Home / Security
Security and data
PointHuddle is built to need as little data as possible. There are no accounts, so there are no passwords or email addresses of yours to leak.
What we store
- The rooms you create: room name, the display names people choose, stories, votes and settings.
- Nothing that identifies you beyond the display name you type. No email, no account, no profile.
- Full details are in the privacy policy.
How it is protected
- Room passwords are stored only as an argon2id hash. Nobody, including us, can read them back.
- Session links are random tokens kept in your browser; the server stores only a hash of each.
- Slack and Teams webhook URLs, Slack app tokens and Linear API keys are encrypted at rest (AES-256-GCM) and never shown again after you save them.
- One-time host links from the Slack and Jira apps work once, for 15 minutes.
- Traffic is HTTPS only (HSTS), with a strict content security policy: the site loads no third-party scripts.
- Abuse limits on creating and joining rooms and on password guesses, which lock out repeated wrong tries.
- Outgoing posts go only to Slack and Microsoft Teams webhook addresses, never to internal networks.
- The Slack and Jira apps verify every request Slack or Atlassian sends, and the Jira app writes story points as the person using it, so it can only change issues they can already edit. PointHuddle never holds a Jira token.
Where it runs and how long data lives
- PointHuddle runs on a single server in the United Kingdom, run by PointHuddle. Cloudflare carries the traffic.
- Rooms are deleted automatically 7, 30 or 90 days after their last activity, as the host chooses (30 by default). Hosts can delete a room any time.
- Usage statistics carry no names or story text and are deleted after 180 days. Page analytics are self-hosted, cookieless and respect Do Not Track.
- Server logs never contain tokens, passwords or query strings, and they are rotated, not archived.
Certifications
PointHuddle has no ISO 27001 or SOC 2 certification. If your organisation needs a security questionnaire answered, write to us.
Reporting a vulnerability
Please email [email protected] rather than posting publicly. We reply within two business days.