Privacy Policy

Ultimo aggiornamento: 15 settembre 2026

1. Introduction

East Agile ("Company", "we", "us", or "our"), a California corporation, operates East Agile Tracker at eastagiletracker.com ("Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.

We are the data controller for the personal data we process through the Service. We are committed to protecting your privacy and handling your data in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

2. Information We Collect

Account Information

When you create an account, we collect:

  • Name and display name
  • Email address
  • Password (stored in hashed form)
  • Organization or company name (if provided)

Usage Data

We automatically collect information about how you interact with the Service:

  • Pages viewed and features used
  • Actions performed (e.g., creating stories, updating projects)
  • Date and time of access
  • Browser type and version
  • Device type and operating system
  • IP address

Analytics Data

We use PostHog for product analytics. If you consent to analytics cookies, PostHog collects anonymized usage data to help us understand how the Service is used and how we can improve it. You can opt out of analytics at any time through your cookie preferences.

3. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service to you, including account management, project data storage, and customer support.
  • Legitimate interest: Processing necessary for our legitimate business interests, such as improving the Service, ensuring security, and preventing fraud, where these interests are not overridden by your rights.
  • Consent: Processing based on your explicit consent, such as analytics cookies and marketing communications. You may withdraw consent at any time.
  • Legal obligation: Processing necessary to comply with applicable laws and regulations.

4. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Authenticate your identity and manage your account
  • Send transactional emails (account verification, password resets)
  • Respond to your support requests and inquiries
  • Analyze usage patterns to improve functionality and user experience
  • Detect, prevent, and address security issues and abuse
  • Comply with legal obligations

5. Third-Party Services

We share your information with the following third-party services, only to the extent necessary to provide the Service:

  • PostHog: Product analytics platform. With your consent, PostHog collects anonymized usage data. PostHog is configured to respect Do Not Track signals and cookie preferences.
  • Misurazione delle conversioni di Google Ads: Registra che una visita ha portato a un'iscrizione. La modalità di consenso mantiene negata l'archiviazione pubblicitaria finché non accetti i cookie non essenziali e, fino ad allora, gli identificatori di clic sugli annunci vengono oscurati.
  • Misurazione dei siti web di Google Analytics: Caricato dallo stesso tag Google, non configurato separatamente da noi. Registra le pagine che visiti, il tipo di dispositivo e la lingua, e riconosce un visitatore che ritorna per un massimo di 400 giorni. Nulla viene memorizzato finché non accetti i cookie non essenziali.
  • Assistente IA Anthropic (Claude): Solo quando colleghi Claude al tuo account. I risultati degli strumenti che Claude richiama (dati di progetti e storie nei limiti del tuo accesso) vengono inviati ad Anthropic e sono disciplinati dall'informativa sulla privacy di Anthropic.
  • Monitoraggio degli errori Honeybadger: Riceve le segnalazioni degli errori del server: la classe dell'errore, il messaggio e lo stack trace, il percorso e il metodo della richiesta e il tuo ID membro. I parametri, il corpo della richiesta e i dati di sessione non vengono inviati.

Non vendiamo i tuoi dati personali a terzi. Condividiamo i dati pubblicitari e di misurazione con Google Ads e Google Analytics solo dopo che hai accettato i cookie non essenziali.

App collegate e assistenti IA

Puoi collegare al tuo account un'app di terze parti, come Claude di Anthropic. Un'app collegata agisce per tuo conto in ogni progetto di cui fai parte, con i permessi del tuo ruolo in ciascuno. Tramite un insieme fisso di strumenti può leggere e scrivere storie, commenti, responsabili delle storie, iterazioni, epic, membri del progetto e menzioni. Può archiviare le storie, ma non può eliminare nulla in modo permanente.

Consenso

Ogni collegamento richiede la tua approvazione esplicita nella nostra pagina di consenso, che indica l'app e l'account a cui viene concesso l'accesso. La tua password, il secondo fattore o la passkey non vengono mai condivisi con l'app.

Cosa conserviamo

  • Il codice di autorizzazione monouso, conservato come hash SHA-256. Scade dopo 5 minuti e può essere usato una sola volta.
  • Il token di accesso dell'app (una chiave ea_mcp_), conservato in forma hash. Scade dopo 30 minuti.
  • Un token di aggiornamento, conservato come hash, che l'app scambia con nuovi token di accesso. Viene sostituito a ogni utilizzo e scade dopo 30 giorni.
  • L'identificatore client dell'app (l'URL dei suoi metadati pubblicati, il cui nome è mostrato nella nostra pagina di consenso) e il suo URI di reindirizzamento.
  • Quando il collegamento è stato creato e quando è stato usato l'ultima volta.
  • Una voce nel nostro registro di audit di sicurezza al momento del collegamento, che registra l'identificatore client dell'app.

Dati inviati all'app collegata

Quando l'app richiama uno strumento, il risultato (dati di progetti e storie nei limiti del tuo accesso) viene inviato a quell'app ed è poi disciplinato dall'informativa sulla privacy del fornitore dell'app. Per Claude, consulta l'Informativa sulla privacy di Anthropic. Riceviamo solo il nome dello strumento e gli argomenti di ogni chiamata, non la tua conversazione con l'app.

Revoca dell'accesso

Puoi visualizzare e revocare ogni collegamento in Impostazioni account → App collegate. La revoca di un collegamento disattiva i suoi token di accesso e di aggiornamento a partire dalla richiesta successiva dell'app.

Conservazione

I codici di autorizzazione usati o scaduti, i token di aggiornamento scaduti e i token di accesso scaduti vengono eliminati automaticamente da un processo di pulizia eseguito ogni 5 minuti.

Registrazione

Per ogni richiesta effettuata da un'app collegata registriamo il tipo di richiesta, il suo esito e il nome dello strumento, mai gli argomenti dello strumento o i valori dei token. Se una chiamata a uno strumento non riesce per un errore del server, segnaliamo l'errore, il nome dello strumento e il tuo ID membro a Honeybadger, il nostro fornitore di monitoraggio degli errori.

6. Cookies

We use cookies and similar technologies to operate the Service. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Specifically:

  • Account data is retained while your account is active and for 30 days after deletion to allow recovery.
  • Project data (stories, comments, history) is retained while the associated project exists.
  • Usage and analytics data is retained for up to 24 months, then aggregated or deleted.

You may request deletion of your data at any time by contacting us at privacy@eastagile.com or by deleting your account through the Service settings.

8. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to data portability: Request your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interest.
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at privacy@eastagile.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.

9. Your Rights Under CCPA

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to delete: Request deletion of your personal information, subject to certain exceptions.
  • Right to opt-out: Opt out of the "sale" of your personal information. Note: we do not sell personal information.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, contact us at privacy@eastagile.com. We will verify your identity before processing your request and respond within 45 days.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit (TLS) and at rest, access controls, regular security assessments, and employee training. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

11. International Data Transfers

Your data may be transferred to and processed in the United States. If you are located outside the United States, we ensure that appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses approved by the European Commission where applicable.

12. Children's Privacy

The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children under 16. If we learn that we have collected personal data from a child under 16, we will take steps to delete that information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service and, where appropriate, by sending you an email notification. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

East Agile
Email: privacy@eastagile.com
Website: eastagiletracker.com