Privacy
Last checked against the code on 2026-10-10.
Who is responsible
Dolutions AB (org.nr 556981-0293), Sweden, is responsible for the personal data in Dashbox. Questions and requests: support@dashbox.se.
In short
Dashbox stores what you put into it, so it can show you your numbers and the reasons beside them.
It has no advertising, sells nothing about you, and uses no Google Analytics and no tracking cookies.
The legal basis is the agreement to provide the service you signed up for; the page counts on the public pages and the server's own logs rest on our legitimate interest in running the site safely.
What Dashbox stores
Only for a signed-in account. Each line below is a part of the database:
Your account: a sign-in identifier, your e-mail address and name if the sign-in service gave them (with Sign in with Apple the address can be Apple's private relay address, and the name arrives only the first time), your plan, time zone and view settings, and, if you created one, a fingerprint (SHA-256) of your developer upload token, used to send card definitions from your own tools - never the token itself.
Why: To know it is you, to show your own cards and nobody else's, and to remember how you want them shown.
Your cards and their settings: name, description, unit, where the number comes from (an API address, an SQL query or a collector key - a key is referred to by name, never stored in the card), direction, display, trigger, target and when it was last read, and which cards you starred.
Why: A card is the thing you asked Dashbox to watch.
Readings: each number a card received, with its time and its comparison values (24 hours, yesterday, 7- and 30-day average). Collectors send these aggregates only, never the rows behind them.
Why: Comparing a number with its own normal needs its history.
What you write beside the numbers: comments and periods, with the date, the text, the name of who wrote it and when.
Why: The reason a number moved is the second half of what Dashbox is for.
A card's history: each time it went low, critical, stale or into error, reached its target, or came back to normal, each change of its target, and each change of its definition (name, unit, direction and similar), with the old and new value.
Why: So the time view can show what happened, and a number can be read against the rules that held at the time.
Keys you enter (API keys, database credentials): encrypted before they are stored (envelope encryption), with a name you choose and a masked hint such as sk-...a1b2. A key is never shown again after you enter it, and it is decrypted only in memory for the moment a card is read.
Why: So Dashbox can call the API or database you chose, without the key being readable in the database.
Your collectors: name, type, interval, status, when one last reported in and its last error. A container collector's key is stored only as a fingerprint (SHA-256); the passwords to the data it reads stay with the collector, next to the data, and never reach Dashbox.
Why: To accept numbers only from collectors you created, and to tell you when one has gone quiet.
Templates: descriptions of public APIs (which address, which numbers), shared by all accounts, with who added each version. A template holds no keys and no readings.
Why: So an API source needs a template and a key, not code.
Cookies and browser storage
After you sign in, Dashbox sets one cookie, dashbox_session: a signed session token that keeps you signed in for up to 30 days. Your browser cannot read it from scripts, and signing out removes it.
The public pages - this page, the start page and support - set no cookie.
Page counts on the public pages
The start page, this page and support count visits with the doable.services tracker. It sends the page address, the referring page, the browser, screen size, language and time zone.
It sets no cookie. It keeps a random id for the open browser tab in sessionStorage (gone when the tab closes) and, if the address had campaign parameters (utm_...), keeps those for 30 minutes in localStorage.
If your browser sends Do Not Track or Global Privacy Control, the tracker is not loaded at all. The signed-in app pages have no tracker.
Who else handles data
- doable.services
- the proxy in front of dashbox.se. Every request, with its IP address, passes through it to Dashbox.
- Apple
- if you use Sign in with Apple: Apple confirms who you are and gives Dashbox an identifier, and on the first sign-in your name and e-mail address (or a relay address).
- Mailgun (EU region)
- when sign-in by e-mail is added (it is not built yet), Mailgun will deliver the sign-in mail, so it will receive your e-mail address and the mail, with open and click tracking off.
- OpenRouter (USA)
- only when an administrator drafts a template from API documentation: the documentation text and what to measure are sent to an AI model. No keys, readings or comments are sent.
- The services you connect
- Dashbox calls the APIs and databases you point a card at, with the key you gave it for them. What they receive is that request.
There are no payments in Dashbox today, so no payment provider handles anything. Before paid plans exist, this page will name the one that does.
Where it runs
Dashbox and its database run on Dolutions' own servers in Sweden.
Keys are encrypted before they reach the database; the server's logs record errors and start-ups and never contain keys or passwords.
How long it is kept
- As long as your account exists.
- When you delete a card, its readings, its history and your star on it are deleted with it.
- Comments and periods you delete are hidden, not erased; they, and those on a card you deleted, are erased together with the account.
- When the account is deleted, everything linked to it is deleted from the database: cards, readings, comments, periods, history, keys and collectors. A template you added stays for the other accounts, marked only with an account id that no longer points at anyone.
Your rights
You can ask for a copy of what Dashbox stores about you, have it corrected, or have your account deleted. Write to support@dashbox.se from the address your account uses. We answer within 30 days.
In the admin, "Export configuration" on the Cards page gives you your configuration (cards, collectors, settings) as a file at any time, without keys.
If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se.
Changes
When Dashbox starts storing something new, or a new company starts handling data, this page changes first. See also support.