Legal

Privacy Policy

Effective September 13, 2026 · Version 2.0

The short version. Driftless stores your account email, a ledger of your runs, and the Journal entries and team profiles you choose to save. When you run a tool, the board content in your tab is sent to Driftless's server and on to Anthropic for that one analysis, and is not retained afterward. Nothing you send is used to train AI models. We don't sell data, and we don't run ads. Email eric@bedriftless.com to delete your account.

1. Who we are

Driftless is operated by Eric Reighard ("we," "us," "our"), a sole proprietorship in Pennsylvania, United States. This policy covers the Driftless Chrome extension, the website at bedriftless.com, the dashboard, and related services (together, the "Service").

Questions: eric@bedriftless.com.

2. What we collect

2.1 What you give us

DataWhenWhy
Email addressSign-in (we email you a 6-digit code), purchaseYour account identity, sign-in codes, receipts
Team profilesWhen you create one in the extensionCoaching context: team name, sprint length, maturity level, recurring challenges. Synced to your account
Journal and Memory entriesWhen you save a tool output or a noteCoaching continuity across sprints. Synced to your account
Contact form contentWhen you use the form on this siteAnswering you

There are no passwords. Sign-in is your email plus a one-time code.

2.2 What the Service records on its own

DataSourceWhy
Run ledger (tool id, timestamp, account)Every tool run and follow-upYour run balance, purchase credits, abuse prevention. A failed run is not recorded as a charge
Terms acceptance timestamp and versionAccount creationLegal record
Standard server logs (IP address, user agent, request path)Website and API hostingSecurity and debugging; rotated by the hosting providers

3. Your board data

When you run a tool on a Jira or Rally board, the extension reads the visible work on that page: ticket ids, titles, status columns, assignee names or initials, point values, labels, sprint name and Sprint Goal. That content is:

  • sent to Driftless's server (hosted on Railway), which forwards it to Anthropic to generate the coaching output for that run;
  • not retained by Driftless after the analysis completes;
  • not used to train AI models, by Driftless or by Anthropic under its API terms;
  • present in abbreviated form only where you save an output to the Journal (a saved output may name ticket ids and the sprint).

Assignee names on your board are names of real people on your team. They are processed only to give the coaching output its context. Driftless is designed to support coaching, not to rank or monitor individuals, and you agree in the Terms not to use outputs for employment or disciplinary decisions without your own professional judgment.

Demo Mode uses Driftless's own mock boards and pre-generated outputs. It sends nothing anywhere and uses no runs.

4. How we use it

  • Running the Service: generating coaching output, keeping your run balance, syncing your Journal and team profiles to the account you sign in with.
  • Account email: sign-in codes, receipts, and service notices such as a change to these terms. We don't send marketing email.
  • Product improvement: which tools are used, where runs fail. Aggregate counts, not board content.
  • Legal: keeping the record of Terms acceptance and responding to lawful requests.

We do not sell your data. We do not use your data to train AI models. We do not share it with advertisers.

5. Who processes it

Driftless runs on a small set of providers. Each handles only what its job needs.

ProviderRoleWhat it sees
AnthropicAI analysisBoard content and the coaching prompt for each run. Not retained for training under Anthropic's API terms
SupabaseDatabase and sign-in codesAccount email, run ledger, synced Journal and team profiles
StripePaymentsYour card details, which Driftless never sees, and the email on the receipt
ResendTransactional emailYour email address and the content of sign-in code and receipt emails
RailwayServer hostingAPI traffic between the extension, Driftless, and Anthropic
NetlifyWebsite hostingStandard web server logs for bedriftless.com
FormspreeContact form deliveryWhat you type into the contact form, including your email

We may also disclose information when required by law, or to protect the rights, property, or safety of Driftless, its users, or the public.

6. Storage, security, retention

6.1 Where

  • Supabase database: United States (AWS us-east-1).
  • Driftless server on Railway: United States.
  • Anthropic processing: United States.
  • Chrome extension storage on your device: your sign-in session, a local copy of your team profiles and Journal, and your settings.

6.2 Security

  • All traffic is encrypted in transit (TLS 1.2 or higher).
  • Sign-in is a one-time emailed code; there is no password to leak.
  • Row-level security on every database table, so an account can read only its own rows.
  • Every run is authenticated by your signed-in session. Secrets live in server environment variables, never in the extension.

6.3 Retention

DataKept
Board content sent for a runNot retained after the analysis
Account email and run ledgerUntil you delete your account, plus up to 30 days for backups
Journal, Memory, team profiles (synced)Until you delete them or your account
Local copies in the extensionUntil you uninstall the extension or clear its storage
Terms acceptance recordRetained as a legal record
Contact form messagesKept in email as long as the conversation is useful

If you stop using Driftless, your history and remaining runs stay on your account. Email us to delete them.

7. Your rights and choices

  • Access and correction. Your run balance and history are on the dashboard. For anything else, email us.
  • Deletion. Email eric@bedriftless.com from the address you sign in with. We process deletion within 30 days, subject to the legal record above. Unused runs on a deleted account are forfeited unless refunded first (see the Terms).
  • Email. The only email we send is transactional: sign-in codes, receipts, and service notices. There is no marketing list to unsubscribe from.
  • Local data. Uninstalling the extension or clearing its storage in Chrome removes everything it kept on your device.
  • California residents. You have the right to know what personal information we hold, to have it deleted, and to opt out of sale. We do not sell personal information. Email us to exercise these rights.
  • EEA and UK residents. Our basis for processing is performance of the contract you enter by using the Service, and our legitimate interest in running it securely. You have the rights of access, rectification, erasure, restriction, portability, and objection. Email us; you may also complain to your local supervisory authority.

8. Cookies and tracking

The website sets no advertising cookies and uses no third-party analytics or tracking pixels. The dashboard keeps your signed-in session in your browser's local storage. The extension keeps its data in Chrome's extension storage, which websites cannot read.

9. Children

The Service is for working professionals and is not directed to anyone under 18. If we learn we hold information from a minor, we delete it. Email us if you believe that has happened.

10. International users

The Service is operated from the United States and your information is processed there. By using it from elsewhere you consent to that transfer.

11. Changes to this policy

When we make a material change we update the effective date above and email the address on your account. Continued use after that date is acceptance of the updated policy.

12. Contact

Driftless · Eric Reighard
Email: eric@bedriftless.com
Web: bedriftless.com