Privacy at Back
Last updated August 28, 2026 · In effect from August 28, 2026
Back makes four things: Backburner (a task list), Backpack (files, documents and spreadsheets), Backdrop (a video editor) and back.dev (this site). One Back account signs you into all of them. This page explains what we hold about you, why, where it is, and what you can make us do about it.
We don't sell your data. We don't run ads. There are no third-party tracking or advertising pixels in any Back product — we read the shipped code to be able to say that.
Who is responsible
Back is a trading name of Tom Grady, a sole proprietor based in Washington State, in the United States. Tom is the data controller for everything described here. Write to him about any of it at privacy@back.dev.
Back has no office, company or representative in the UK or the EU. If you are in the UK or the EEA, that means there is no local agent to go through: write to the address above and you are writing to the person responsible. If that ever changes we will name them here.
What we hold, and why
Your account — all products
Your email address, a hash of your password (scrypt — we never store the password itself), your first and last name if you give them, and your settings. We need this to have an account for you at all. Lawful basis: performing our contract with you.
Backburner
Your tasks, goals, initiatives, projects, records, comments and links; the order you put things in; and what you mark done. Contract.
We also keep a log of your actions in the app — that you completed, skipped, reordered or created something, which item it was, and the hour of your local day it happened. This is not anonymous and it is not aggregate: it is per-user, and Backburner uses it to learn how you work so it can rank your list. It is used for you alone. It is never pooled with other people's data, never used to train a shared model, and never sent to any AI provider. Contract, because the ranking is the product.
Backpack
Your files, folders, documents and spreadsheets, and their contents. Share links you create, and which of them are switched on. Contract.
Worth knowing how the storage works: the bytes of an uploaded file live in Vercel's object store at a long, unguessable web address. That address is not guessable and we never publish it — but it is not password-protected either. Anyone you give a share link to, or anyone who obtains one of those addresses, can fetch the file. Turning a share off gives the file a brand-new address, which is what makes the old link stop working.
Backdrop
Your project structure, edit lists, comments and approvals. Contract.
About your video — read this bit. Editing happens in your browser: cutting, transcoding and captions all run on your own machine, and nothing is uploaded just to edit. But two things do send video to us, and you should know which:
- If you are signed in, Backdrop saves your original into your Backpack so you don't lose it. That is a copy on our servers.
- If you invite someone to edit with you, a preview copy goes to our sync server so that they can see it.
If you use Backdrop signed out and never share a project, your footage genuinely never leaves your device. If you sign in or share, it does. We would rather say that plainly than repeat a slogan that isn't true for everyone.
Feedback
If you turn on the feedback button — it is off unless you switch it on — and then file a report, we receive: your note, the thing you pointed at, the page you were on, your browser's user-agent string, your window size, and a trail of roughly the last 60 things you clicked or pages you visited in that session. The trail is there so a bug report makes sense without a conversation. It can contain the names of your own tasks, files or pages, so treat it as you would a screenshot. Lawful basis: our legitimate interest in fixing our software — and you can object at any time by leaving the button off, or by asking us to delete a report.
If someone asks Backdrop for an invite
The invite form takes a name, an email address and a note. If somebody enters your details there, we hold them so we can reply. Legitimate interest in responding to an enquiry. Write to us and we will delete them.
What you type is up to you
Task titles, notes, documents, spreadsheets and comments are free text, so they can hold anything — including things about your health, your money, or other people. We never ask for any of it and we don't treat it as a special category. The only thing Backburner works out from a task's wording is what kind of action it is: reaching out, reviewing, creating, organizing, learning, or none of those. Those six are the whole list in the code, and none of them is a health category, so nothing Backburner works out says anything about your health. We never sell or share what you write, and we never pass it to an advertiser or an analytics company, because we don't use either.
Even so, the honest advice: don't put anything in a task title you would mind being in a database.
Cookies and local storage
We use two cookies and no others.
| Cookie | What it does | Consent needed? |
|---|---|---|
bb_session | Keeps you signed in across the Back products. Signed, HttpOnly, Secure. | No — strictly necessary |
back_theme | Remembers light or dark mode. | No — it only stores a setting you chose |
Both are exempt from consent under UK PECR and the ePrivacy Directive because they are strictly necessary to deliver something you asked for. We run no analytics and set no advertising or measurement cookies, which is why you don't see a cookie banner. If that ever changes we will ask you first, properly, before setting anything.
The products also keep some things in your browser's own local storage so they work offline and remember your place. That stays on your device.
Do Not Track. We don't track you across other websites, so there is nothing for a Do Not Track signal to switch off, and we do not respond to one. No third party collects information about what you do on other sites through anything we run.
Who else touches your data
We keep this list short on purpose.
| Who | What they do | Where |
|---|---|---|
| Vercel | Runs the sites and the API, stores uploaded files, keeps server logs | United States |
| Neon | The database — everything described above | United States |
| Forward Email | Receives mail sent to any @back.dev address and forwards it on | United States |
| The mailbox that forwarded mail lands in, so we can read and answer it | United States | |
| Anthropic | Back is built with an AI coding assistant. When you file a feedback report, we read it — and so does that assistant, because it is what fixes the bug. See below. | United States |
No analytics provider, no advertising network, no data broker. If we ever add an email provider to send password-reset messages, it will be listed here before it sends anything.
About the AI assistant, plainly. Back is built almost entirely with an AI coding assistant. Your ordinary content — your tasks, files, documents and video projects — is never sent to it, and nothing you store is ever used to train any model, ours or anyone else's.
The one exception is feedback reports. If you file one, its text and the context that came with it are read by whoever is fixing the bug, and that is often the AI assistant. So treat a feedback report as something you are sending to a person and a machine, not just into a void. Everything else stays here.
We will also hand over data if the law actually requires it — a valid court order, not a polite request.
Where your data is
Everything is processed in the United States, us included: Back is run from Washington State, and the servers are in Virginia. If you are in the UK or the EEA, that means your data is held outside your country from the moment you sign up. Where we pass it on to Vercel or Neon, our agreements with them include the standard data protection clauses.
How long we keep it
- Your content — until you delete it, or until you delete your account.
- Your account — deleted when you ask us to, in the way described below. It goes then, not on a timer.
- Password-reset links — 30 minutes, and single-use.
- Server logs — Vercel's, not ours. We don't set how long they are kept, and we hold no copy of them.
- Feedback reports — kept while we are still acting on them. Ask and we will delete yours.
What you can make us do
- See what we hold. Ask at privacy@back.dev and we will send you a machine-readable file. Today the automatic part of it covers your account, your Backburner content and your documents; it does not yet cover the files in your Backpack, your feedback reports, or the detail of the action log — those we pull out by hand and send with it. We are building the automatic export out to cover everything, and this page will say so when it does.
- Correct anything wrong. Most of it you can edit directly in the product; write to us for the rest.
- Delete your account and everything in it. Ask at the same address. We delete it rather than deactivating it. Today one sweep clears your account, your Backburner content, your documents and your feedback; the files in your Backpack and the share links pointing at them are not on that sweep yet, so we finish those by hand and confirm when it is done. One button will cover all of it, and this page will say so when it does.
- Take your data elsewhere. The file we send you is machine-readable JSON.
- Object to the feedback trail, or to anything else we do on legitimate interests, by writing to us.
- Complain. Tell us first if you can — but you have every right to go straight to the data protection authority where you live. In the UK that is the Information Commissioner's Office (ico.org.uk); in the EEA it is your national authority. In the United States you can go to the Federal Trade Commission, or to the Attorney General of your state.
We answer within a month wherever you are, and there is no charge.
Automated decisions
Backburner ranks your list automatically and learns from how you work. It decides what to show you first — nothing else. It has no legal effect on you and decides nothing that matters outside the app, so it is not the kind of automated decision-making you have a right to opt out of. You can always reorder the list by hand, and Backburner treats your manual order as the final word.
Children
Back isn't for under-13s and we don't knowingly hold their data. If you live somewhere that sets a higher minimum age for online services, that age applies to you. If we learn that someone below the age for their country has an account, we delete the account and everything in it, and we don't keep any record of their age either. If you think a child has an account, tell us.
Security
Passwords are hashed with scrypt. Sessions are signed and HttpOnly. Everything is served over HTTPS with HSTS. Share links use 256-bit random tokens, and we store only a hash of them.
If your data is ever exposed, we will tell you, and quickly.
We are a very small team. If you find a security problem, please tell us at security@back.dev — details at security.txt. We will not take legal action against anyone who reports a genuine issue in good faith.
When this changes
We will update this page and change the date at the top. If a change actually matters to you, we will tell you in the app or by email before it takes effect.