What we collect
Only what's needed to run your workspaces, and nothing we don't tell you about.
Account information
When you sign up we store your full name and email address, plus a securely hashed password if you register with email. If you use a social provider, we keep the identifiers that provider returns.
Workspace content
Everything you create in a workspace is yours and stays scoped to it: projects, sprints, tickets and their comments, documents and subpages, attachments, member roles, and permission grants. This includes assignment notifications we send to your workspace members by email.
Usage & device information
Basic analytics such as pages visited, feature interactions, and device/browser type help us find dead ends and measure what works. We do not sell or trade this data.
How we use your information
Every use case below exists to make the workspace function, never to profile you.
- Provide the service: authenticate you, render your boards and documents, enforce permissions, and send assignment/approval emails.
- Keep it secure: verify workspace membership, detect unauthorized access, and maintain audit trails through the Agile History viewer.
- Improve the product: aggregate, de-identified usage signals to prioritize features and fix performance issues.
The short version
Data retention
We keep what you create until you don't need it anymore.
Workspace content (projects, sprints, tickets, documents) is kept for as long as your account is active and the workspace exists. Soft-deleted items are recoverable by leads for a grace period, after which they are permanently removed from our systems.
Account records are retained while you remain a member of at least one workspace, plus a short period after deletion so a reactivation or data request can still be honored. Email verification links expire in 24 hours and password reset links in 1 hour by design.
Security
Permissions are enforced server-side, every request.
- Passwords are hashed with industry-standard algorithms, and we never store them in plain text.
- All traffic is served over HTTPS in transit, and data is encrypted at rest by our hosting provider.
- Lead-only documents and ticket instances are filtered and enforced on the server, so a crafted client request can't bypass a role boundary.
- Access to workspaces is gated by an approval queue; invites must be accepted, and requests must be approved by a lead.
Your rights & choices
Wherever you are, you get the basics: access, correction, deletion.
- Access & export: leads can export project analytics (including XLSX reports) directly from Agile History.
- Correction: update your name, email, and profile from your profile page.
- Deletion: leave a workspace to remove yourself from it, or contact us to delete your account and its data entirely.
- Marketing opt-out: we only email about your workspaces or account security, with no marketing lists, so there's nothing to opt out of.
Children's privacy
Agilytics is intended for working technical teams and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us and we will delete it promptly.
Changes to this policy
We may update this policy as the product evolves. Material changes will be announced in-app and the “last updated” date at the top of this page will move. Continued use of Agilytics after a change means you accept the revised policy.
Contact us
Questions about this policy or a privacy request? Reach the team at privacy@agilytics.com and we'll respond within 5 business days. Please include the email address associated with your account so we can verify your request.