Privacy Policy
What personal data we hold, why, and what you can ask us to do with it.
Who is responsible for your data
In this policy “we” means whoever operates this installation of Open Backlog — the organisation that put it online and holds the account you are signing in to. They are the people to go to for anything this policy says to raise with us, and if you reached the service through your employer, they are your employer.
The service is built to United Kingdom data protection standards, and this policy describes what it actually does with your data — which is the same wherever it is run from.
Which party is legally responsible for your data depends on how you signed in:
- If you signed in with a personal account, we are the controller of your data and this policy describes what we do with it.
- If you signed in through your employer or another organisation, that organisation is the controller. We process the data on its instructions, as its processor, under the terms at Data Processing Terms. Its own privacy notice governs, and questions about your data are best directed to it. This policy still tells you accurately what we do.
What we collect
Only what the service needs to work:
- Account data. A username, which we generate for you — you are never asked for your real name. For a personal account, the identifiers needed to recognise the sign-in credential you created on your device.
- Corporate sign-in data. If you sign in through your organisation: the domain part of the address you type, an identifier for you supplied by your organisation’s sign-in system, and any name or email address that system chooses to send us. When you type a full email address, only the part after the @ leaves your browser.
- What you create. The backlogs, items, notes and comments you add, and a record of who changed what and when, which is a feature of the service rather than a by-product.
- Operational data. Network address, approximate location derived from it, timestamps, and error and security records generated when your device talks to ours. We use these to keep the service running and to detect abuse.
- Verification data. If you verify that you work somewhere by sending an email, the address you sent it from and the technical results of checking it.
Some information is also kept on your own device to make signing in quicker — the username or work address you last used, and your colour-scheme choice. It stays on your device and clearing your browser data removes it.
What we do not do
- We do not ask you for, or store, a password.
- We do not sell or rent personal data, and we do not share it for advertising.
- We do not track you across other websites, and we run no advertising or analytics products.
- We do not make decisions about you by automated means, and we do not profile you.
- We do not ask for special category data (such as health, beliefs or biometrics). Where your device unlocks a sign-in credential with your face or fingerprint, that check happens on your device and we never receive it.
Why we are allowed to use it
Under UK data protection law we must have a lawful basis for each use. Ours are:
- To perform our contract with you — creating and running your account, storing what you create, and showing it to the people you share it with.
- Our legitimate interests — keeping the service secure and available, investigating abuse, and improving it. We use the least data that achieves this, and you can object (see below).
- Your consent — for anything optional, which today means only verifying where you work. You can withdraw it at any time.
- Legal obligation — where we are required to keep or disclose information.
Who else sees it
- Our infrastructure provider, Cloudflare, Inc., which hosts the service and stores its data on our behalf under terms that restrict it to that purpose.
- Your organisation, if you signed in through it. Its administrators can see the accounts in their organisation and export the content created within it. This is the point of a corporate account, and we tell you here because it may not be obvious.
- People you share with. Anything you put in a shared backlog is visible to the others in it.
- Authorities or advisers, where we are legally required to disclose, or need to establish or defend legal claims.
- A buyer or successor, if the service changes hands — on the same terms, and we will tell you first.
We do not add a new provider that handles personal data without updating the list at Data Processing Terms first.
Where it goes
The service runs on a global network, so your data may be handled outside the United Kingdom. Where it is, we rely on UK adequacy regulations for that country, or on the UK International Data Transfer Agreement (or the Addendum to the European Commission’s standard contractual clauses), together with an assessment of the protection actually available.
How long we keep it
- Account and content data: while your account exists. Delete your account and we remove it, along with the content only you could see.
- Content in a shared backlog: stays with the backlog, which belongs to the people still using it, unless they delete it too.
- Operational and security records: a short period, normally no more than 12 months.
- For a corporate account: for as long as your organisation instructs, and we return or delete it when its agreement with us ends.
Your rights
You have the right to a copy of your data, to have it corrected or deleted, to restrict or stop a particular use, and to have it handed to another provider. You can withdraw consent, and you can object to processing based on legitimate interests.
Most of it you can exercise yourself, without asking anyone, which is deliberate — a right you have to request is a right somebody can be slow about:
- A copy of your data — export any backlog, or the whole of a company’s content if you administer it, from the app at any time.
- Correction — your handle is yours to change on your profile, and everything you have written stays editable.
- Deletion — delete your account from your profile. It removes your credentials, your account and the content only you could see.
For anything you cannot do yourself, ask whoever operates this installation; a request must be answered within one month, free of charge, and you do not have to give a reason. If your account came from your employer, they are the controller and the request goes to them.
If it goes wrong you can complain to the Information Commissioner’s Office (ico.org.uk) or to the data protection authority where you live.
Security
We design the service so that a compromise of any one part gives up as little as possible: sign-in resists phishing by construction, data is encrypted in transit and at rest, each organisation’s data is separated from every other’s, and access to production is limited and recorded. There is more detail at Security. No service is immune, and if a breach affects your rights we will tell the regulator within 72 hours and you without undue delay.
Children
The service is not intended for children under 13, we do not knowingly create accounts for them, and an account found to belong to one is removed.
Changes
If this policy changes, the date at the foot of the page changes with it, and anything that materially affects you is announced in the app before it takes effect.
Last updated 29 July 2026.