Legal
Privacy Policy
Last updated: July 29, 2026
Introduction
Ubistart ("we," "our," or "us") operates Concordia, a planning poker application available at https://concordia.ubistart.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Concordia.
Concordia is intended for authorized Ubistart users (sign-in is limited to allowed email domains). By using the Service, you acknowledge the practices described here.
Information We Collect
Account information
When you sign in with Google, we receive and store account details needed to operate Concordia:
- Name and email address
- Profile picture (if provided by Google)
- Role within Concordia (for example Superadmin, Project Manager, Estimator, or Observer) and whether the account is active
- Authentication session data (Auth.js session cookies and related OAuth account records)
We do not collect passwords. Authentication is handled by Google OAuth.
User-generated content
We store content you create or submit through the Service, including:
- Projects, descriptions, and estimation scale settings
- Project collaborators and access grants
- Planning poker sessions, stories (manual or imported), and final scores
- Votes and estimates cast during sessions
- Invitations (email, role, and invite status)
Jira integration (optional)
If you connect a Jira account, we store encrypted Atlassian OAuth tokens and optional project–site linkage so Concordia can import issues and write story points back to Jira. Atlassian processes data under its own policies when you authorize the app.
Usage and technical data
We automatically process technical data needed to run the Service:
- Application and container logs (may include IP address, user agent, request paths, and errors)
- Live session presence over WebSockets (who is connected to a poker session and related session state)
Information from third parties
- Google — identity information when you sign in
- Atlassian — accessible Jira sites and issue data when you connect Jira
How We Use Your Information
- Provide and maintain the Service
- Legal basis: contractual necessity / legitimate interest in operating an internal workplace tool
- Authenticate users and enforce access control
- Legal basis: contractual necessity / legitimate interest (roles, domain allowlist, and account status)
- Run live planning poker sessions
- Legal basis: contractual necessity
- Optional Jira import and score sync
- Legal basis: contractual necessity (when you choose to connect Jira)
- Detect and prevent abuse; maintain security
- Legal basis: legitimate interest
- Comply with legal obligations
- Legal basis: legal obligation
We do not use your information for marketing communications or sell personal information.
Data Storage and Security
Infrastructure
Concordia runs on servers hosted on Amazon Web Services (AWS EC2). Application data is stored in PostgreSQL on the same deployment environment. Traffic is served over HTTPS (TLS) via a reverse proxy (Caddy).
Security measures
- Encryption in transit (TLS)
- Atlassian OAuth tokens encrypted at rest (AES-256-GCM) before storage
- Role-based access controls within the application
- Database not exposed publicly; reachable only within the deployment network
Soft-deleted projects
Deleted projects may be retained in a recycle bin so a Superadmin can restore them. They remain subject to the access controls of the Service until permanently removed by an administrator.
Data breach response
If a breach affecting personal information occurs, we will take reasonable steps to investigate, contain the incident, and notify affected users and relevant authorities where required by applicable law.
Third-Party Services
We use the following third parties that may process data in connection with Concordia:
- Purpose: sign-in (OAuth). Data shared: identity profile (name, email, image) as provided by Google.
- Atlassian
- Purpose: optional Jira OAuth and API access. Data shared: OAuth tokens and Jira issue/project data you authorize Concordia to access.
- Amazon Web Services
- Purpose: hosting the Service. Data shared: application data and logs stored or processed on the VPS.
Each provider has its own privacy policy governing its processing of information.
Data Sharing
We do not sell your personal information. We may share data:
- Within your organization — project owners, collaborators, session hosts, and Superadmins may see content and participation data needed to run sessions and manage access
- With service providers — Google, Atlassian (when connected), and AWS, as described above
- For legal compliance — when required by law, subpoena, or court order
- During business transfers — in connection with a merger, acquisition, or asset sale, with notice where appropriate
Data Retention
- Account data
- Retained while your account is used for Concordia, and until an administrator deactivates or removes it
- Projects, sessions, stories, and votes
- Retained for as long as needed to provide the Service; soft-deleted projects remain until a Superadmin restores or permanently removes them
- Session cookies
- Retained until expiry or sign-out
- Application logs
- Rotated according to operational Docker log limits on the host
- Jira connection tokens
- Retained until you disconnect Jira or an administrator removes the connection
Your Rights
Depending on applicable law, you may have the right to:
- Access a copy of your personal data
- Correct inaccurate information
- Request deletion or deactivation of your account
- Object to or restrict certain processing
- Lodge a complaint with a supervisory authority (for example, where GDPR applies)
Concordia is an internal workplace tool. Account and data requests are typically handled by Ubistart administrators (including Superadmins who manage users and invitations). To exercise these rights, contact us at [email protected].
Cookies
We use cookies and similar technologies for:
- Authentication — keeping you signed in (Auth.js session cookies)
- Security — supporting secure OAuth and session flows (including short-lived OAuth state cookies when connecting Jira)
We do not use analytics or advertising cookies. You can clear or block cookies in your browser; doing so may prevent sign-in.
International Data Transfers
If you access Concordia from outside the country where our AWS infrastructure is located, your information may be transferred to and processed in that hosting location. We rely on appropriate safeguards with our hosting and identity providers as applicable.
Children's Privacy
The Service is not intended for users under 16 years of age. We do not knowingly collect information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be communicated through the Service or by email to administrators. Continued use of Concordia after changes take effect constitutes acceptance of the updated policy.
Contact
For privacy-related inquiries:
Email: [email protected]
Ubistart — Concordia at https://concordia.ubistart.com
