SprintCards

Privacy Policy

Effective date: 14 August 2026

Who is responsible

The controller responsible for processing your data under the GDPR is:

Tobias Horak
Email: hello@tobiashorak.com

What we process and why

SprintCards is a real-time planning-poker tool. To let you create and join estimation rooms, we process:

  • Display name — the name you type when you create or join a room, shown to others in that room.
  • Anonymous session identifier — a random identifier generated in your browser to keep your seat in a room. It is not linked to your real identity.
  • Room content— the room name, your estimates and votes, agenda and topic titles, your role (estimator or viewer), and the room password if a host sets one. Room passwords are stored as plain text so hosts can view and share them, so don’t reuse a password from anywhere else.
  • Topic links — if you paste a link as a topic name, our server requests that page once to read its title, so the topic gets a friendly name. The site you linked sees that request coming from our servers, not from your browser, and we store only the link and the title.

Usage statistics

To understand whether the app is used and which parts of it are worth keeping, we record anonymous counts of what happens in a room: that a room was created, that a session started, how many people were in it, how many topics were planned, which built-in settings were changed, and how a session ended.

These records describe rooms, not people. They contain no display names, no session identifiers, no room names, and no topic titles or links. Estimates are recorded only as anonymous positions in the deck (for example “the third card”), as a count of how many people picked each position. They are never tied to a person, and never stored next to what was being estimated, so they can’t reveal anything about your work.

If your team builds a custom deck, we record its card labels only when every one of them is a plain number (like 1 or 0.5) or a standard size (XS through XXL), which tells us whether we should offer a preset for it. If any card is something you wrote yourself, we store only how many cards the deck had and nothing else about it.

We keep these detailed records for 12 months. A small summary of each room (its size, how many topics it covered, how long it lasted) is kept longer so we can see how usage changes over time.

When we read these numbers, we keep a copy on the machine doing the reading so we can chart the long run without downloading everything again each time. That copy holds the same anonymous records described above, and it can outlive the 12 months, because a trend is only visible if the older points are still there.

Data stored in your browser

We store a small amount of data in your browser’s local storage so you can rejoin a room without re-entering your details:

  • sprintcards:sessionId — your anonymous session identifier.
  • sprintcards:room:<code> — your name and role for a room you joined.
  • sprintcards:recentRooms — the codes and names of the last few rooms you joined, so the join screen can offer a quick way back in.
  • sprintcards:customDeck — the last custom estimation deck you defined, so a new room can offer it again without you retyping the values.

These entries are strictly necessary or functional. They exist only to run the app and remember your details on this device. We don’t use them for tracking or advertising, and we set no third-party or advertising cookies. You can clear them at any time through your browser settings.

Service providers

We use the following processors to run the service:

  • Convex — provides the backend and database that store the room data described above. Data is hosted in the European Union.
  • Vercel — hosts the application and processes server logs, which may include your IP address and browser user-agent, for operating and securing the service.
  • Vercel Web Analytics— counts page views and records which site referred you, so we can tell whether anyone is finding the app. It sets no cookies and no identifier that could follow you across sites or visits. Room addresses are hidden from it: because a room address is built from the name the host chose, a visit to a room is reported only as “a room page”, never as the address itself. Vercel processes this data outside the EU under its standard data protection terms. The usage statistics described above stay on our own servers in the EU and are not sent to Vercel.

Fonts are served from our own domain (bundled at build time), so no request is made to Google Fonts. We use no advertising and no third-party tracking, and we set no cookies at all.

Legal bases

We process the data above on the basis of Art. 6(1)(b) GDPR (performing the service you request) and Art. 6(1)(f) GDPR (our legitimate interest in operating, securing, and improving the service, e.g. server logs and the anonymous usage statistics described above).

How long we keep it

Rooms are ephemeral. A room and all its data — participants, estimates, and agenda — are automatically deleted after about four hours of inactivity. Hosts can also delete a room immediately when finishing a session, which removes the same data right away. Data stored in your browser persists until you clear it. The anonymous usage statistics described above outlive the room, on the schedule set out in that section, because they no longer describe anyone.

Your rights

You have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and the right to data portability. You may also lodge a complaint with a supervisory authority. To exercise any of these rights, contact hello@tobiashorak.com.

Changes to this policy

We may update this policy as the service evolves. The effective date at the top reflects the current version.