Privacy Policy
Effective October 1, 2026
This policy explains how ScrumBuddy, LLC (“ScrumBuddy,” “we,” “us”) collects, uses, and shares information when an organization installs and uses the ScrumBuddy app in Slack or Microsoft Teams (the “Service”). The organization that installs ScrumBuddy (the “Customer”) controls the workspace data we process on its behalf.
Information we collect
- Workspace and account information from Slack or Microsoft Teams when the app is installed: workspace or tenant ID and name, and an access token for the app (stored encrypted).
- User profile information for members of configured stand-up teams: platform user ID, display name, email address, and time zone.
- Stand-up content that users submit: what they did, what they plan to do, and any blockers, plus team settings such as the stand-up channel, prompt time, working days, and sprint names and goals.
- Optional mood check-ins (a 1–5 score), collected only when a team administrator turns this feature on for that team.
- Connected tools. If a team connects a project tracker such as Asana, we store the access tokens (encrypted) and read the project and task data needed to show sprint context in stand-ups.
- Operational records such as audit logs of configuration changes, usage counts used for billing, and service logs.
We do not ask for and do not intend to collect sensitive personal information, and the Service is not directed to children.
How we use information
- To run stand-ups: send prompts and reminders, collect responses, and post summaries to the team’s channel.
- To generate AI summaries of a team’s daily updates (see “AI processing” below).
- To surface blockers that remain open and, where enabled, alert a team’s designated scrum master to mood changes.
- To secure, maintain, troubleshoot, and improve the Service, and to bill for it.
We do not sell personal information and do not use it for advertising.
AI processing
To produce daily summaries, ScrumBuddy sends a team’s stand-up content for that day to Anthropic’s API. Anthropic processes this data as our service provider; under its commercial terms, inputs sent through its API are not used to train its models.
Service providers
We share information only with providers that help us run the Service:
- Vercel — application hosting
- Neon — database hosting
- Upstash — job queue and caching
- Anthropic — AI summaries
- Slack, Microsoft, and Asana — the platforms the Customer connects ScrumBuddy to
We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets, subject to this policy.
Security
Data is encrypted in transit. Access tokens for Slack, Microsoft, and connected tools are encrypted at rest with AES-256. Access to production systems is limited to personnel who need it to operate the Service.
Retention and deletion
We keep Customer data while ScrumBuddy is installed. When the app is uninstalled, the workspace’s teams are deactivated and stop receiving prompts. A Customer administrator can ask us to delete the workspace’s data by emailing support@scrum-buddy.ai; we will delete it within 30 days of a verified request, except where we must keep records to meet legal obligations.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information. Because the Customer controls its workspace data, we may refer your request to your organization’s administrator. To make a request or ask a question, email support@scrum-buddy.ai.
International transfers
ScrumBuddy is operated from the United States, and our service providers may process data in the United States and other countries.
Changes
We may update this policy. We will change the effective date above and, for material changes, notify Customer administrators before the change takes effect.
Contact
ScrumBuddy, LLC · support@scrum-buddy.ai