Privacy

Last checked against the code on 2026-10-10.

Who is responsible

Dolutions AB (org.nr 556981-0293), Sweden, is responsible for the personal data in Dashbox. Questions and requests: support@dashbox.se.

In short

Dashbox stores what you put into it, so it can show you your numbers and the reasons beside them.

It has no advertising, sells nothing about you, and uses no Google Analytics and no tracking cookies.

The legal basis is the agreement to provide the service you signed up for; the page counts on the public pages and the server's own logs rest on our legitimate interest in running the site safely.

What Dashbox stores

Only for a signed-in account. Each line below is a part of the database:

Cookies and browser storage

After you sign in, Dashbox sets one cookie, dashbox_session: a signed session token that keeps you signed in for up to 30 days. Your browser cannot read it from scripts, and signing out removes it.

The public pages - this page, the start page and support - set no cookie.

Page counts on the public pages

The start page, this page and support count visits with the doable.services tracker. It sends the page address, the referring page, the browser, screen size, language and time zone.

It sets no cookie. It keeps a random id for the open browser tab in sessionStorage (gone when the tab closes) and, if the address had campaign parameters (utm_...), keeps those for 30 minutes in localStorage.

If your browser sends Do Not Track or Global Privacy Control, the tracker is not loaded at all. The signed-in app pages have no tracker.

Who else handles data

doable.services
the proxy in front of dashbox.se. Every request, with its IP address, passes through it to Dashbox.
Apple
if you use Sign in with Apple: Apple confirms who you are and gives Dashbox an identifier, and on the first sign-in your name and e-mail address (or a relay address).
Mailgun (EU region)
when sign-in by e-mail is added (it is not built yet), Mailgun will deliver the sign-in mail, so it will receive your e-mail address and the mail, with open and click tracking off.
OpenRouter (USA)
only when an administrator drafts a template from API documentation: the documentation text and what to measure are sent to an AI model. No keys, readings or comments are sent.
The services you connect
Dashbox calls the APIs and databases you point a card at, with the key you gave it for them. What they receive is that request.

There are no payments in Dashbox today, so no payment provider handles anything. Before paid plans exist, this page will name the one that does.

Where it runs

Dashbox and its database run on Dolutions' own servers in Sweden.

Keys are encrypted before they reach the database; the server's logs record errors and start-ups and never contain keys or passwords.

How long it is kept

Your rights

You can ask for a copy of what Dashbox stores about you, have it corrected, or have your account deleted. Write to support@dashbox.se from the address your account uses. We answer within 30 days.

In the admin, "Export configuration" on the Cards page gives you your configuration (cards, collectors, settings) as a file at any time, without keys.

If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se.

Changes

When Dashbox starts storing something new, or a new company starts handling data, this page changes first. See also support.