Privacy

Privacy Policy

Last updated: 10 August 2026

This Privacy Policy explains how Precision Systems, the operator of Sprint Buddy (“Sprint Buddy”, “we”, “us”), collects, uses, stores and protects personal data when you use our website, application and related services. Questions? Write to support@sprintbuddy.com.

Data controller

  • Precision Systems
  • Mgr. Veronika Porubčanská
  • Kukučínova 52/2, 831 03 Bratislava, Slovakia
  • Company registration number: 56305117
  • Support: support@sprintbuddy.com · Privacy: privacy@sprintbuddy.app

1. What is Sprint Buddy?

Sprint Buddy is a project management and agile productivity platform that helps teams manage sprint information, generate reports, create retrospective insights, and automate selected project management workflows. Sprint Buddy can integrate with third-party services, including Atlassian Jira, to provide sprint reporting, issue synchronization, and retrospective analysis.

2. Information we collect

We collect the information necessary to provide, secure and improve the Service.

2.1 Account information

When you create an account or use Sprint Buddy, we may collect:

  • email address
  • name or display name
  • authentication provider identifiers
  • account and workspace information
  • subscription and account status

2.2 Jira and project data

If you connect a Jira Cloud workspace, we may process information retrieved from Jira and use it only to provide the Jira features you request (synchronization, sprint reporting, summaries, retrospective analysis and related functionality):

  • projects, boards and project metadata
  • issues, titles and descriptions
  • issue status, priority and story points
  • assignees and comments
  • sprints and timestamps
  • other information available through the Jira API that is necessary for the integration

2.3 Jira authentication (Atlassian OAuth 2.0)

Sprint Buddy connects to Jira Cloud exclusively using Atlassian OAuth 2.0 (3LO). You are redirected to Atlassian's authorization interface, where you authenticate with Atlassian and authorize Sprint Buddy to access the Jira data required by the integration.

  • Sprint Buddy never asks for and never stores your Atlassian password or a personal Jira API token.
  • We store only the OAuth credentials (encrypted access and refresh tokens and your Jira site identifier) needed to maintain the authorized connection.
  • OAuth credentials are encrypted at rest and are not exposed to other users of your workspace.
  • You can disconnect Jira at any time. After disconnecting we stop accessing your Jira account and delete or anonymize the synchronized Jira data in line with our retention policy.

2.4 Content you provide

You may submit content to Sprint Buddy, including sprint information, retrospectives, user stories, notes, project information, meeting notes, meeting transcripts and other text or files. We process it to provide the functionality you request. You are responsible for having the necessary rights and lawful basis to upload content relating to other individuals or your organization.

2.5 AI-generated content and AI processing

Sprint Buddy uses artificial intelligence for sprint summaries, retrospective insights, stakeholder reports, user stories, action items and other project-related outputs. When you use an AI feature, the information necessary to fulfil your request is sent to our AI provider - the Lovable AI Gateway, which routes requests to Google Gemini models. The provider processes this information solely to return the requested output on our behalf. We do not use customer Jira data or customer content to train third-party foundation models. AI-generated content may contain errors and should be reviewed before being relied upon for business decisions.

2.6 Billing information

Subscriptions and payments are processed by our payment provider. We do not store full payment card numbers on our servers. We may receive:

  • customer name and billing email
  • billing address
  • subscription plan and payment status
  • transaction identifiers
  • VAT or tax information

2.7 Technical information and telemetry

To operate, secure and improve Sprint Buddy we collect limited technical information - IP address, browser and device information, request paths, timestamps, application errors, diagnostic information and authentication or security events. We use it for security, troubleshooting, reliability, abuse prevention and service improvement, never for advertising or cross-site behavioural tracking.

3. How we use personal data

We use personal data to create and manage accounts, authenticate users, provide Sprint Buddy functionality, connect and synchronize Jira workspaces, generate reports and AI outputs, provide support, process subscriptions and payments, maintain and secure the Service, detect and prevent fraud and abuse, troubleshoot, improve the Service and comply with legal obligations. We do not sell personal data and we do not use customer Jira data or content to train third-party foundation models.

4. Legal bases for processing

Where the GDPR applies, we rely on:

  • Performance of a contract - creating and managing your account, providing Sprint Buddy and the Jira integration, synchronizing your authorized Jira workspace, generating requested outputs and processing your subscription.
  • Legal obligations - accounting, tax, financial and regulatory requirements.
  • Legitimate interests - securing the Service, preventing fraud and abuse, reliability, troubleshooting, improvement and defending legal claims, always balanced against your rights.
  • Consent - where consent is required, we request it beforehand and you may withdraw it at any time.

5. Jira and Atlassian data

Sprint Buddy accesses Jira data only after you authorize the connection through Atlassian OAuth 2.0, and only within the permissions you grant. We use Jira data to synchronize issues and sprints, generate sprint reports and retrospective insights, provide project analytics, create requested AI outputs and maintain the integration. We do not sell Jira data, do not use it for advertising and do not use it to train third-party foundation models. Jira data is not made available to other Sprint Buddy users except where it is intentionally shared within your workspace. Atlassian's own terms and privacy practices apply to your use of Jira.

6. How we share personal data

We do not sell personal data. We share it only with service providers processing it on our behalf, and we may disclose it where required by law or valid legal process, to protect our rights, users or property, to investigate security or abuse, or in connection with a merger, acquisition, financing, restructuring or sale of our business.

7. Subprocessors

The following providers may process personal data on our behalf. We may update this list as the Service evolves and will give notice of material changes where required:

  • Supabase - database, authentication and application infrastructure (account and application data)
  • Lovable AI Gateway (Google Gemini models) - AI inference (content submitted to AI features)
  • Stripe - payment processing, subscription management and tax handling (customer and subscription information)
  • Atlassian - Jira integration and authorized access to your Jira Cloud data

8. International data transfers

Sprint Buddy may use service providers located outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an appropriate legal mechanism such as an adequacy decision or Standard Contractual Clauses, depending on the provider and processing activity.

9. Data retention

We keep personal data only as long as necessary for the purposes described here, unless a longer period is required by law:

  • Account data - retained while your account is active; deleted or anonymized within 30 days of deletion or cancellation, except where retention is legally required.
  • Jira data - synchronized Jira data is deleted or anonymized within 7 days of disconnecting the integration, subject to backup retention.
  • OAuth credentials - deleted or invalidated when the Jira integration is disconnected.
  • Customer content - retained while needed to provide the Service, then deleted or anonymized with your account.
  • Technical logs - retained for a limited period for security, troubleshooting and reliability.
  • Billing records - retained for the period required by tax and accounting law.

10. Data security

We use reasonable technical and organizational measures to protect personal data, including encryption in transit, encryption of OAuth credentials at rest, access and authentication controls, restricted production access, secure credential management, monitoring and logging, and backup and recovery procedures. No internet-based service can guarantee absolute security. If we become aware of a personal data breach requiring notification, we will investigate, mitigate and notify affected parties and authorities where required.

11. Your GDPR rights

You may have the right to access, correct, delete, restrict or port your personal data, to object to certain processing and to withdraw consent. Contact privacy@sprintbuddy.app; we may need to verify your identity and will respond within one month. You may also lodge a complaint with your supervisory authority - in Slovakia, the Office for Personal Data Protection of the Slovak Republic.

12. Business customers and data processing

When an organization uses Sprint Buddy and provides personal data through the Service, the organization may act as the data controller and Sprint Buddy as a data processor. Where required, processing is governed by a Data Processing Agreement covering processing instructions, confidentiality, security, subprocessors, international transfers, assistance with data subject requests, breach notification and deletion or return of data. Request a DPA at privacy@sprintbuddy.app.

13. Cookies and similar technologies

We use cookies and similar technologies necessary for authentication, session management, security and user preferences. We do not use advertising or cross-site behavioural tracking cookies. Where consent is required for non-essential cookies, we obtain it before using them - you can review and change your choice on our cookie preferences page.

14. Third-party services

Sprint Buddy integrates with third-party services including Atlassian Jira, payment providers, AI providers, authentication providers and infrastructure providers. Your use of those services is also subject to their own terms and privacy practices.

15. Children's privacy

Sprint Buddy is intended for business and professional use and is not directed at children. We do not knowingly collect personal data from children where such collection is prohibited. If you believe a child has provided personal data to us, contact privacy@sprintbuddy.app.

16. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to the Service, our processing practices, our providers or applicable laws. Where required, we give appropriate notice before material changes take effect. The "Last updated" date above shows the most recent revision.

17. Contact us

Precision Systems, operator of Sprint Buddy, Kukucinova 52/2, 831 03 Bratislava, Slovakia. Support: support@sprintbuddy.com. Privacy: privacy@sprintbuddy.app.