Privacy Policy
Last updated: July 19, 2025
1. Information We Collect
eephus collects the following data to provide our agile automation services:
- Slack Workspace Data: Team names, user IDs, channel information
- Message Content: Standup responses, retrospective feedback, survey answers
- Usage Analytics: Feature usage, interaction patterns, sentiment scores
- JIRA Integration Data: Project keys, ticket information (when connected)
- Billing Information: Payment details processed through Stripe
2. How We Use Your Data
We use collected data exclusively to:
- Provide AI-powered sentiment analysis and team insights
- Generate automated reports and recommendations
- Improve our natural language processing algorithms
- Provide customer support and technical assistance
- Process billing and subscription management
Data Reception and Minimal Processing
eephus receives data through Slack API interactions (user IDs, channel information, message content) as necessary for functionality. We only use the minimum data required and request only appropriate and necessary Slack permissions. Some data may be received by our service through system logging and API interactions but is not actively processed unless specifically needed for the service.
3. Data Storage and Security
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest
- Access Control: Strict role-based access with multi-factor authentication
- Data Centers: AWS infrastructure with SOC 2 Type II compliance
- Data Retention: Data retained according to your subscription plan (30 days to unlimited)
4. Data Sharing and Disclosure
We never sell your data. Limited sharing occurs only for:
- Service Providers: AWS (hosting), Stripe (payments), OpenAI (AI processing)
- Legal Requirements: When required by law or to protect our rights
- Anonymous Analytics: Aggregated, non-identifiable usage statistics
5. Your Rights and Controls
You have the right to:
- Access: Request copies of your data through your workspace admin
- Deletion: Request data deletion by uninstalling the app or contacting us. All data will be permanently deleted within 14 business days
- Portability: Export your data in machine-readable formats
- Correction: Update or correct inaccurate information
- Opt-out: Disable specific features like sentiment analysis
6. Third-Party Services
eephus integrates with:
- Slack: Governed by Slack's Privacy Policy
- JIRA: Governed by Atlassian's Privacy Policy
- OpenAI: AI processing with data protection agreements
- Stripe: Payment processing with PCI DSS compliance
7. International Data Transfers
Data may be processed in the United States and other countries where our service providers operate. We ensure adequate protection through:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
- Additional safeguards for sensitive data
8. Children's Privacy
ScrumDog is not intended for users under 13. We do not knowingly collect personal information from children under 13.
9. Data Breach Notification
In the event of a data breach, we will:
- Notify affected users within 72 hours
- Provide details about the incident and our response
- Offer guidance on protective measures
- Cooperate with regulatory authorities as required
10. Policy Updates
We may update this policy periodically. Significant changes will be communicated through:
- Email notifications to workspace administrators
- In-app notifications through ScrumDog
- Updated version posted on our website
11. Contact Information
For privacy-related questions or requests:
- Email: privacy@scrumdog.app
- Data Protection Officer: dpo@scrumdog.app
- Mailing Address: ScrumDog Privacy Team, [Company Address]
12. Compliance and Data Handling
This policy complies with:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Slack App Directory Requirements and Developer Policy
- Slack's Privacy Model (users only access data they would normally have access to in Slack)
- SOC 2 Type II Standards
App Discontinuation
If ScrumDog is discontinued or removed from your workspace, all associated data will be deleted within 14 business days as required by Slack's Developer Policy.
This privacy policy is designed to be transparent and comprehensive. If you have questions about any aspect of our data practices, please contact us.