Legal
Privacy Policy
Last updated: May 11, 2026
1. Who we are
ScrumTool ("we", "us", "our") is an all-in-one Scrum ceremony platform available at scrumtool.io. We provide retrospective boards, planning poker, and async standup tools for agile teams.
2. Information we collect
Account information: When you sign up, we collect your email address and name. You may also sign in anonymously as a guest without providing personal details.
Content you create: Retro cards, planning poker votes, standup submissions, action items, and board configurations are stored to provide the service.
Usage data: We collect basic analytics (page views, feature usage) through Vercel Analytics to understand how the product is used. No individual-level tracking is performed.
Payment information: Payments are processed by Stripe. We do not store credit card numbers. Stripe's privacy policy governs their handling of payment data.
3. How we use your information
- To provide and operate the ScrumTool service
- To send transactional emails (account confirmation, password reset) via Resend
- To generate AI summaries of retrospectives and standups using the Anthropic API — content is processed but not used to train models
- To manage your subscription and process payments via Stripe
- To improve the product based on aggregated usage patterns
4. Data storage and security
Your data is stored in Supabase (PostgreSQL) hosted on AWS infrastructure. Data is encrypted at rest and in transit. We use row-level security to ensure users can only access data within their workspace.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Third-party services
ScrumTool uses the following third-party services to operate:
- Supabase — authentication and database
- Anthropic — AI summary and digest generation
- Stripe — payment processing
- Resend — transactional email
- Vercel — hosting and analytics
Each provider operates under their own privacy policy and data processing agreements.
6. Data retention
We retain your data for as long as your account is active. Free plan data older than 30 days may be subject to archival. Pro plan data is retained for 1 year. Team plan data is retained indefinitely. You may request deletion of your account and all associated data at any time.
7. Your rights
Depending on your location, you may have rights under GDPR, CCPA, or other applicable privacy laws, including the right to access, correct, delete, or export your personal data. To exercise these rights, email us at privacy@scrumtool.io.
8. Cookies
ScrumTool uses session cookies for authentication (HttpOnly, Secure). We do not use advertising or tracking cookies. We do not use third-party cookie-based analytics.
9. Children
ScrumTool is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
We may update this policy as the product evolves. Material changes will be communicated via email or an in-app notice. Continued use of the service after changes constitutes acceptance of the updated policy.
11. Contact
Questions about this policy: privacy@scrumtool.io