Legal

Privacy Policy

Last updated: July 29, 2026

Introduction

Ubistart ("we," "our," or "us") operates Concordia, a planning poker application available at https://concordia.ubistart.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Concordia.

Concordia is intended for authorized Ubistart users (sign-in is limited to allowed email domains). By using the Service, you acknowledge the practices described here.

Information We Collect

Account information

When you sign in with Google, we receive and store account details needed to operate Concordia:

  • Name and email address
  • Profile picture (if provided by Google)
  • Role within Concordia (for example Superadmin, Project Manager, Estimator, or Observer) and whether the account is active
  • Authentication session data (Auth.js session cookies and related OAuth account records)

We do not collect passwords. Authentication is handled by Google OAuth.

User-generated content

We store content you create or submit through the Service, including:

  • Projects, descriptions, and estimation scale settings
  • Project collaborators and access grants
  • Planning poker sessions, stories (manual or imported), and final scores
  • Votes and estimates cast during sessions
  • Invitations (email, role, and invite status)

Jira integration (optional)

If you connect a Jira account, we store encrypted Atlassian OAuth tokens and optional project–site linkage so Concordia can import issues and write story points back to Jira. Atlassian processes data under its own policies when you authorize the app.

Usage and technical data

We automatically process technical data needed to run the Service:

  • Application and container logs (may include IP address, user agent, request paths, and errors)
  • Live session presence over WebSockets (who is connected to a poker session and related session state)

Information from third parties

  • Google — identity information when you sign in
  • Atlassian — accessible Jira sites and issue data when you connect Jira

How We Use Your Information

Provide and maintain the Service
Legal basis: contractual necessity / legitimate interest in operating an internal workplace tool
Authenticate users and enforce access control
Legal basis: contractual necessity / legitimate interest (roles, domain allowlist, and account status)
Run live planning poker sessions
Legal basis: contractual necessity
Optional Jira import and score sync
Legal basis: contractual necessity (when you choose to connect Jira)
Detect and prevent abuse; maintain security
Legal basis: legitimate interest
Comply with legal obligations
Legal basis: legal obligation

We do not use your information for marketing communications or sell personal information.

Data Storage and Security

Infrastructure

Concordia runs on servers hosted on Amazon Web Services (AWS EC2). Application data is stored in PostgreSQL on the same deployment environment. Traffic is served over HTTPS (TLS) via a reverse proxy (Caddy).

Security measures

  • Encryption in transit (TLS)
  • Atlassian OAuth tokens encrypted at rest (AES-256-GCM) before storage
  • Role-based access controls within the application
  • Database not exposed publicly; reachable only within the deployment network

Soft-deleted projects

Deleted projects may be retained in a recycle bin so a Superadmin can restore them. They remain subject to the access controls of the Service until permanently removed by an administrator.

Data breach response

If a breach affecting personal information occurs, we will take reasonable steps to investigate, contain the incident, and notify affected users and relevant authorities where required by applicable law.

Third-Party Services

We use the following third parties that may process data in connection with Concordia:

Google
Purpose: sign-in (OAuth). Data shared: identity profile (name, email, image) as provided by Google.
Atlassian
Purpose: optional Jira OAuth and API access. Data shared: OAuth tokens and Jira issue/project data you authorize Concordia to access.
Amazon Web Services
Purpose: hosting the Service. Data shared: application data and logs stored or processed on the VPS.

Each provider has its own privacy policy governing its processing of information.

Data Sharing

We do not sell your personal information. We may share data:

  • Within your organization — project owners, collaborators, session hosts, and Superadmins may see content and participation data needed to run sessions and manage access
  • With service providers — Google, Atlassian (when connected), and AWS, as described above
  • For legal compliance — when required by law, subpoena, or court order
  • During business transfers — in connection with a merger, acquisition, or asset sale, with notice where appropriate

Data Retention

Account data
Retained while your account is used for Concordia, and until an administrator deactivates or removes it
Projects, sessions, stories, and votes
Retained for as long as needed to provide the Service; soft-deleted projects remain until a Superadmin restores or permanently removes them
Session cookies
Retained until expiry or sign-out
Application logs
Rotated according to operational Docker log limits on the host
Jira connection tokens
Retained until you disconnect Jira or an administrator removes the connection

Your Rights

Depending on applicable law, you may have the right to:

  • Access a copy of your personal data
  • Correct inaccurate information
  • Request deletion or deactivation of your account
  • Object to or restrict certain processing
  • Lodge a complaint with a supervisory authority (for example, where GDPR applies)

Concordia is an internal workplace tool. Account and data requests are typically handled by Ubistart administrators (including Superadmins who manage users and invitations). To exercise these rights, contact us at [email protected].

Cookies

We use cookies and similar technologies for:

  • Authentication — keeping you signed in (Auth.js session cookies)
  • Security — supporting secure OAuth and session flows (including short-lived OAuth state cookies when connecting Jira)

We do not use analytics or advertising cookies. You can clear or block cookies in your browser; doing so may prevent sign-in.

International Data Transfers

If you access Concordia from outside the country where our AWS infrastructure is located, your information may be transferred to and processed in that hosting location. We rely on appropriate safeguards with our hosting and identity providers as applicable.

Children's Privacy

The Service is not intended for users under 16 years of age. We do not knowingly collect information from children.

Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be communicated through the Service or by email to administrators. Continued use of Concordia after changes take effect constitutes acceptance of the updated policy.

Contact

For privacy-related inquiries:

Email: [email protected]

Ubistart — Concordia at https://concordia.ubistart.com