PointFlow

Privacy Policy

Effective June 24, 2026

This Privacy Policy explains how PointFlow (“we”, “us”) collects, uses, and protects information when you use our planning-poker and Jira estimation service (the “Service”). We collect only what we need to run the Service.

1. Information we collect

  • Account data — when a facilitator signs in with Atlassian, we receive your Atlassian account ID, name, and email via OAuth.
  • Jira data — for the issues you choose to import, we read the issue key, summary, description, labels, type, and your selected estimation field, and we write the agreed estimate back to that field.
  • Session data — estimation sessions, votes, participant display names (including guests who join by link), and the final estimates.
  • Billing data — handled by our payment provider, Kelviq. We do not store your card details.

2. Atlassian OAuth scopes

We request only the scopes needed to function:
  • read:me — to identify the signed-in facilitator.
  • read:jira-work — to import the issues you select.
  • write:jira-work — to write the agreed estimate back to Jira.
  • offline_access — to refresh access so syncs work without re-authenticating each time.

3. How we use information

We use your information solely to provide and operate the Service: authenticate you, import and display Jira issues, run real-time voting, write estimates back to Jira, and manage your subscription. We do not sell your data or use it for advertising.

4. Sub-processors

We share data only with the service providers that help us run PointFlow:
  • Vercel — application hosting.
  • Neon — managed PostgreSQL database.
  • Ably — real-time room presence and vote events.
  • Atlassian — Jira and identity data you authorize.
  • Kelviq — subscription billing (merchant of record).

5. Data retention and deletion

We keep your data while your account is active. You can delete an estimation session at any time (which removes its issues and votes), disconnect Jira from Settings, or request deletion of your account and associated data by emailing us. Tokens are revoked when you disconnect.

6. Security

Access tokens are stored encrypted and are never exposed to the browser. We use HTTPS in transit and reputable infrastructure providers. No method of transmission or storage is 100% secure, but we take reasonable measures to protect your data.

7. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to let guests rejoin a room. We do not use advertising or cross-site tracking cookies.

8. Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data. To exercise them, contact us at the address below.

9. Changes

We may update this policy from time to time. Material changes will be reflected by an updated effective date and, where appropriate, a notice.

10. Contact

For privacy questions or data requests, email support@getpointflow.com.

See also our Terms of Service.