Home / Privacy
Privacy policy
PointHuddle is built to need as little about you as possible. There are no accounts, and nobody is asked for an email address.
Last updated 10 October 2026.
Rooms
- What: the room name and settings, the display names people type, their votes and confidence, the stories (titles, descriptions, estimates, notes, actuals) and the round history.
- Why: to run the planning poker session and show its history and export to the people in the room.
- How long: a room and everything in it is deleted automatically 7, 30 or 90 days after its last activity, as the host chooses. The host can delete it at any time.
- Room passwords are stored only as an argon2id hash. Slack and Teams webhook URLs are stored encrypted and are never shown again.
Your browser
PointHuddle keeps your display name, your session for each room and a few preferences (theme, sound) in your browser’s local storage. It uses no tracking or advertising cookies. Installing the Slack app sets one short-lived, security-only cookie that ties the install to your browser.
Slack app
- What: your workspace’s Slack id and name, the app’s bot id, the Slack id of the person who installed it, the bot token (encrypted) and, for each room started from Slack, the channel id to post to.
- Why: to start rooms from /pointhuddle and post accepted estimates to that channel. The app never reads messages or looks up anyone’s profile or email address, and never posts voter names.
- How long: until the app is uninstalled or its token is revoked; then it is deleted straight away.
Jira app
- What: for issues you choose, the issue key, summary and link; your Jira site address, cloud id and installation id; and which story belongs to which issue.
- Why: to create rooms from issues and show the estimate back in Jira. Atlassian account ids are not stored.
- How long: until the app is uninstalled; then the installation and its issue links are deleted straight away. Rooms follow the retention above.
Usage statistics
We count events such as “room created” or “round revealed” to understand how PointHuddle is used. They are tied to random room and participant ids, never to names or story text, and are deleted after 180 days.
Page visits
We count page visits with Umami, an open-source analytics tool that runs on our own server, so nothing goes to a third party. It sets no cookies, respects your browser’s Do Not Track setting and doesn’t store IP addresses. We see which page was visited, the site you came from, your browser type and country. Room links are recorded without the room code, and invite links without their tokens.
Server logs
Like any website, our server records each request’s path, status and IP address to keep the service running and secure. Tokens, passwords and query strings are not logged. Logs are rotated automatically: older entries are overwritten and nothing is archived.
Where it is hosted and who else is involved
- PointHuddle runs on a single server run by PointHuddle.
- Cloudflare carries all traffic to pointhuddle.com.
- Slack and Atlassian receive what you send through their apps, and the messages PointHuddle posts there.
We don’t sell or share data with anyone else.
Your choices
Delete a room from its settings, uninstall the Slack or Jira app, or ask us to delete something by writing to [email protected].