Privacy Policy
Última actualización: 15 de septiembre de 2026
1. Introduction
East Agile ("Company", "we", "us", or "our"), a California corporation, operates East Agile Tracker at eastagiletracker.com ("Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
We are the data controller for the personal data we process through the Service. We are committed to protecting your privacy and handling your data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
2. Information We Collect
Account Information
When you create an account, we collect:
- Name and display name
- Email address
- Password (stored in hashed form)
- Organization or company name (if provided)
Usage Data
We automatically collect information about how you interact with the Service:
- Pages viewed and features used
- Actions performed (e.g., creating stories, updating projects)
- Date and time of access
- Browser type and version
- Device type and operating system
- IP address
Analytics Data
We use PostHog for product analytics. If you consent to analytics cookies, PostHog collects anonymized usage data to help us understand how the Service is used and how we can improve it. You can opt out of analytics at any time through your cookie preferences.
3. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract performance: Processing necessary to provide the Service to you, including account management, project data storage, and customer support.
- Legitimate interest: Processing necessary for our legitimate business interests, such as improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights.
- Consent: Processing based on your explicit consent, such as analytics cookies and marketing communications. You may withdraw consent at any time.
- Legal obligation: Processing necessary to comply with applicable laws and regulations.
4. How We Use Your Information
- Provide, maintain, and improve the Service
- Authenticate your identity and manage your account
- Send transactional emails (account verification, password resets)
- Respond to your support requests and inquiries
- Analyze usage patterns to improve functionality and user experience
- Detect, prevent, and address security issues and abuse
- Comply with legal obligations
5. Third-Party Services
We share your information with the following third-party services, only to the extent necessary to provide the Service:
- PostHog: Product analytics platform. With your consent, PostHog collects anonymized usage data. PostHog is configured to respect Do Not Track signals and cookie preferences.
- Medición de conversiones de Google Ads: Registra que una visita dio lugar a un registro. El modo de consentimiento mantiene denegado el almacenamiento publicitario hasta que aceptes las cookies no esenciales, y los identificadores de clic en anuncios se ocultan hasta entonces.
- Medición de sitios web de Google Analytics: Se carga mediante la misma etiqueta de Google, sin que nosotros la configuremos por separado. Registra las páginas que visitas, tu tipo de dispositivo y tu idioma, y reconoce a un visitante que vuelve durante un máximo de 400 días. No se almacena nada hasta que aceptes las cookies no esenciales.
- Asistente de IA Anthropic (Claude): Solo cuando conectas Claude a tu cuenta. Los resultados de las herramientas que Claude invoca (datos de proyectos e historias dentro de tu acceso) se envían a Anthropic y se rigen por la propia política de privacidad de Anthropic.
- Monitorización de errores de Honeybadger: Recibe informes de errores del servidor: la clase de error, el mensaje y la traza de pila, la ruta y el método de la solicitud, y tu ID de miembro. No se envían los parámetros de la solicitud, el cuerpo de la solicitud ni los datos de sesión.
No vendemos tus datos personales a terceros. Compartimos datos publicitarios y de medición con Google Ads y Google Analytics solo después de que aceptes las cookies no esenciales.
Aplicaciones conectadas y asistentes de IA
Puedes conectar a tu cuenta una aplicación de terceros, como Claude de Anthropic. Una aplicación conectada actúa en tu nombre en todos los proyectos a los que perteneces, con los permisos de tu rol en cada uno. Mediante un conjunto fijo de herramientas puede leer y escribir historias, comentarios, responsables de historias, iteraciones, epics, miembros del proyecto y menciones. Puede archivar historias, pero no puede eliminar nada de forma permanente.
Consentimiento
Cada conexión requiere tu aprobación explícita en nuestra página de consentimiento, que indica la aplicación y la cuenta a la que se concede el acceso. Tu contraseña, segundo factor o llave de acceso nunca se comparten con la aplicación.
Qué almacenamos
- El código de autorización de un solo uso, almacenado como hash SHA-256. Caduca a los 5 minutos y solo puede usarse una vez.
- El token de acceso de la aplicación (una clave ea_mcp_), almacenado en forma de hash. Caduca a los 30 minutos.
- Un token de actualización, almacenado como hash, que la aplicación canjea por nuevos tokens de acceso. Se reemplaza en cada uso y caduca a los 30 días.
- El identificador de cliente de la aplicación (la URL de sus metadatos publicados, cuyo nombre muestra nuestra página de consentimiento) y su URI de redirección.
- Cuándo se creó la conexión y cuándo se usó por última vez.
- Una entrada en nuestro registro de auditoría de seguridad al establecerse la conexión, que registra el identificador de cliente de la aplicación.
Datos enviados a la aplicación conectada
Cuando la aplicación llama a una herramienta, el resultado (datos de proyectos e historias dentro de tu acceso) se envía a esa aplicación y pasa a regirse por la política de privacidad de su proveedor. Para Claude, consulta la Política de privacidad de Anthropic. Solo recibimos el nombre de la herramienta y los argumentos de cada llamada, no tu conversación con la aplicación.
Revocar el acceso
Puedes ver y revocar cada conexión en Configuración de la cuenta → Aplicaciones conectadas. Revocar una conexión desactiva sus tokens de acceso y de actualización a partir de la siguiente solicitud de la aplicación.
Conservación
Los códigos de autorización usados o caducados, los tokens de actualización caducados y los tokens de acceso caducados se eliminan automáticamente mediante una tarea de limpieza que se ejecuta cada 5 minutos.
Registros
Por cada solicitud que hace una aplicación conectada, registramos el tipo de solicitud, su resultado y el nombre de la herramienta, nunca los argumentos de la herramienta ni los valores de los tokens. Si una llamada a una herramienta falla por un error del servidor, comunicamos el error, el nombre de la herramienta y tu ID de miembro a Honeybadger, nuestro proveedor de monitorización de errores.
6. Cookies
We use cookies and similar technologies to operate the Service. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:
- Account data is retained while your account is active and for 30 days after deletion to allow recovery.
- Project data (stories, comments, history) is retained while the associated project exists.
- Usage and analytics data is retained for up to 24 months, then aggregated or deleted.
You may request deletion of your data at any time by contacting us at privacy@eastagile.com or by deleting your account through the Service settings.
8. Your Rights Under GDPR
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data ("right to be forgotten").
- Right to data portability: Request your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest.
- Right to restrict processing: Request that we limit how we use your data.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at privacy@eastagile.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Your Rights Under CCPA
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: Request deletion of your personal information, subject to certain exceptions.
- Right to opt-out: Opt out of the "sale" of your personal information. Note: we do not sell personal information.
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a CCPA request, contact us at privacy@eastagile.com. We will verify your identity before processing your request and respond within 45 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS) and at rest, access controls, regular security assessments, and employee training. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
11. International Data Transfers
Your data may be transferred to and processed in the United States. If you are located outside the United States, we ensure that appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses approved by the European Commission where applicable.
12. Children's Privacy
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children under 16. If we learn that we have collected personal data from a child under 16, we will take steps to delete that information promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and, where appropriate, by sending you an email notification. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:
East Agile
Email: privacy@eastagile.com
Website: eastagiletracker.com