Privacy Policy

Last updated 5 August 2026

This policy explains what Discord Scrum Board ("the Service") collects, why, and what happens to it. It describes what the Service actually does — not what it might do later.

1. What is collected

From Discord, when you use the Service:

What you create:

No password is ever collected: sign-in happens through Discord. No payment details are collected — the Service is free. There are no third-party analytics or advertising scripts; Discord's Activity sandbox blocks them outright.

2. Why

The bot sends you a direct message when someone assigns work to you. You can turn that off in the account menu inside the activity, and every such message says so.

To operate the board: to show you your server's projects, to attribute changes to the right person, to check that you are a member of the server whose board you are requesting, and to notify people in Discord about work assigned to them. Feature requests are used to decide what to build.

3. Where it is stored

Data is held in a PostgreSQL database hosted by Supabase (AWS, Canada) and served by an application running on Fly.io (Toronto). Discord provides the identity and delivers the bot's messages. These three are the only processors involved.

4. Who it is shared with

Nobody. Data is not sold, rented, or used for advertising or model training. It is disclosed only to the processors above, and where required by law.

5. Who can see your content

Boards are scoped to the Discord server they were created in, and the Service checks your membership of that server on every request. Within a server, a board is visible to every member by default, or — if it has been restricted — only to holders of a chosen Discord role or to people who can read a chosen Discord channel. That check runs on every read, including the live updates and anything the bot posts. Server administrators can see every board. The operator can technically access stored data in order to run and debug the Service.

6. How long it is kept

7. Your choices

8. Security

Connections are encrypted in transit. Sessions are signed and expire. Access to the database is restricted to the application and the operator. No system is perfectly secure, and the Service should not be used to store sensitive personal information.

9. Children

The Service is not directed at children under the minimum age required by Discord for their country. If such an account's data has been collected, contact the address below and it will be deleted.

10. Changes

This policy may change. The date at the top shows when it last did.

11. Contact

cmcruse15@gmail.com