ProjectLibre Global Privacy Policy
Effective Date: September 17, 2026
Last Updated: September 17, 2026
ProjectLibre, Inc. (“ProjectLibre,” “we,” “us,” or “our”) provides ProjectLibre Desktop,
ProjectLibre Cloud, ProjectLibre artificial-intelligence functionality, ProjectLibre websites,
communities, support services, and related online and cloud-connected services.
ProjectLibre is used by individuals, businesses, educational institutions, government
organizations, nonprofit organizations, and other organizations throughout the world.
This Privacy Policy explains how ProjectLibre collects, receives, processes, uses, stores,
discloses, protects, and otherwise handles information in connection with our products and services.
This is a global Privacy Policy covering both ProjectLibre Desktop and ProjectLibre Cloud.
Some sections apply only when a particular feature or service is used. For example,
ProjectLibre Desktop normally stores project files locally on the user’s computer.
Provisions concerning cloud storage, project uploads, collaboration, or cloud-based artificial
intelligence apply to a Desktop user only when the user chooses to use a feature involving those services.
This Privacy Policy does not modify the open-source license applicable to ProjectLibre Desktop
or any other software-license terms.
This Privacy Policy applies to information processed through or in connection with:
Collectively, these are referred to as the “Services.”
ProjectLibre Desktop is installed and operated on the user’s computer. Project files created,
opened, or edited using normal Desktop functionality ordinarily remain on that computer.
ProjectLibre Desktop may periodically communicate with ProjectLibre or service-provider
infrastructure to support software operation, language and translation capabilities, security,
diagnostics, compatibility, version information, and product improvements.
These communications may involve limited technical information such as:
Network, security, hosting, or content-delivery providers may process technical information
such as IP addresses and request metadata while providing these services.
Normal ProjectLibre Desktop connectivity does not upload the user’s project plans
or project files to ProjectLibre Cloud.
ProjectLibre Cloud is a hosted, multi-user, multi-project service.
Projects and related information placed in ProjectLibre Cloud are transmitted to, stored in,
and processed using cloud infrastructure operated by or on behalf of ProjectLibre.
Cloud information may therefore include the complete project-management information described
in this Privacy Policy.
ProjectLibre Desktop may provide an option to open, evaluate, migrate, or otherwise use a
Desktop project in ProjectLibre Cloud.
When a user intentionally selects this functionality, the user will be informed that the
project and its contents will be uploaded to ProjectLibre Cloud.
The uploaded information may include:
The original Desktop project file remains on the user’s computer unless the user separately
modifies or deletes it.
Once a project has been intentionally uploaded to ProjectLibre Cloud, it is processed as Cloud
Customer Content under this Privacy Policy and the applicable ProjectLibre Terms of Service.
The information ProjectLibre processes depends on the Services being used and the information
users and organizations choose to provide.
This may include:
Projects may contain:
We refer to information supplied to or maintained within the Services on behalf of a customer
as “Customer Content.”
ProjectLibre projects and enterprise resource pools may contain information concerning employees,
contractors, team members, vendors, consultants, or other resources, including:
This information may constitute personal information even if the individual does not personally
have a ProjectLibre account.
We and our service providers may process:
Organizations and users may place information concerning other individuals into ProjectLibre.
For example, a project manager may add a resource’s name, email address, role, assignments,
availability, work, or cost rate to a project.
ProjectLibre may therefore process personal information that we did not receive directly from
the individual concerned.
The organization or user providing such information is responsible for ensuring that it has
appropriate authority and a lawful basis to collect, use, and provide that information through
ProjectLibre and for providing any notices required by applicable law.
Where ProjectLibre processes this information on behalf of a customer, ProjectLibre generally
acts as the customer’s processor, service provider, contractor, or equivalent role under
applicable privacy law.
ProjectLibre’s legal role depends on the processing activity.
When a customer determines what employee, resource, contractor, customer, supplier, or other
personal information is entered into its projects, the customer will generally be the controller
or business responsible for that information, and ProjectLibre will generally process the
information as a processor, service provider, or contractor on the customer’s behalf.
ProjectLibre may separately act as the controller or business responsible for information used to:
Enterprise customers may also enter into a Data Processing Agreement, Master Services Agreement,
Order Form, or other agreement with ProjectLibre.
ProjectLibre may use information to:
ProjectLibre provides artificial-intelligence functionality as part of certain Services.
AI functionality may process Customer Content when necessary to perform a function requested by a user.
Depending on the feature, this may include:
For example, AI functionality may be used to:
ProjectLibre may use third-party cloud infrastructure, AI infrastructure, large-language models,
foundation models, and other technology providers to perform this processing.
Those providers may process the information necessary to perform the requested function on
ProjectLibre’s behalf.
ProjectLibre does not authorize these providers to sell Customer Content or use Customer Content
for advertising.
Where commercially and technically available, ProjectLibre selects or configures enterprise AI
services so that Customer Content submitted to provide ProjectLibre functionality is not used by
the underlying provider to independently train its general-purpose AI models.
ProjectLibre continually develops and improves its project-management technology, scheduling
technology, and artificial-intelligence capabilities.
Where permitted by applicable law and applicable customer agreements, ProjectLibre may create
and use aggregated, de-identified, or anonymized information derived from Customer Content,
project structures, use of the Services, and AI interactions.
ProjectLibre may use such information for:
For information used for cross-customer AI or product improvement, ProjectLibre takes measures
designed to remove, exclude, generalize, mask, or transform information that directly identifies
a customer, individual, resource, or specific project.
Depending on the information involved, those measures may include removing or transforming:
Information useful for project-management research and improvement may include patterns or
structures such as:
ProjectLibre does not intentionally use de-identified information to determine or recreate the
identity of an individual, customer, resource, or specific project.
Where information is maintained in de-identified form, ProjectLibre will take reasonable measures
designed to maintain that information in de-identified form and will not intentionally reidentify
it except as permitted by law, including where necessary to test or evaluate the effectiveness of
de-identification procedures.
ProjectLibre does not sell de-identified project information and does not use it for third-party advertising.
Nothing in this section transfers ownership of Customer Content to ProjectLibre.
Where applicable law requires consent or another specific authorization for a particular
AI-development or data-improvement activity, ProjectLibre will use the process required by that law.
Where applicable law requires ProjectLibre to identify a legal basis for processing personal
information, the basis depends on the activity.
We may process information when necessary to:
Where permitted by law, ProjectLibre may process information where necessary for legitimate interests such as:
Where required, ProjectLibre considers the nature of the processing, its necessity, reasonable
expectations, safeguards, and potential effects on individuals before relying on legitimate interests.
ProjectLibre may rely on consent where applicable law requires consent for a particular activity,
such as certain marketing communications, cookies, sensitive-data processing, international transfers,
or other activities.
ProjectLibre may process information where necessary to comply with laws, regulations, court orders,
lawful government requests, taxation obligations, accounting requirements, or other legal obligations.
ProjectLibre uses service providers and subprocessors to operate the Services.
These may include providers of:
These providers may process information on ProjectLibre’s behalf where necessary to provide their
contracted services.
ProjectLibre uses contractual, organizational, and technical measures appropriate to the nature
of the information and processing and as required by applicable law.
A current list of material subprocessors may be provided or made available to customers where
required by applicable law or contract.
ProjectLibre does not sell Customer Content.
ProjectLibre does not sell:
ProjectLibre does not use Customer Content for third-party behavioral advertising.
ProjectLibre does not provide one customer’s project to another ProjectLibre customer except
when authorized through collaboration, sharing, access-control, or other functionality selected
by the customer.
Where applicable U.S. privacy laws define “sale,” “sharing,” “targeted advertising,” or
“cross-context behavioral advertising,” ProjectLibre does not sell or share Customer Content
for those purposes.
ProjectLibre websites and browser-based Services may use cookies, local storage, and similar technologies.
These technologies may be used for:
Where applicable law requires consent for non-essential cookies or similar technologies,
ProjectLibre will provide the required choices.
ProjectLibre may use contact information to provide:
Users may unsubscribe from marketing emails using the mechanism provided in those communications.
An unsubscribe request does not prevent necessary transactional, account, security, support,
or service communications.
ProjectLibre uses administrative, technical, and organizational safeguards designed to protect
personal information and Customer Content from unauthorized access, unauthorized disclosure,
misuse, alteration, loss, and destruction.
These measures may include, where appropriate:
No electronic system can be guaranteed to be completely secure, and ProjectLibre cannot guarantee
absolute security.
If ProjectLibre becomes aware of a qualifying personal-data breach or security incident, we will
provide notices to customers, individuals, regulators, or other parties where required by applicable law.
ProjectLibre retains information for as long as reasonably necessary for the purpose for which it
is processed, including to provide Services, maintain customer accounts, perform contractual
obligations, maintain security, resolve disputes, enforce agreements, comply with legal obligations,
meet tax and accounting requirements, prevent fraud, and maintain necessary business records.
Retention periods may vary according to:
Information may remain temporarily in backups after deletion until the applicable backup is
overwritten, expired, or securely deleted in the normal course.
Aggregated, de-identified, or anonymized information that is no longer treated as identifiable
personal information under applicable law may be retained for longer periods.
ProjectLibre is a United States company serving users and organizations throughout the world.
Information may be stored or processed in the United States and in other countries in which
ProjectLibre or our service providers operate.
ProjectLibre may use regional hosting or processing locations based on service configuration,
customer requirements, operational needs, security, performance, and applicable law.
Where ProjectLibre provides regional hosting, certain primary Customer Content may be stored in
the applicable region. However, limited information may still be processed in other locations
when necessary for security, support, communications, AI functionality, infrastructure, or other
Services and where legally permitted.
Privacy laws differ between jurisdictions.
Where applicable law restricts international transfers of personal information, ProjectLibre
uses an appropriate lawful transfer mechanism or safeguard. Depending upon the jurisdiction,
this may include:
ProjectLibre will provide additional transfer information or contractual terms where required
by applicable law or an applicable customer agreement.
Depending upon where an individual is located and the law applicable to the processing,
the individual may have rights including:
These rights are subject to the conditions, limitations, verification requirements, and
exceptions provided by applicable law.
ProjectLibre will not unlawfully discriminate or retaliate against an individual for exercising
applicable privacy rights.
ProjectLibre Cloud frequently processes personal information on behalf of a business, university,
government agency, or other ProjectLibre customer.
If your information appears in a customer’s ProjectLibre project or resource pool—for example,
because your employer has entered your name, email address, assignments, availability, work,
or rate information—the ProjectLibre customer may be the organization responsible for responding
to your privacy request.
If ProjectLibre receives a request concerning information we process solely on behalf of a customer, we may:
ProjectLibre operates globally. The following provisions supplement the remainder of this
Privacy Policy where the referenced laws apply.
Individuals may have rights including access, rectification, erasure, restriction, portability,
objection, withdrawal of consent, and the right to complain to an applicable supervisory authority.
Where ProjectLibre relies on legitimate interests, individuals may have a right to object to the
processing in circumstances provided by applicable law.
Where personal information is transferred internationally, ProjectLibre will use an applicable
legal transfer mechanism such as an adequacy determination, Standard Contractual Clauses,
the UK International Data Transfer Agreement or applicable addendum, or another authorized safeguard.
Where ProjectLibre processes Customer Content as a processor, processing may additionally be governed
by a Data Processing Agreement with the customer.
Residents of California and other U.S. states with comprehensive privacy laws may have additional
rights including access, correction, deletion, portability, and the ability to opt out of activities
defined by applicable law as sale, sharing, targeted advertising, or qualifying profiling.
ProjectLibre does not sell Customer Content and does not share Customer Content for
cross-context behavioral advertising.
ProjectLibre may disclose information to service providers, processors, contractors, and other
parties for legitimate business purposes described in this Privacy Policy.
Individuals in Canada may have rights concerning access, correction, knowledge of processing practices,
and the ability to challenge ProjectLibre’s compliance with applicable privacy requirements.
ProjectLibre remains responsible for personal information under its control and uses contractual
or other safeguards for information transferred to third-party processors where required.
Personal information may be processed outside Canada and may therefore be subject to lawful access
requirements in the jurisdiction where it is processed.
Where Brazil’s Lei Geral de Proteção de Dados (“LGPD”) or other applicable Latin American privacy
laws apply, individuals may exercise the rights provided by those laws.
ProjectLibre will use an applicable lawful basis for processing and an approved mechanism or other
lawful basis for international transfers where required.
Where applicable Australian or New Zealand privacy law applies, individuals may request access
to and correction of personal information and may raise privacy complaints.
ProjectLibre will take measures required by applicable law when personal information is disclosed
to recipients outside the applicable jurisdiction.
Where practicable and legally required, ProjectLibre will provide information about countries or
regions in which relevant overseas recipients are located.
Where Japan’s Act on the Protection of Personal Information applies, ProjectLibre will handle
personal information and international transfers in accordance with applicable requirements,
including requirements applicable to transfers to third parties located in foreign countries.
Where Singapore’s Personal Data Protection Act applies, ProjectLibre will use reasonable security
measures, limit retention as appropriate, and apply legally required safeguards to transfers of
personal information outside Singapore.
Where the Republic of Korea’s Personal Information Protection Act applies, ProjectLibre will
provide applicable notices, respect applicable data-subject rights, and use required safeguards
or authorizations for overseas processing and transfers.
Where India’s Digital Personal Data Protection law and implementing rules apply, ProjectLibre
will process personal data in accordance with applicable notice, security, data-principal-rights,
breach, retention, and cross-border requirements.
Where the People’s Republic of China’s Personal Information Protection Law or related laws apply,
ProjectLibre will comply with applicable requirements concerning personal-information processing,
individual rights, sensitive personal information, and cross-border processing.
Where Chinese law requires a separate consent, filing, assessment, certification, contract,
localization measure, or other cross-border mechanism, ProjectLibre will implement the applicable
requirement before relying on that mechanism for covered processing.
Users in other countries may have additional rights under local privacy or data-protection law.
ProjectLibre will apply applicable mandatory privacy requirements to the extent required by law.
If local law requires a notice, consent, contract, transfer mechanism, or other requirement beyond
this global Privacy Policy, the applicable supplemental notice or mechanism will form part of
ProjectLibre’s privacy framework for the affected processing.
ProjectLibre is a general project-management platform and is not designed primarily to collect
highly sensitive categories of personal information.
However, because customers control Customer Content, a customer could place sensitive information
into a project.
Customers should avoid entering sensitive personal information unless the information is reasonably
necessary for an authorized project-management purpose and the customer has a lawful basis and
appropriate safeguards for doing so.
ProjectLibre does not use sensitive personal information contained in Customer Content for
third-party advertising.
Direct identifiers and sensitive personal information are not intended to form part of ProjectLibre’s
cross-customer de-identified AI-training or product-improvement datasets.
ProjectLibre may use automation and artificial intelligence to assist users with:
These systems are designed to assist human users.
Unless expressly stated otherwise, ProjectLibre AI functionality is not intended to independently
make legal, employment, credit, insurance, medical, or other decisions producing similarly
significant legal effects concerning an individual.
Customers are responsible for appropriate human review of ProjectLibre output before using it
for significant decisions.
ProjectLibre’s commercial and Cloud Services are intended primarily for professional,
organizational, and educational use and are not directed to young children.
ProjectLibre does not knowingly seek to collect personal information directly from children
in violation of applicable law.
Educational institutions or other organizations using ProjectLibre with students are responsible
for obtaining any parental, institutional, or other authorization required by applicable law.
If ProjectLibre learns that personal information concerning a child has been collected in
circumstances requiring deletion or additional authorization, we will take appropriate action.
If ProjectLibre is involved in a merger, acquisition, financing, reorganization, sale of assets,
corporate restructuring, bankruptcy, or similar business transaction, information may be
transferred as part of that transaction.
Any such transfer will remain subject to applicable law and appropriate confidentiality or
privacy obligations.
ProjectLibre may preserve or disclose information when reasonably necessary to:
Where legally permitted, ProjectLibre seeks to limit disclosures to information reasonably
necessary for the applicable purpose.
Individuals may contact ProjectLibre with questions or complaints concerning our handling
of personal information.
We will review privacy complaints and respond as required by applicable law.
Where applicable, individuals may also submit a complaint to the data-protection, privacy,
consumer-protection, or supervisory authority having jurisdiction over the matter.
ProjectLibre may update this Privacy Policy as our Services, technology, business practices,
or legal obligations evolve.
We will update the “Last Updated” date when this Privacy Policy changes.
Where applicable law requires additional notice or consent for a material change,
ProjectLibre will provide that notice or obtain that authorization as required.
Earlier versions may be retained where appropriate for compliance and recordkeeping.
This Privacy Policy should be read together with the applicable:
If a negotiated customer agreement imposes additional privacy or data-protection obligations
on ProjectLibre, ProjectLibre will comply with those obligations according to the terms of
that agreement.
Questions, privacy requests, complaints, or requests concerning personal information may be
directed to:
ProjectLibre, Inc.
3773 Howard Hughes Parkway, Suite 500S
Las Vegas, Nevada 89169-6014
United States
Email:
Privacy Policy:
https://projectlibre.com/privacy-policy/
Terms of Service:
When contacting ProjectLibre about a privacy request, please provide sufficient information
for us to identify the applicable account or processing activity. ProjectLibre may need to
verify identity before fulfilling certain requests.
If the request concerns information controlled by an employer, university, government organization,
or other ProjectLibre customer, ProjectLibre may refer the request to that organization.
ProjectLibre’s Services are used internationally.
This Privacy Policy is intended to provide a consistent global framework for how ProjectLibre
handles personal information and Customer Content across ProjectLibre Desktop, ProjectLibre Cloud,
AI functionality, websites, and cloud-connected services.
Where the privacy or data-protection law applicable to a particular user or processing activity
provides greater protection than this Privacy Policy, ProjectLibre will apply the mandatory
requirements of that applicable law.
Nothing in this Privacy Policy is intended to limit rights that cannot lawfully be limited under
applicable privacy or data-protection law.