Privacy Policy
TeamFlow draws a delivery map from reports about work, not from the work itself. This page says exactly what that means: what we hold, what a report can never carry, where it lives, who else touches it and what you can ask us to do with it.
Effective 17 September 2026 Last updated 17 September 2026 Applies to teamflow.macleodlabs.com and the TeamFlow service
1. Who is responsible
TeamFlow is made and operated by MacleodLabs, trading as [TO CONFIRM: registered legal entity name and company registration number], of [TO CONFIRM: registered address].
For your account and billing details, MacleodLabs is the controller: we decide what to hold and why. For the delivery reports your organisation sends us, your organisation decides what its people and agents report, and we hold it on their behalf as a processor. A written data processing agreement for organisations is [TO CONFIRM: whether a DPA is offered, and on what terms].
You can reach us about anything on this page at [TO CONFIRM: privacy contact email address].
2. What we collect and why
Account and organisation
When you sign up we hold your email address and your organisation name. The first person to sign up creates the organisation and becomes its owner. The organisation's domain is taken from the owner's email domain, and the organisation's icon is fetched from that domain when the organisation is displayed. We need this to give you an account, to tell one organisation's board from another's, and to email you about the service.
Sign-in identity
Sign-in runs through Amazon Cognito. You can sign in with a passkey, with a one-time code emailed to you, or through Google or GitHub. When you use Google or GitHub we receive only your email address and name from them, never your password and never any other part of your account there. A passkey's private key never leaves your device; we hold only the public credential needed to check a signature. We do not hold passwords.
Payment
Stripe takes and processes every payment. TeamFlow never sees or stores card numbers. We hold what Stripe tells us about the subscription: the Stripe customer and subscription identifiers, the plan, the billing period, whether the subscription is paid, and the credit allowance that follows from it.
Delivery reports
The TeamFlow plugin in your editor and the CI reporters write a small, fixed set of derived facts about an issue's current state. The published reporting contract is an allowlist: the service drops any field it does not recognise rather than storing it, and answers with a list of what it dropped. A report may carry only:
- the organisation's tenant identifier, and the tracker the issue lives in (Jira, Linear or GitHub);
- the issue key, its link and its short title and status, plus parent and related issue keys;
- the actor who did the work, the repository and the branch;
- the normalised stage and status, any rework origin and loop count;
- a concise derived summary of the state, capped at 180 characters;
- compact evidence counts and references, execution identifiers and kinds;
- timestamps.
We hold this because it is the map: it is what draws your board, your delivery rail and your activity feed.
Service logs and usage
Our servers keep ordinary operational logs: the time of a request, the route it hit, the response status, the size and duration, the account behind the credential, and the network address it came from. We use these to keep the service up, to find faults, to stop abuse and to count credits. One accepted report costs one credit; a repeated report whose content has not changed is recognised as the same report and is not counted again.
3. What we never collect
This is the part of the policy worth reading twice, because it is enforced by the service and not only promised here. A report is never allowed to persist:
- prompts or transcripts;
- source contents or diffs;
- raw shell commands or tool output;
- secrets;
- issue descriptions, comments or attachments;
- raw CI or test logs.
Because unknown fields are dropped rather than rejected, a reporter that is modified, or talked into attaching a prompt or a diff under a new name, still cannot make that content reach the store. We publish the full contract at docs/REPORTING_CONTRACT.md so you can check the rule rather than take our word for it.
We also run no analytics, no advertising, no tracking pixels and no third-party scripts on this website.
4. Where it is stored
TeamFlow's own data, including accounts, organisations and every delivery report, is stored on Amazon Web Services in the eu-west-1 region (Ireland).
Some of the companies listed below operate outside the United Kingdom and the European Economic Area, so payment and sign-in data may be processed elsewhere. The transfer safeguard we rely on for each of them is [TO CONFIRM: transfer mechanism relied on per processor, for example standard contractual clauses or the UK addendum].
5. Who processes it
We keep this list short on purpose. Every company here does one job for us and gets only what that job needs.
| Who | What they do | What they get |
|---|---|---|
| Amazon Web Services | Hosting, storage and the service itself, in eu-west-1 | Everything described in section 2 |
| Amazon Cognito | Sign-in and session tokens | Email address, name, passkey public credential |
| Amazon SES | Sends sign-in codes and service email | Email address and the message |
| Stripe | Takes payment and runs subscriptions | Email address, organisation name, payment details you give Stripe |
| Optional sign-in provider; serves the site's web fonts | Email address and name on sign-in; your network address when a font or an organisation icon is fetched | |
| GitHub | Optional sign-in provider; issues the CI identity token | Email address and name on sign-in; the workflow identity behind a CI report |
We do not sell personal data, we do not share it for advertising, and we do not use your reports to train machine learning models.
6. How long we keep it
- Account and organisation data is kept for as long as the organisation exists, and for 30 days after you ask us to delete it. After that it is removed from live systems.
- Delivery reports are kept until your organisation deletes them or until the organisation is archived. An organisation is archived when its last member leaves; its data stays readable to its administrators rather than being destroyed, so that a team that merges into another does not lose its history.
- Billing records are kept for as long as tax and accounting law requires, which is [TO CONFIRM: statutory retention period for billing records in the governing jurisdiction].
- Service logs are kept for [TO CONFIRM: log retention period] and then deleted.
Backups are overwritten on their own cycle, so a deleted record can survive in a backup for a short time after it leaves the live service.
7. Owners, members and your organisation
TeamFlow is bought and used by teams, so some of your data is visible to the people you work with. Be clear about what that means before you invite anyone.
The reports in an organisation are visible to that organisation's members, including the actor name attached to each one. The owner administers the organisation: they invite people, remove them, and can see and delete the organisation's reports. Joining is invite-only, and the tenant a report lands in comes from the credential that sent it rather than from the report itself, so one organisation cannot address, read or write another's data.
If you are a member rather than an owner and you want your data changed or removed, ask your owner first, because they decide what their organisation reports. You can always come to us directly if that does not work.
9. Your rights
Under the UK GDPR and the EU GDPR you have the right to ask us for a copy of your personal data, to have it corrected, to have it deleted, to receive it in a portable form, to restrict or object to how we use it, and to withdraw consent where we relied on it. Write to us at [TO CONFIRM: privacy contact email address] and we will answer within one month.
We rely on contract as our lawful basis for running your account and taking payment, on legitimate interests for keeping the service secure and working, and on legal obligation for keeping billing records.
If you think we have handled your data badly, please tell us first so we can fix it. You can also complain to the Information Commissioner's Office at ico.org.uk, or to the supervisory authority in the EU country where you live or work.
10. Security
Everything travels over TLS. Reporters authenticate with short-lived tokens rather than long-lived keys: a person signs in once, and a CI job exchanges the identity token its workflow already has. Long-lived organisation keys exist only as a documented fallback for setups that cannot sign in. Our own secrets are held in AWS Systems Manager Parameter Store and never in the repository.
Tenant isolation is structural rather than a setting: the account behind a credential owns the tenant, and a tenant named in a request body is ignored.
11. Children
TeamFlow is a tool for workplaces. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, tell us and we will delete it.
12. Changes to this policy
When we change this policy we update the effective date at the top of the page. If a change materially affects what we collect or who we share it with, we will email the owner of every organisation before it takes effect.
13. Contact us
Questions, requests and complaints about privacy go to [TO CONFIRM: privacy contact email address], or by post to [TO CONFIRM: registered address]. Our Terms of Service cover the rest of the relationship.