Legal

Privacy Policy

Effective Date: March 27, 2026  ·  Version 1.0

The short version: We collect what we need to run the product — your email, license key, and usage metadata. We do not sell your data. Board data from your agile tools is processed for coaching and not stored. You can delete your account anytime.

1. Who We Are

Driftless is operated by Eric Reighard ("we," "us," or "our"), a sole proprietorship based in Pennsylvania, United States. This Privacy Policy describes how we collect, use, and protect information when you use the Driftless Chrome extension, website at bedriftless.com, and related services (the "Service").

Questions? Contact us at eric@bedriftless.com.

2. Information We Collect

2.1 Information You Provide Directly

DataWhen CollectedWhy
First and last nameAccount creationDashboard personalization
Email addressAccount creation, beta signupAccount management, license delivery, notifications
Password (hashed)Account creationAuthentication — never stored in plain text
License keyGenerated on purchase/signupAccess control and usage tracking
Anthropic API keyOptional, entered in SettingsStored locally in Chrome storage only — never transmitted to Driftless servers
Team profile dataOnboarding and SettingsAI coaching context — team name, sprint length, maturity level, recurring challenges
Feedback form contentWhen you submit feedbackProduct improvement

2.2 Information Collected Automatically

DataSourceWhy
Tool run logs (tool ID, timestamp, license key)Every AI tool runUsage analytics, daily throttle enforcement, billing
Coaching journal entriesAuto-saved after tool runs (user-initiated)Sprint memory and coaching continuity
Sprint Health Prediction scoresWhen prediction is runCoaching history on dashboard
ToS acceptance timestamp and versionAccount creationLegal compliance

2.3 Sprint Board Data

When you open a sprint board in Jira, Rally, or another supported tool, the extension reads the visible content of that page — including ticket IDs, titles, statuses, assignee names, point values, sprint name, and sprint goal. This data is:

Assignee names from your board are sent to Anthropic as part of the coaching analysis. These are real names of real people on your team. We process them solely to provide coaching context.

3. How We Use Your Information

We do not sell your data. We do not use your data to train AI models. We do not share your data with advertisers.

4. How We Share Your Information

We share data only with the service providers necessary to operate the product:

ProviderPurposeData SharedPrivacy Policy
AnthropicAI coaching analysisBoard data, coaching prompts (not stored per Anthropic API policy)anthropic.com/legal/privacy
SupabaseDatabase and authenticationAccount data, license keys, usage logs, journal entriessupabase.com/privacy
StripePayment processingPayment information (Stripe handles directly — we never see card numbers)stripe.com/privacy
RailwayServer hostingAPI request data passes through Railway infrastructurerailway.app/legal/privacy
NetlifyWebsite hostingWeb traffic (standard server logs)netlify.com/privacy
ResendTransactional emailEmail address, email content for license/notification emailsresend.com/privacy
FormspreeFeedback form processingFeedback content and email address (if provided)formspree.io/legal/privacy-policy
ImprovMXEmail forwardingEmails sent to eric@bedriftless.com pass through ImprovMXimprovmx.com/privacy

We may also disclose information if required by law, court order, or to protect the rights, property, or safety of Driftless, its users, or the public.

5. Data Storage and Security

5.1 Where Data Is Stored

5.2 Security Measures

5.3 Data Retention

Data TypeRetention
Account informationUntil account deletion + 30 days
Usage logsDuration of active subscription
Journal entries (synced)Duration of active subscription
Journal entries (local)Until browser data cleared or extension uninstalled
Sprint board dataNot retained — processed in memory only
ToS acceptance recordsRetained indefinitely for legal compliance

6. Your Rights and Choices

6.1 Access and Correction

You can view and update your account information at bedriftless.com/dashboard. For data not accessible through the dashboard, contact eric@bedriftless.com.

6.2 Deletion

You can request deletion of your account and associated data by emailing eric@bedriftless.com. We will process deletion requests within 30 days, subject to legal retention requirements. Note that ToS acceptance records are retained for legal compliance and cannot be deleted.

6.3 Unsubscribing from Email

You can unsubscribe from non-essential emails by replying to any email with "unsubscribe" or contacting us directly. Note that transactional emails (license keys, billing notifications) cannot be opted out of while your account is active.

6.4 Local Data

Data stored in Chrome local storage (team profiles, journal, settings) can be cleared at any time by uninstalling the extension or clearing Chrome storage in DevTools.

6.5 California Residents

If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete it, and the right to opt out of sale (we do not sell personal information). To exercise these rights, contact eric@bedriftless.com.

7. Cookies and Tracking

The Driftless website uses minimal tracking. We do not use advertising cookies or third-party tracking pixels. Supabase authentication uses session tokens stored in localStorage. We do not use Google Analytics or similar analytics platforms on the core product.

The Chrome extension does not use cookies. It stores data in chrome.storage.local, which is sandboxed to the extension and not accessible by websites.

8. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have collected information from a minor, we will delete it promptly. Contact eric@bedriftless.com if you believe we have information from a minor.

9. International Users

The Service is operated from the United States. If you access the Service from outside the US, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer. If you are located in the European Economic Area (EEA) or UK and have questions about our legal basis for processing, contact us at eric@bedriftless.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top and notify you by email. Continued use of the Service after the effective date constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, your data, or your rights, contact us at:

Driftless
Eric Reighard
Email: eric@bedriftless.com
Website: bedriftless.com