Legal

Privacy policy

Effective 20 September 2026 Last updated 20 September 2026 KammCS, publisher of Boardhop

Placeholder. This document describes how Boardhop actually works, but its wording has not been reviewed by a lawyer and it is not yet binding. It is published so the app stores, the Marketplace listing and prospective customers have something to read during the beta. The reviewed version replaces it before public launch.

1. Who we are

Boardhop is a mobile application for Azure DevOps Services published by KammCS (“we”, “us”). This policy covers the Boardhop mobile app, the Boardhop extension for the Azure DevOps Marketplace, the Boardhop relay service, and this website.

Where an organization turns on the Boardhop relay for its Azure DevOps organization, that organization is the controller of the event metadata described in section 4 and we act as its processor. For your own account and billing details we are the controller.

2. The short version

  • Your work content never reaches us. The app talks to Azure DevOps directly from your device using your own credentials. Work items, comments, code, diffs and wiki pages go between your device and Microsoft, not through us.
  • We have no accounts. There is no Boardhop login, no password and no profile. You sign in with your existing Microsoft work or school account.
  • No advertising and no tracking. We do not sell data, we do not run advertising, and there are no third-party analytics or advertising SDKs in the app.
  • Notifications carry a pointer, not content. A push says who did what to which item, and links to it. Your device then fetches the detail with your own credentials.

3. What the app does with your data

Sign-in

You sign in through Microsoft Entra ID. We never see your password. The access and refresh tokens Microsoft issues are stored in the operating system's secure store on your device (the iOS Keychain or the Android Keystore) and are used only to call Azure DevOps. They are not transmitted to us, except for the one-off organization check described in section 4, where the token is used and discarded and never written down.

The offline cache

Pages you open are cached on your device so the app works without a signal. That cache lives only on your device, is namespaced per account, and is deleted when you sign that account out or remove the app.

Settings

Your preferences — theme, default project, notification choices — are stored on your device. Notification preferences are additionally stored by the relay when your organization uses it, because the relay needs them to decide what to send.

4. What the relay sees

The relay only exists for organizations whose administrator has installed the Boardhop extension and turned it on. If your organization has not, nothing in this section applies to you and the relay holds nothing about you.

Device registration

To receive notifications your device registers with the relay. It presents its Apple or Google push token together with your Azure DevOps token. We use your token once, to confirm with Microsoft that you are a member of that organization and to learn your user id, and then discard it. We never store your Azure DevOps token. What we keep is the organization id, your Azure DevOps user id, your device's push token, and your notification preferences.

Events

Azure DevOps sends the relay a webhook when something happens in your organization — a comment, a review request, an assignment, a finished run, a waiting approval. The relay reads that payload in memory to work out who should be told and which item it concerns, and persists nothing from it: not the payload, not comment text, not descriptions, not code.

What is sent to Apple and Google

Only a pointer: the organization, the event type, the type and id of the item, the display name of the person who acted, a short verb such as “replied on”, a title of at most 80 characters, and a link. Item titles are metadata that appear in every list view in Azure DevOps; comment bodies, descriptions and code are content and are never included. Your device fetches the detail itself, with your own credentials, before showing you the notification.

Logs

The relay logs the pointer it emitted, the organization, and technical delivery results, with credentials redacted. These logs exist to debug delivery failures.

5. The active-user count

Organizations on the paid plan are billed per active user. To do that the relay records, for each organization and each calendar month, the set of Azure DevOps user ids that opened the app for that organization. It records that a user was active, not what they did. Your organization's administrators can see this list — it is shown in the admin hub so an invoice can be checked.

6. Diagnostics and crash data

Store builds of the app contain no analytics SDK and no crash reporting service. Diagnostic screens exist only in internal builds and never leave the device. If you send us a diagnostic report yourself, you choose what it contains before it is sent.

Apple and Google may provide us with aggregate, anonymised crash and install statistics from their own stores; this is governed by their policies and we cannot identify you from it.

7. Who else is involved

We use a small number of service providers. They are listed, with what each one receives and where it is processed, on the subprocessors page. We do not sell personal data and we do not share it for advertising.

We will disclose data if we are legally required to. Where the law allows, we will tell the affected organization first.

8. How long anything is kept

WhatWhereKept for
Azure DevOps tokensYour device onlyUntil you sign out
Offline cacheYour device onlyUntil you sign out or remove the app
Device registrationRelayUntil the device unregisters, the token is rejected by Apple or Google, or 90 days of inactivity
Webhook payloadsRelay, in memoryNot persisted
Delivery logsRelay30 days
Active-user ledgerRelay24 months, for billing history
Billing recordsStripe and our recordsAs long as tax law requires

9. Your rights

Depending on where you live you may have the right to access, correct, delete or export the personal data we hold, to object to processing, or to complain to a supervisory authority. Because most of what concerns you sits in your employer's Azure DevOps organization rather than with us, the fastest route is usually your own administrator. For the little we hold — your device registration, your notification preferences and the fact that you were active in a month — write to privacy@boardhop.dev and we will respond within 30 days.

You can remove everything we hold about you at any time by turning off notifications in the app or by signing out, which unregisters the device.

10. Children

Boardhop is a tool for workplaces and is not directed at children. We do not knowingly collect data from anyone under 16.

11. Changes

If we change this policy materially we will update the date at the top and, for organizations on a paid plan, notify the billing contact before the change takes effect.

12. Contact

KammCS, publisher of Boardhop — privacy@boardhop.dev. Postal address to be added before public launch.