Privacy Policy

Last updated: February 8, 2026

Welcome to ScrumBoard. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect information when you use our project management platform.

1. Information We Collect

Account Information

When you create an account through our authentication provider (Clerk), we receive and store your basic profile information, including your name, email address, and profile picture.

Project Data

We store all data you create within our platform, including but not limited to:

  • Project names and descriptions
  • Tickets, tasks, and their associated details
  • Sprint planning information
  • Team member assignments and roles
  • Comments and activity logs

Usage Data

We may collect information about how you interact with our service, including pages visited, features used, and timestamps of activity.

2. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve our services
  • Process and complete transactions
  • Send you technical notices and support messages
  • Respond to your comments and questions
  • Generate AI-powered ticket suggestions based on your project context
  • Monitor and analyze trends, usage, and activities
  • Detect, investigate, and prevent fraudulent transactions and abuse

3. Data Storage and Security

Your data is stored in secure, enterprise-grade cloud infrastructure. We employ industry-standard security measures including:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL
  • Encryption at Rest: Database storage is encrypted at the infrastructure level
  • Access Controls: Strict access controls ensure only authorized personnel can access production systems
  • Authentication Security: We use Clerk, a trusted third-party authentication provider, to handle user authentication securely

Note: While we implement robust security measures, project data (such as ticket titles and descriptions) is stored in a readable format within our database to enable the core functionality of our service. This is standard practice for SaaS applications and is necessary to provide features like search, AI-powered suggestions, and collaboration.

4. AI Features and Data Processing

ScrumBoard includes AI-powered features to enhance your productivity. When using these features:

  • Your project context may be processed by third-party AI services to generate ticket suggestions
  • We do not use your data to train AI models
  • AI processing is performed on-demand when you explicitly request it

5. Data Sharing

We do not sell your personal data. We may share your information with:

  • Service Providers: Third-party companies that help us provide our service (hosting, authentication, AI processing)
  • Team Members: Other users you invite to your projects can see project-related data
  • Legal Requirements: When required by law or to protect our rights

6. Your Rights

You have the right to:

  • Access and receive a copy of your personal data
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal retention requirements)
  • Object to processing of your data
  • Export your data in a portable format

To exercise these rights, please contact us using the information provided below.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide you services. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal purposes.

8. Cookies and Tracking

We use essential cookies to maintain your session and authenticate your account. These cookies are necessary for the service to function and cannot be disabled. We do not use advertising or tracking cookies.

9. Third-Party Services

Our service integrates with third-party providers who act as data processors on our behalf. These providers process your data according to our instructions and their own privacy policies:

  • Clerk

    Provides authentication and user management. Clerk acts as a data processor for user identity data (name, email, profile picture) and processes this data solely to provide authentication services.

    View Clerk Privacy Policy →
  • Neon

    Provides serverless PostgreSQL database hosting. Neon acts as a data processor and stores your project data (tickets, sprints, etc.) on secure servers. Neon does not control or access your data except as necessary to provide the database service.

    View Neon Privacy Policy →
  • Vercel

    Provides application hosting and edge network infrastructure. Vercel processes requests and may collect technical data such as IP addresses and access logs.

    View Vercel Privacy Policy →

Important: While we carefully select providers with strong security practices, no system is 100% secure. We encourage you to review each provider's privacy policy to understand how they handle data.

10. Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at: