Privacy Policy
SprintUnity is committed to protecting your privacy and handling your data in a transparent and secure way.
Our Commitment to You
We collect no email addresses, never sell your data, never send it to a third-party AI provider, and keep every organization's data separately scoped to their own Jira site.
1. Scope & how it's built
SprintUnity ("the App", "SprintUnity") is developed and operated by Toba Sayed ("we", "us"). This policy applies specifically to SprintUnity — your use of Jira itself is governed separately by Atlassian's own privacy policy.
SprintUnity is a Forge app: the parts you interact with inside Jira run on Atlassian's own Forge platform. A companion backend service ("backend-api"), hosted separately by us at issueeval.com, stores the data SprintUnity needs to calculate sprint intelligence, risk analysis, evaluations, and reporting across sprints. Every request between the Forge app and backend-api is scoped to your Jira site and authenticated using Atlassian's own signed Forge context — never a value supplied by the browser.
2. What data we collect
We do not collect or store email addresses anywhere in SprintUnity. Identity is tracked exclusively through Jira's own opaque account ID, plus a display name captured at the time a record is created.
| Data category | What's stored |
|---|---|
| Estimation votes | Per-issue votes and vote history |
| Sprint risks | Risk title, free-text description, mitigation notes, owner's account ID |
| Time log entries | Account ID, display name, time spent, free-text worklog description |
| Team evaluations | Account ID, evaluator's account ID, scores, free-text notes — the most sensitive category in the app |
| Teams and roles | Account ID, role type, team membership |
| Audit log | Which setting changed, old/new value, who made the change |
| Intelligence snapshots | Calculated health/quality/capacity scores; in one case, a snapshot of Jira issue summary text |
| Advisor conversations | The question asked and the answer given, plus account ID — rule-based, not a third-party AI/LLM integration |
All of the above is stored per-tenant (keyed to your Jira site's cloud ID) and is never shared across organizations.
3. How we use your data
Data is used solely to power SprintUnity's own features for your organization: sprint dashboards, risk detection, team evaluation, time tracking reports, and the in-app Advisor. We do not use your data for advertising, and we do not sell data to third parties.
4. Who we share data with
We do not share your data with third-party advertisers, data brokers, or external AI/LLM providers. The only external transfer this app makes is between Atlassian's Forge platform and our own backend-api service at issueeval.com, which we operate directly. We do not currently use any third-party sub-processor beyond our own infrastructure.
5. Where & how data is stored
Backend-api runs on infrastructure we operate directly, backed by a MySQL database. Access is restricted by network firewall to Atlassian's published Jira/Forge IP ranges plus a small set of administrative access points; the application connects using a least-privilege database account, not an administrative one. Traffic between your browser, Forge, and backend-api is encrypted in transit over HTTPS.
6. Data retention
As of this policy's last update, SprintUnity does not yet apply an automatic time-based retention window to most tables — data persists for as long as your organization has the app installed, consistent with historical trend reporting needing that history to function. We do not apply any retention decision to Team Evaluation data without a tenant's own explicit configuration, since that data reflects each organization's own HR policies, not ours.
7. Your rights
Depending on your location, you may have rights under data protection law (such as the GDPR) to access, correct, export, or request erasure of personal data we hold. A site administrator can request a full export or deletion of your organization's data by contacting Support@Sprintunity.com. Site administrators can also remove data associated with a specific team member directly within the app wherever a delete action is available.
8. Uninstalling the app
Uninstalling SprintUnity from your Jira site stops the app from collecting any new data. It does not immediately erase previously stored data — contact Support@Sprintunity.com to request full deletion.
9. Children's privacy
SprintUnity is a business productivity tool intended for use by adult professionals within an organization's Jira instance. It is not directed at, and we do not knowingly collect data from, children.
10. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected in the "Last updated" date above.
11. Contact us
Questions about this policy or your data: Admin@Sprintunity.com
Your privacy matters to us.
If you have any questions, we're here to help.