Privacy Policy
Last updated: October 6, 2026
This policy explains what Planning Poker Web collects, why, who can see it, and how you can have it removed. It covers this website and the application at https://app.planningpokerweb.com.
What we collect
- Account data: name, e-mail address, a hash of your password (never the password), your language, and, if you turn it on, the secret for two-factor authentication.
- Workspace data: the organizations you belong to, your role in them, and the members you invite.
- Session data: rooms, tasks, estimates, votes and retro notes you or your team create. Votes and retro notes are stored with the name of the person, whether signed in or a guest who typed one.
- Integrations: if you connect Jira, Linear or ClickUp, the access token or OAuth credentials you give us, stored encrypted, and the issue titles, references and short description teasers you import.
- Technical data: IP address and browser information for sign-in sessions and security logs.
If you write to us through the contact form, we keep your name, e-mail address and message to answer you.
Guests who join a room do not create an account. We keep the name they typed and what they do in that room.
Why we use it
- to run the service: rooms, voting, retros, history and exports;
- to keep accounts and rooms secure: sign-in protection, abuse prevention and audit logs;
- to send the e-mails the service needs, such as the verification code, invitations and password resets;
- to answer you when you write to us.
We do not sell personal data.
Who can see it
- Inside a room, people see what the room shows: the tasks, who is at the table, and votes after the reveal. A vote is secret until then.
- Names stored with votes and retro notes are shown only to people who manage planning poker in the organization. Other people see "Player 1", "Player 2" and so on. This is a rule of the application.
- Organization owners and administrators can see the members of their organization.
Service providers
- Google Firebase runs the live part of a room (who is at the table, votes before they are revealed, retro notes while the retro is open). That data is removed when the room is deleted.
- Our hosting and e-mail providers process data on our behalf to run the service and deliver e-mail.
- Jira, Linear and ClickUp, only if you connect them, and only to import tasks and write estimates back.
Cookies and browser storage
The application keeps your sign-in session and your preferences (theme, language) in your browser. This website keeps your theme preference and, only if you accept it in the banner, a cookie from our analytics tool (below). We do not use advertising cookies.
Analytics
If you accept, we use PostHog to see how this website is used: the pages you visit, your approximate location, your browser and device, and how you arrived. It helps us improve the site. It is switched off until you accept, it respects your browser's "Do Not Track" setting, and you can change your mind at any time with "Privacy choices" in the footer.
How long we keep it
Until you delete it. You can delete your account yourself, at any time, from your profile settings. Deleting a room removes its tasks, rounds, votes, players and retro, in our database and in Firebase. Backups and logs are rotated on a schedule.
Your rights
You can delete your account yourself from your profile settings. For anything else, such as asking to access, correct or export your personal data, or to object to how we use it (including under Brazil's LGPD and, where it applies, the GDPR), write to the address below. If you are a guest and want a name removed from a room, ask the person who hosts it, or write to us.
Children
The service is meant for working professionals and is not directed at children.
Changes
If we change this policy in a way that matters, we will update the date above and, for significant changes, tell account holders by e-mail.
Contact
Questions about this page? Write to hello@planningpokerweb.com.