Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your information.

Effective: January 22, 2025Last Updated: January 22, 2025

Introduction

IssueFlow AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service, including our website, Slack integration, and any related services (collectively, the "Service").

By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this policy, please do not access the Service.

Information We Collect

Account Information

  • Email address and name (via Slack OAuth or direct registration)
  • Organization name and details
  • Billing information (processed securely through Stripe)

Slack Integration Data

  • Slack workspace information (team ID, team name)
  • Messages in conversations where the bot is mentioned
  • User IDs of participants in processed conversations
  • OAuth tokens for Slack API access (encrypted)

GitHub Integration Data

  • Repository information and access permissions
  • Issues created through our Service
  • OAuth tokens for GitHub API access (encrypted)

Usage Data

  • Number of issues created and AI credits used
  • Feature usage patterns and preferences
  • Error logs and performance metrics

How We Use Your Information

We use the collected information for the following purposes:

  • Provide Service: Process Slack conversations, generate issue summaries, and create GitHub issues
  • Account Management: Manage your account, billing, and subscription
  • Communication: Send service updates, security alerts, and support messages
  • Improvement: Analyze usage patterns to improve our Service and develop new features
  • Security: Detect, prevent, and address technical issues and abuse
  • Legal Compliance: Comply with legal obligations and enforce our terms

AI and Data Processing

We use OpenAI's GPT models to process Slack conversations and generate issue summaries. Here's what you should know:

  • Conversation data is sent to OpenAI only when you explicitly trigger the bot
  • We do not use your data to train AI models
  • OpenAI processes data according to their API data usage policies
  • Generated summaries are stored in our database for your reference
  • You retain full control and can delete your data at any time

Data Security

We implement industry-standard security measures to protect your information:

  • All OAuth tokens are encrypted using AES-256-GCM encryption
  • Data transmission is protected with TLS/SSL encryption
  • Database access is restricted with Row Level Security (RLS)
  • Regular security audits and vulnerability assessments
  • Secure infrastructure hosted on Vercel and Supabase
  • Payment processing handled by PCI-compliant Stripe

Data Sharing and Third Parties

We do not sell, trade, or rent your personal information. We may share your information only in these circumstances:

  • Service Providers: With trusted third parties who assist in operating our Service (OpenAI, Stripe, Supabase)
  • Legal Requirements: When required by law or to respond to legal process
  • Business Transfers: In connection with a merger, acquisition, or sale of assets
  • Consent: With your explicit consent for specific purposes

Data Retention

We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:

  • Account data is retained while your account is active
  • Conversation summaries and issues are retained for your reference
  • Audit logs are retained for 90 days for security purposes
  • Deleted data is removed from our active databases within 30 days
  • Backups may retain data for up to 90 days after deletion

Your Rights and Choices

You have the following rights regarding your information:

  • Access: Request a copy of your personal information
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a machine-readable format
  • Opt-out: Unsubscribe from marketing communications
  • Revoke Access: Disconnect Slack or GitHub integrations at any time

To exercise these rights, please contact us at privacy@issueflow.ai

International Data Transfers

Our Service is operated from the United States. If you are located outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

By using our Service, you consent to the transfer of your information to these countries, which may have different data protection laws than your country of residence.

California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information we collect, use, and disclose
  • Right to delete your personal information (with some exceptions)
  • Right to opt-out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

Children's Privacy

Our Service is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last Updated" date at the top of this policy
  • Sending an email notification for material changes

Your continued use of the Service after any changes indicates your acceptance of the updated policy.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@issueflow.ai

Support: support@issueflow.ai

Website: https://issueflow.ai

For data protection inquiries or to exercise your privacy rights, please include "Privacy Request" in the subject line of your email. We aim to respond to all privacy-related requests within 30 days.

© 2025 IssueFlow AI. All rights reserved.