Privacy Policy
Last updated: July 13, 2026
This policy explains what data the ProdPush cloud service collects, why, and the choices you have. The short version: we collect what's needed to run the product, we don't sell your data, and your workspace content belongs to you.
1. Scope
This policy applies to the hosted ProdPush service at prodpush.app and its subdomains, and to this website. It does not apply to self-hosted deployments of the open-source ProdPush software — in that case the operator of that deployment is responsible for its own privacy practices.
2. Data we collect
Account data
- Name, email address, and a hashed password (we never store plaintext passwords), plus an optional avatar.
- Workspace and membership details: organization names, roles, invitations you send or receive.
Workspace content
- The material you and your team create in the product: issues, comments, projects, documents, attachments, and related metadata. This content is private to your workspace.
Usage and technical data
- Server logs (IP address, timestamps, request paths) kept for security and debugging.
- Activity records inside your workspace (who changed what, when) — a product feature your team can see.
- Device push-notification tokens, if you enable notifications in the mobile app.
Cookies
We use strictly necessary cookies for authentication and security (session tokens, CSRF protection). We do not use advertising cookies or sell data to advertisers.
3. How we use data
- To provide, secure, and maintain the Service (contractual necessity).
- To send transactional email such as invitations, password resets, alerts, and digests you've enabled.
- To power features you use — including AI features, which process relevant workspace content to generate answers, summaries, or automations.
- To debug problems, prevent abuse, and improve the product (legitimate interest).
We do not sell personal data, and we do not use your workspace content to train AI models.
4. Service providers
We share data with a small set of processors, only as needed to run the Service:
- Cloud hosting providers — application and database hosting.
- Resend — transactional email delivery.
- Expo & Google Firebase Cloud Messaging — mobile push-notification delivery.
- AI model providers — process the specific content involved in an AI request when you use AI features.
Each provider receives only the data required for its function. We may disclose data if required by law or to protect the rights, safety, or security of ProdPush or its users.
5. Data retention and deletion
We keep your data while your account is active. When you delete content, it is removed from the live product; residual copies may persist in backups for a limited period before being purged. You can request deletion of your account and associated personal data by emailing [email protected]; we will complete verified requests within 30 days, except where retention is required by law.
6. Security
We use industry-standard measures: encrypted transport (HTTPS), hashed passwords, httpOnly authentication cookies, tenant isolation between workspaces, and role-based access control. No system is perfectly secure — if we learn of a breach affecting your personal data, we will notify affected users without undue delay.
7. Your rights
Depending on where you live (including under the GDPR and India's DPDP Act), you may have rights to access, correct, export, restrict the processing of, or delete your personal data, and to object to certain processing. To exercise any of these, contact [email protected]. If you are a member of a workspace, some requests may need to be routed through your workspace owner, who controls that workspace's content.
8. International transfers
Our infrastructure and service providers may store or process data in countries other than your own. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.
10. Changes
We may update this policy as the product evolves. Material changes will be announced by email or in-app notice, and the "Last updated" date above always reflects the current version.
11. Contact
Privacy questions or requests: [email protected]