Privacy Policy
1. Who we are
Driftless is operated by Eric Reighard ("we," "us," "our"), a sole proprietorship in Pennsylvania, United States. This policy covers the Driftless Chrome extension, the website at bedriftless.com, the dashboard, and related services (together, the "Service").
Questions: eric@bedriftless.com.
2. What we collect
2.1 What you give us
| Data | When | Why |
|---|---|---|
| Email address | Sign-in (we email you a 6-digit code), purchase | Your account identity, sign-in codes, receipts |
| Team profiles | When you create one in the extension | Coaching context: team name, sprint length, maturity level, recurring challenges. Synced to your account |
| Journal and Memory entries | When you save a tool output or a note | Coaching continuity across sprints. Synced to your account |
| Contact form content | When you use the form on this site | Answering you |
There are no passwords. Sign-in is your email plus a one-time code.
2.2 What the Service records on its own
| Data | Source | Why |
|---|---|---|
| Run ledger (tool id, timestamp, account) | Every tool run and follow-up | Your run balance, purchase credits, abuse prevention. A failed run is not recorded as a charge |
| Terms acceptance timestamp and version | Account creation | Legal record |
| Standard server logs (IP address, user agent, request path) | Website and API hosting | Security and debugging; rotated by the hosting providers |
3. Your board data
When you run a tool on a Jira or Rally board, the extension reads the visible work on that page: ticket ids, titles, status columns, assignee names or initials, point values, labels, sprint name and Sprint Goal. That content is:
- sent to Driftless's server (hosted on Railway), which forwards it to Anthropic to generate the coaching output for that run;
- not retained by Driftless after the analysis completes;
- not used to train AI models, by Driftless or by Anthropic under its API terms;
- present in abbreviated form only where you save an output to the Journal (a saved output may name ticket ids and the sprint).
Assignee names on your board are names of real people on your team. They are processed only to give the coaching output its context. Driftless is designed to support coaching, not to rank or monitor individuals, and you agree in the Terms not to use outputs for employment or disciplinary decisions without your own professional judgment.
Demo Mode uses Driftless's own mock boards and pre-generated outputs. It sends nothing anywhere and uses no runs.
4. How we use it
- Running the Service: generating coaching output, keeping your run balance, syncing your Journal and team profiles to the account you sign in with.
- Account email: sign-in codes, receipts, and service notices such as a change to these terms. We don't send marketing email.
- Product improvement: which tools are used, where runs fail. Aggregate counts, not board content.
- Legal: keeping the record of Terms acceptance and responding to lawful requests.
We do not sell your data. We do not use your data to train AI models. We do not share it with advertisers.
5. Who processes it
Driftless runs on a small set of providers. Each handles only what its job needs.
| Provider | Role | What it sees |
|---|---|---|
| Anthropic | AI analysis | Board content and the coaching prompt for each run. Not retained for training under Anthropic's API terms |
| Supabase | Database and sign-in codes | Account email, run ledger, synced Journal and team profiles |
| Stripe | Payments | Your card details, which Driftless never sees, and the email on the receipt |
| Resend | Transactional email | Your email address and the content of sign-in code and receipt emails |
| Railway | Server hosting | API traffic between the extension, Driftless, and Anthropic |
| Netlify | Website hosting | Standard web server logs for bedriftless.com |
| Formspree | Contact form delivery | What you type into the contact form, including your email |
We may also disclose information when required by law, or to protect the rights, property, or safety of Driftless, its users, or the public.
6. Storage, security, retention
6.1 Where
- Supabase database: United States (AWS us-east-1).
- Driftless server on Railway: United States.
- Anthropic processing: United States.
- Chrome extension storage on your device: your sign-in session, a local copy of your team profiles and Journal, and your settings.
6.2 Security
- All traffic is encrypted in transit (TLS 1.2 or higher).
- Sign-in is a one-time emailed code; there is no password to leak.
- Row-level security on every database table, so an account can read only its own rows.
- Every run is authenticated by your signed-in session. Secrets live in server environment variables, never in the extension.
6.3 Retention
| Data | Kept |
|---|---|
| Board content sent for a run | Not retained after the analysis |
| Account email and run ledger | Until you delete your account, plus up to 30 days for backups |
| Journal, Memory, team profiles (synced) | Until you delete them or your account |
| Local copies in the extension | Until you uninstall the extension or clear its storage |
| Terms acceptance record | Retained as a legal record |
| Contact form messages | Kept in email as long as the conversation is useful |
If you stop using Driftless, your history and remaining runs stay on your account. Email us to delete them.
7. Your rights and choices
- Access and correction. Your run balance and history are on the dashboard. For anything else, email us.
- Deletion. Email eric@bedriftless.com from the address you sign in with. We process deletion within 30 days, subject to the legal record above. Unused runs on a deleted account are forfeited unless refunded first (see the Terms).
- Email. The only email we send is transactional: sign-in codes, receipts, and service notices. There is no marketing list to unsubscribe from.
- Local data. Uninstalling the extension or clearing its storage in Chrome removes everything it kept on your device.
- California residents. You have the right to know what personal information we hold, to have it deleted, and to opt out of sale. We do not sell personal information. Email us to exercise these rights.
- EEA and UK residents. Our basis for processing is performance of the contract you enter by using the Service, and our legitimate interest in running it securely. You have the rights of access, rectification, erasure, restriction, portability, and objection. Email us; you may also complain to your local supervisory authority.
8. Cookies and tracking
The website sets no advertising cookies and uses no third-party analytics or tracking pixels. The dashboard keeps your signed-in session in your browser's local storage. The extension keeps its data in Chrome's extension storage, which websites cannot read.
9. Children
The Service is for working professionals and is not directed to anyone under 18. If we learn we hold information from a minor, we delete it. Email us if you believe that has happened.
10. International users
The Service is operated from the United States and your information is processed there. By using it from elsewhere you consent to that transfer.
11. Changes to this policy
When we make a material change we update the effective date above and email the address on your account. Continued use after that date is acceptance of the updated policy.
12. Contact
Driftless · Eric Reighard
Email: eric@bedriftless.com
Web: bedriftless.com