Legal
Privacy policy
Placeholder. This document describes how Boardhop actually works, but its wording has not been reviewed by a lawyer and it is not yet binding. It is published so the app stores, the Marketplace listing and prospective customers have something to read during the beta. The reviewed version replaces it before public launch.
1. Who we are
Boardhop is a mobile application for Azure DevOps Services published by KammCS (“we”, “us”). This policy covers the Boardhop mobile app, the Boardhop extension for the Azure DevOps Marketplace, the Boardhop relay service, and this website.
Where an organization turns on the Boardhop relay for its Azure DevOps organization, that organization is the controller of the event metadata described in section 4 and we act as its processor. For your own account and billing details we are the controller.
2. The short version
- Your work content never reaches us. The app talks to Azure DevOps directly from your device using your own credentials. Work items, comments, code, diffs and wiki pages go between your device and Microsoft, not through us.
- We have no accounts. There is no Boardhop login, no password and no profile. You sign in with your existing Microsoft work or school account.
- No advertising and no tracking. We do not sell data, we do not run advertising, and there are no third-party analytics or advertising SDKs in the app.
- Notifications carry a pointer, not content. A push says who did what to which item, and links to it. Your device then fetches the detail with your own credentials.
3. What the app does with your data
Sign-in
You sign in through Microsoft Entra ID. We never see your password. The access and refresh tokens Microsoft issues are stored in the operating system's secure store on your device (the iOS Keychain or the Android Keystore) and are used only to call Azure DevOps. They are not transmitted to us, except for the one-off organization check described in section 4, where the token is used and discarded and never written down.
The offline cache
Pages you open are cached on your device so the app works without a signal. That cache lives only on your device, is namespaced per account, and is deleted when you sign that account out or remove the app.
Settings
Your preferences — theme, default project, notification choices — are stored on your device. Notification preferences are additionally stored by the relay when your organization uses it, because the relay needs them to decide what to send.
4. What the relay sees
The relay only exists for organizations whose administrator has installed the Boardhop extension and turned it on. If your organization has not, nothing in this section applies to you and the relay holds nothing about you.
Device registration
To receive notifications your device registers with the relay. It presents its Apple or Google push token together with your Azure DevOps token. We use your token once, to confirm with Microsoft that you are a member of that organization and to learn your user id, and then discard it. We never store your Azure DevOps token. What we keep is the organization id, your Azure DevOps user id, your device's push token, and your notification preferences.
Events
Azure DevOps sends the relay a webhook when something happens in your organization — a comment, a review request, an assignment, a finished run, a waiting approval. The relay reads that payload in memory to work out who should be told and which item it concerns, and persists nothing from it: not the payload, not comment text, not descriptions, not code.
What is sent to Apple and Google
Only a pointer: the organization, the event type, the type and id of the item, the display name of the person who acted, a short verb such as “replied on”, a title of at most 80 characters, and a link. Item titles are metadata that appear in every list view in Azure DevOps; comment bodies, descriptions and code are content and are never included. Your device fetches the detail itself, with your own credentials, before showing you the notification.
Logs
The relay logs the pointer it emitted, the organization, and technical delivery results, with credentials redacted. These logs exist to debug delivery failures.
5. The active-user count
Organizations on the paid plan are billed per active user. To do that the relay records, for each organization and each calendar month, the set of Azure DevOps user ids that opened the app for that organization. It records that a user was active, not what they did. Your organization's administrators can see this list — it is shown in the admin hub so an invoice can be checked.
6. Diagnostics and crash data
Store builds of the app contain no analytics SDK and no crash reporting service. Diagnostic screens exist only in internal builds and never leave the device. If you send us a diagnostic report yourself, you choose what it contains before it is sent.
Apple and Google may provide us with aggregate, anonymised crash and install statistics from their own stores; this is governed by their policies and we cannot identify you from it.
7. Who else is involved
We use a small number of service providers. They are listed, with what each one receives and where it is processed, on the subprocessors page. We do not sell personal data and we do not share it for advertising.
We will disclose data if we are legally required to. Where the law allows, we will tell the affected organization first.
8. How long anything is kept
| What | Where | Kept for |
|---|---|---|
| Azure DevOps tokens | Your device only | Until you sign out |
| Offline cache | Your device only | Until you sign out or remove the app |
| Device registration | Relay | Until the device unregisters, the token is rejected by Apple or Google, or 90 days of inactivity |
| Webhook payloads | Relay, in memory | Not persisted |
| Delivery logs | Relay | 30 days |
| Active-user ledger | Relay | 24 months, for billing history |
| Billing records | Stripe and our records | As long as tax law requires |
9. Your rights
Depending on where you live you may have the right to access, correct, delete or export the personal data we hold, to object to processing, or to complain to a supervisory authority. Because most of what concerns you sits in your employer's Azure DevOps organization rather than with us, the fastest route is usually your own administrator. For the little we hold — your device registration, your notification preferences and the fact that you were active in a month — write to privacy@boardhop.dev and we will respond within 30 days.
You can remove everything we hold about you at any time by turning off notifications in the app or by signing out, which unregisters the device.
10. Children
Boardhop is a tool for workplaces and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Changes
If we change this policy materially we will update the date at the top and, for organizations on a paid plan, notify the billing contact before the change takes effect.
12. Contact
KammCS, publisher of Boardhop — privacy@boardhop.dev. Postal address to be added before public launch.