Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains what information StoryPointCards ("we," "us") collects when you use our planning poker application at storypointcards.com (the "Service"), how we use it, and the choices you have.
Information we collect
- Account information
Name, email address, and password (stored as a salted hash, never in plain text) when you create an account. If you sign in with Google, Facebook, or GitHub, we store the profile information they share with us (name, email, and—for GitHub—your username), that provider's unique ID for your account, and the OAuth access/refresh token used to keep you signed in with them.
- Team and session data
Teams you create or join, pointing sessions, stories, and the point estimates you submit.
- Jira integration data
If a team connects Jira, we store an encrypted OAuth access/refresh token for that connection, plus the minimal Jira issue data needed to display and import issues as stories (issue key, summary, and URL). We do not access your Jira data except to service features you explicitly use, such as importing a selected issue.
- Usage data
On our production site we use Google Analytics (GA4) to understand aggregate usage patterns. This is not enabled in development or testing environments.
- Contact form submissions
If you use our contact form, we collect the name, email address, and message you submit, and deliver it by email to our support inbox so we can respond to you. We retain that correspondence in our email system for as long as reasonably needed to handle your request.
How we use your information
We use the information above to operate the Service: authenticating you, running pointing sessions in real time, syncing team membership, sending transactional emails (such as registration confirmations and team invites), and—where you've connected Jira—importing issues you select into a session. We do not sell your personal information, and we do not use your Jira data for any purpose beyond the features you use within StoryPointCards.
Third-party services
We rely on a small number of third-party providers to operate the Service: Amazon Web Services (application hosting and transactional email delivery via SES), Neon (our production PostgreSQL database host), Pusher/Soketi (real-time updates during a live pointing session), Google/Facebook/GitHub (optional sign-in), Atlassian (the optional Jira integration), Cloudflare (bot/spam protection on our contact form via Cloudflare Turnstile—see Cloudflare's Turnstile Privacy Policy for what it collects), and Google Analytics (aggregate usage analytics on our production site). Each of these providers processes data under their own privacy policies and only to the extent necessary to provide their service to us.
Data retention and deletion
We retain your account and team data for as long as your account is active. Disconnecting a Jira integration immediately revokes and permanently clears its stored access and refresh tokens; a record of the connection itself (the connected Jira site's identity, when it was connected, and who connected it) is kept for audit purposes rather than deleted outright. Requesting account deletion (see below) deactivates your account—it can no longer log in—but we don't currently erase your account record, team memberships, or past session/story history outright; contact us if you need that data fully removed and we'll handle it manually.
Security
Connections to the Service are encrypted in transit (HTTPS). Passwords are stored as salted hashes, never in plain text. OAuth tokens for integrations you connect from within the app (such as Jira) are encrypted at rest; sign-in provider tokens (Google, Facebook, GitHub) are not currently encrypted at rest, though database access itself is restricted to the Service.
Children's privacy
The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this policy from time to time. We'll update the "Last updated" date above when we do.
Contact us
Questions about this policy or your data? Reach out via our contact page.