Privacy policy
ProductOwner runs on your own server. This page explains the little we collect, and what happens to the data your team puts in the app.
Who is responsible
LotfyTech LLC, Charles Town, West Virginia, USA. Questions: privacy@productownerapp.com.
Data in the app
Work items, comments, files, meeting recordings, names and email addresses of the people you invite are stored in your own database, on your server. Your organisation decides who can see them and how long to keep them. We have no access to them. For requests about that data (for example, to delete a person's information), contact the organisation that runs the install; admins can remove people in Settings → Team.
Services you choose to connect
When your admins connect them, your server sends data directly to:
- your code host (GitHub, GitLab or Azure DevOps) for branches and pull requests;
- your email server, to send invitations, password resets and notifications;
- your company sign-in provider (Microsoft, Google, Okta or another OpenID provider);
- Anthropic, only if you add an API key for the PO agent: the text of the stories and meeting notes it works on.
Those services handle the data under your agreements with them. Nothing goes through us.
Phone apps
The ProductOwner apps for iPhone and Android connect to your organisation's server, the same as the web app. The app keeps your sign-in and the server's address on the phone; it has no tracking or analytics.
Phone notifications can only be delivered through Apple and Google, so your server sends them through our push service, which passes them on and keeps nothing. Each notification carries the phone's notification address (a random code Apple or Google gives the app), which item to open when it's tapped (for example US-164), and by default only a general text: “Something new needs a look”. If your admins turn on notification details, it carries the notification's title and a short summary instead. Our push service sees them for the moment it takes to pass them on and doesn't store them; it counts notifications per install to apply daily limits. Apple and Google deliver them under their own privacy policies. The organisation running the install can turn phone notifications off completely, and anyone can turn them off on their phone.
What we collect
- Licence requests: your company name, the number of people, your install's address, and the name and email of the person asking. We use them to make your licence and invoice, and keep them for as long as the law requires for accounting.
- Support emails: what you write to us, to answer you.
- This website: no cookies and no analytics. The fonts load from Google Fonts, which sees your IP address as with any website. Our hosting provider keeps standard server logs for security.
We don't sell personal data or use it for advertising.
Your rights
You can ask us for a copy of the personal data we hold about you, to correct it or to delete it, by writing to privacy@productownerapp.com. We answer within 30 days.
Changes
If this policy changes, the date at the top changes too.