Legal

Privacy Policy

Skrum collects the minimum data needed to run your collaborative workspace. This Policy explains what that is, how it is protected, and the choices you have.

Last updated: July 2026

1. Overview

This Privacy Policy explains what Skrum collects, why, how it is protected, and the choices you have. It applies to the Service at skrum.io.

Skrum collects only what the Service needs to operate. The sections below describe each category of data and its purpose.

2. Data we collect

Account data. Name, email address, password (scrypt hash only), preferred language, role, and email-verification state. Optional Google OAuth profile if you sign in with Google.

Session data. Session token, IP address, and user agent stored with each session for security and abuse prevention.

Usage data. Per-workspace counters for projects, storage, guest seats, AI actions, transcription minutes, and meeting-recording minutes. These counters enforce plan limits.

Product data. Projects, channels, messages, tasks, boards, sprints, meeting records and transcripts, files, code-activity metadata, reports, and integration settings. This is the working data you place in the Service.

Billing data. Subscription tier, invoices, and credit-ledger entries. Card details are handled by Polar; Skrum does not store full card numbers.

Vendor credentials. AI-provider keys and integration credentials, when you configure them. They are encrypted at rest with AES-256-GCM under a master key.

Contact-form messages. If you use the contact form, the message content and your email address are delivered to our support inbox via Resend.

3. How we use your data

We use the data above to:

  • Provision and operate your account, workspace, projects, and collaboration features.
  • Enforce plan limits and prevent abuse through rate limiting and cross-account isolation.
  • Process payments through Polar and maintain an invoice and credit-ledger history.
  • Send transactional email such as verification, password reset, invitations, notifications, reports, and deletion warnings. Marketing email is sent only where the corresponding preference and lawful basis apply.
  • Generate AI digests, meeting summaries, and action proposals only when the feature is invoked. The Service sends the bounded workspace context required for that request, never your stored provider key as prompt content.
  • Maintain audit logs for security. Audit logs never record email addresses, request bodies, headers, or sensitive parameters.

4. Cookies and similar technologies

Session cookie. A single httpOnly, SameSite=Lax cookie (better-auth.session_token) keeps you signed in. It is marked Secure in production.

CSRF cookie. A double-submit token (x-csrf-token by default) protects forms. It is SameSite=Strict and Secure in production.

Language cookie. A lang cookie stores your interface-language preference for one year.

Skrum does not use analytics, advertising, or third-party tracking cookies.

5. Data sharing and sub-processors

Skrum shares data only with the sub-processors required to run the Service:

  • Polar — payment processing and subscription management. Receives product IDs, customer references, and webhook events; it does not receive workspace content.
  • LiveKit — real-time meeting media and recording orchestration when meetings are enabled. It receives room identifiers, participant display data, and the audio/video you choose to transmit.
  • Configured object storage — stores files and meeting recordings in an S3-compatible object store managed for the Service.
  • AI providers — the configured provider receives bounded workspace context when you request a digest, summary, or proposal. Bring-your-own-key runs use the provider you select; operator-key runs follow the configured fallback chain. Provider terms and retention policies apply.
  • Resend — transactional and notification email delivery.

Each sub-processor is bound by its own data-protection terms. Skrum does not sell your data.

6. AI processing and human approval

AI generation runs only when an authorised user invokes it. For each run:

  • Skrum selects only the bounded messages, tasks, sprint facts, meeting transcript, or code metadata needed for the requested output.
  • The selected context is sent to your chosen bring-your-own-key provider or to the operator's configured provider chain. Provider credentials are never inserted into prompts.
  • Usage events record provider, model, token counts, latency, and cost metadata for billing and operations; prompt and completion bodies are not stored in usage telemetry.
  • Digests, summaries, and proposals are drafts. Skrum never changes tasks or publishes actions without an authorised human approval.
  • You control workspace retention and can delete generated outputs. External provider retention and training choices are governed by the provider and account settings you select.

Use AI output as assistance, not as authoritative advice. Review every output before relying on it or applying a proposed action.

7. Security safeguards

  • Vendor secrets and refresh tokens are encrypted at rest with AES-256-GCM using a master key.
  • Passwords are hashed with scrypt via Better Auth; plaintext passwords are never stored.
  • Cross-account isolation: every product route verifies ownership and returns 404 (not 403) for foreign resources so existence never leaks.
  • Rate limits on authentication and webhook routes reduce brute-force and volumetric abuse.
  • Two-factor authentication (TOTP + backup codes) is available on all accounts and required for admins.
  • CSRF is enforced via Origin and trusted-origins checks plus the double-submit cookie.

No system is perfectly secure. If you believe you have found a vulnerability, please contact security@skrum.io before public disclosure.

8. Data retention

Skrum retains workspace data for as long as your account is active, subject to workspace retention rules and legal holds. You can export or delete supported data from the product.

Billing records (invoices, credit ledger) are retained for the period required by tax law in the operating jurisdiction.

Audit logs that carry security-relevant metadata are retained on a rolling basis and never contain email addresses or request bodies.

9. Your rights (GDPR and similar)

Depending on your jurisdiction (EU/EEA, UK, California, etc.) you may have the right to:

  • Access a copy of your personal data.
  • Correct inaccurate data.
  • Export supported workspace data and reports in CSV, JSON, or PDF formats.
  • Delete your account. Deletion enters a 30-day grace period during which you can cancel. A final warning email is sent 24 hours before the purge. A legal hold may delay deletion where required by law.
  • Object to or restrict certain processing, and withdraw consent for marketing email at any time via notification preferences.
  • Lodge a complaint with your supervisory authority if you believe processing violates applicable law.

To exercise any of these rights, use the in-app data-rights endpoints (/api/legal/*) or contact privacy@skrum.io.

10. International data transfers

Your data may be processed by Skrum and its sub-processors in jurisdictions outside your country of residence. Where the EU/EEA is involved, transfers rely on appropriate safeguards such as Standard Contractual Clauses or another lawful transfer mechanism.

Current sub-processor locations and roles are listed on the sub-processors page.

11. Children’s privacy

The Service is not directed to children under 16. Skrum does not knowingly collect personal data from children. If you believe a minor has registered, contact privacy@skrum.io and the account will be removed.

12. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be announced by email (to verified accounts) or in-app at least 30 days before taking effect. The “Last updated” date below reflects the most recent revision.

13. Contact

Questions about this Privacy Policy or a data-subject request? Contact privacy@skrum.io.

Bring delivery into one workspace

Start your free workspace →

See managed plans, explicit caps, and credit packs on the pricing page.