether it failed — stays for as long as the organisation exists and is deleted with it.
- Server logs: our host keeps short-lived request logs that include IP addresses.
Your rights
You can ask for a copy of what we hold about you, have it corrected, have it deleted, have it sent somewhere else, or object to what we are doing with it. Where we rely on consent, you can withdraw it, and that does not affect what happened before.
Write to hello@excubia.dk. We answer within a month.
If you think we are handling your data wrongly and we cannot sort it out between us, you can complain to Datatilsynet, the Danish Data Protection Agency, at datatilsynet.dk.
Changes
When this policy changes in a way that matters, we email everyone with an account before it takes effect. The date at the top says when it was last changed, and the history of every version is kept in our source repository.