Back to Sign In

Privacy Policy

Last updated: August 16, 2025

Our Commitment to Privacy

At Flow Metrics Dashboard, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, process, and safeguard your information when you use our service.

1. Information We Collect

Authentication Information

When you sign in using Google OAuth, we collect:

  • Email address: To identify and authenticate your account
  • Full name: To personalize your experience
  • Profile picture: To display in the user interface
  • Google user ID: To maintain your session securely

Jira Integration Data

When you connect your Jira instance, we temporarily process:

  • Work item data: Issue keys, summaries, statuses, dates
  • Workflow information: Status transitions and timestamps
  • Project metadata: Board configurations and sprint information
  • Historical data: For calculating cycle times and trends

Usage Information

  • Session data: Login times and dashboard interactions
  • Feature usage: Which analytics features you access
  • Technical information: Browser type, device information for optimization

2. How We Use Your Information

Service Delivery

  • Authenticate and authorize access to your account
  • Process Jira data to generate flow metrics and visualizations
  • Provide cycle time analysis, WIP aging, and Monte Carlo predictions
  • Generate charts and dashboard displays

AI-Powered Features

  • Send anonymized chart data to AI providers for analysis
  • Generate insights and recommendations about your metrics
  • Provide intelligent interpretations of workflow patterns

Service Improvement

  • Analyze usage patterns to improve features
  • Optimize performance and user experience
  • Troubleshoot technical issues

3. Data Processing Legal Basis (GDPR)

We process your personal data based on:

  • Legitimate Interest: Providing analytics services and improving functionality
  • Consent: When you authorize Google OAuth access
  • Contract Performance: Delivering the service you've requested

4. Data Sharing and Third Parties

Third-Party Services

  • Google OAuth: For authentication (subject to Google's privacy policy)
  • Jira: We connect to your Jira instance using your credentials
  • AI Providers: Anonymized chart data may be sent to OpenAI, Anthropic, or Google AI for analysis

No Data Selling

We do not sell, rent, or trade your personal data to any third parties for marketing purposes.

5. Data Retention and Storage

  • Session Data: Retained during your active session only
  • Authentication Information: Stored until you revoke access or delete your account
  • Jira Data: Processed in real-time and not permanently stored
  • Usage Analytics: Aggregated data retained for service improvement (max 24 months)

6. Data Security

We implement industry-standard security measures:

  • Encryption: Data in transit and at rest is encrypted
  • Access Controls: Strict access controls for our systems
  • Secure Authentication: OAuth 2.0 with secure tokens
  • Regular Security Audits: Ongoing security assessments

7. Your Rights (GDPR & Privacy Laws)

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Revoke consent for data processing

8. International Data Transfers

Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place, including:

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses (SCCs)
  • Other appropriate safeguards as required by applicable law

9. Cookies and Tracking

We use essential cookies for:

  • Authentication: Maintaining your login session
  • Security: CSRF protection and secure communication
  • Preferences: Remembering your theme and display settings

We do not use tracking cookies or third-party analytics beyond what's necessary for service operation.

10. Children's Privacy

Our service is not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of significant changes through the service or via email. The "Last updated" date indicates when the policy was last revised.

12. Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, please contact us through the support channels provided in the application.

Your Privacy Choices

You can revoke access to your Google account at any time through your Google Account settings. You can also request account deletion or data export by contacting our support team.

Effective Date: This Privacy Policy is effective as of August 16, 2025 and will remain in effect until modified.