SprintCards

Privacy Policy

Effective date: 7 July 2026

Who is responsible

The controller responsible for processing your data under the GDPR is:

Tobias Horak
Email: hello@tobiashorak.com

What we process and why

SprintCards is a real-time planning-poker tool. To let you create and join estimation rooms, we process:

  • Display name — the name you type when you create or join a room, shown to others in that room.
  • Anonymous session identifier — a random identifier generated in your browser to keep your seat in a room. It is not linked to your real identity.
  • Room content— the room name, your estimates and votes, agenda and topic titles, your role (estimator or viewer), and the room password if a host sets one. Room passwords are stored as plain text so hosts can view and share them, so don’t reuse a password from anywhere else.
  • Topic links — if you paste a link as a topic name, our server requests that page once to read its title, so the topic gets a friendly name. The site you linked sees that request coming from our servers, not from your browser, and we store only the link and the title.

Data stored in your browser

We store a small amount of data in your browser’s local storage so you can rejoin a room without re-entering your details:

  • sprintcards:sessionId — your anonymous session identifier.
  • sprintcards:room:<code> — your name and role for a room you joined.
  • sprintcards:recentRooms — the codes and names of the last few rooms you joined, so the join screen can offer a quick way back in.
  • sprintcards:customDeck — the last custom estimation deck you defined, so a new room can offer it again without you retyping the values.

These entries are strictly necessary or functional. They exist only to run the app and remember your details on this device. We don’t use them for tracking or advertising, and we set no third-party or advertising cookies. You can clear them at any time through your browser settings.

Service providers

We use the following processors to run the service:

  • Convex — provides the backend and database that store the room data described above. Data is hosted in the European Union.
  • Vercel — hosts the application and processes server logs, which may include your IP address and browser user-agent, for operating and securing the service.

Fonts are served from our own domain (bundled at build time), so no request is made to Google Fonts. We use no analytics, advertising, or third-party tracking.

Legal bases

We process the data above on the basis of Art. 6(1)(b) GDPR (performing the service you request) and Art. 6(1)(f) GDPR (our legitimate interest in operating and securing the service, e.g. server logs).

How long we keep it

Rooms are ephemeral. A room and all its data — participants, estimates, and agenda — are automatically deleted after about four hours of inactivity. Hosts can also delete a room immediately when finishing a session, which removes the same data right away. Data stored in your browser persists until you clear it.

Your rights

You have the right to access, rectify, erase, restrict, and object to the processing of your personal data, and the right to data portability. You may also lodge a complaint with a supervisory authority. To exercise any of these rights, contact hello@tobiashorak.com.

Changes to this policy

We may update this policy as the service evolves. The effective date at the top reflects the current version.