Privacy Policy
Last updated: 21 June 2026
This Privacy Policy explains how Sprintly (“Sprintly”, “we”, “us”) collects, uses, and protects your information when you use our web-based agile project-management platform at sprintly.site. By creating an account or using the service, you agree to the practices described here.
Information We Collect
- Account information. When you register with an email and password, or sign in with Google, we collect your name, email address, and (for Google sign-in) your basic profile information such as your profile picture.
- Project content. The organisations, projects, sprints, tasks, comments, attachments, and skill information you create or upload while using the platform.
- Uploaded documents. Files you upload for the AI features are processed to provide document-grounded answers and planning (see below).
- Technical data. Limited technical and log information needed to operate the service securely, such as request metadata used for authentication, rate limiting, and security monitoring. Logs are stripped of personally identifiable information before retention.
How We Use Your Information
- To provide, maintain, and secure the platform and your account.
- To deliver the AI features — sprint planning, estimation, skill-based task assignment, and document-grounded question answering.
- To send transactional emails such as account and invitation notices.
- To detect, prevent, and investigate security incidents and abuse.
We do not sell your personal data.
Third-Party Services
Sprintly relies on the following service providers to operate:
- Supabase — managed database, authentication, and file storage. Your account and project data are stored on Supabase’s infrastructure.
- Google — Google Sign-In (OAuth) for authentication, and the Google Gemini API, which powers the AI features. Text from your prompts and uploaded documents may be sent to the Gemini API to generate responses and embeddings.
These providers process data on our behalf under their own terms and privacy policies.
Documents and AI Processing
When you upload a document for the AI features, its text is split into chunks and converted into numerical embeddings (using Google Gemini) so that relevant passages can be retrieved to answer your questions. These chunks and embeddings are stored against your project and are accessible only within that project.
Data Storage in Your Browser
After you sign in, your authentication tokens are stored in your browser’s local storage so that you remain signed in. Clearing your browser storage or logging out removes them.
Data Retention and Security
We retain your data for as long as your account is active or as needed to provide the service. Data is encrypted in transit (HTTPS) and at rest by our managed data provider, access is controlled by per-user authorisation and database row-level security, and traffic is filtered at the network edge. You may request deletion of your account and associated data at any time.
Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. To exercise these rights, contact us using the details below.
Children’s Privacy
Sprintly is not intended for children under 13, and we do not knowingly collect personal data from them.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
Contact Us
If you have any questions about this Privacy Policy or your data, contact us at support@sprintly.site.