Account information: name, email address, password (stored as a salted hash, never in plain text), profile picture, and workspace role.
Content you provide: messages, replies, reactions, tags, pins, files and attachments you upload, poll and survey responses, and Touch Base recordings/transcripts you or your workspace generate.
Usage and diagnostic data: app and feature usage events, device type and operating system version, crash and error logs, and IP address, used to operate, secure, and improve the Services.
Mobile-specific data: which platform a message was sent from (iOS, Android, or web) is recorded so workspace admins and OnceAsked can see activity by client; this is metadata about the app used, not additional personal content.
We do not require or collect biometric data. If you enable Face ID, Touch ID, or fingerprint unlock in the mobile app, that authentication happens entirely on your device using Apple's or Google's own secure hardware (e.g., iOS Secure Enclave) — OnceAsked never receives, transmits, or stores your biometric data. We only receive a yes/no result confirming your device unlocked the app.