At Flow Metrics Dashboard, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, process, and safeguard your information when you use our service.
1. Information We Collect
Authentication Information
When you sign in using Google OAuth, we collect:
Email address: To identify and authenticate your account
Full name: To personalize your experience
Profile picture: To display in the user interface
Google user ID: To maintain your session securely
Jira Integration Data
When you connect your Jira instance, we temporarily process:
Work item data: Issue keys, summaries, statuses, dates
Workflow information: Status transitions and timestamps
Project metadata: Board configurations and sprint information
Historical data: For calculating cycle times and trends
Usage Information
Session data: Login times and dashboard interactions
Feature usage: Which analytics features you access
Technical information: Browser type, device information for optimization
2. How We Use Your Information
Service Delivery
Authenticate and authorize access to your account
Process Jira data to generate flow metrics and visualizations
Provide cycle time analysis, WIP aging, and Monte Carlo predictions
Generate charts and dashboard displays
AI-Powered Features
Send anonymized chart data to AI providers for analysis
Generate insights and recommendations about your metrics
Provide intelligent interpretations of workflow patterns
Service Improvement
Analyze usage patterns to improve features
Optimize performance and user experience
Troubleshoot technical issues
3. Data Processing Legal Basis (GDPR)
We process your personal data based on:
Legitimate Interest: Providing analytics services and improving functionality
Consent: When you authorize Google OAuth access
Contract Performance: Delivering the service you've requested
4. Data Sharing and Third Parties
Third-Party Services
Google OAuth: For authentication (subject to Google's privacy policy)
Jira: We connect to your Jira instance using your credentials
AI Providers: Anonymized chart data may be sent to OpenAI, Anthropic, or Google AI for analysis
No Data Selling
We do not sell, rent, or trade your personal data to any third parties for marketing purposes.
5. Data Retention and Storage
Session Data: Retained during your active session only
Authentication Information: Stored until you revoke access or delete your account
Jira Data: Processed in real-time and not permanently stored
Usage Analytics: Aggregated data retained for service improvement (max 24 months)
6. Data Security
We implement industry-standard security measures:
Encryption: Data in transit and at rest is encrypted
Access Controls: Strict access controls for our systems
Secure Authentication: OAuth 2.0 with secure tokens
Portability: Receive your data in a machine-readable format
Restriction: Limit how we process your data
Objection: Object to processing based on legitimate interests
Withdraw Consent: Revoke consent for data processing
8. International Data Transfers
Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place, including:
Adequacy decisions by the European Commission
Standard Contractual Clauses (SCCs)
Other appropriate safeguards as required by applicable law
9. Cookies and Tracking
We use essential cookies for:
Authentication: Maintaining your login session
Security: CSRF protection and secure communication
Preferences: Remembering your theme and display settings
We do not use tracking cookies or third-party analytics beyond what's necessary for service operation.
10. Children's Privacy
Our service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of significant changes through the service or via email. The "Last updated" date indicates when the policy was last revised.
12. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights, please contact us through the support channels provided in the application.
Your Privacy Choices
You can revoke access to your Google account at any time through your Google Account settings. You can also request account deletion or data export by contacting our support team.
Effective Date: This Privacy Policy is effective as of August 16, 2025 and will remain in effect until modified.