Last updated: March 28, 2026
This Privacy Policy explains how CmSoftware ("Company", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Public Backlog platform ("Service") at app.publicbacklog.com. By using the Service, you agree to the collection and use of information in accordance with this policy.
When you create an account, we collect:
When you create or join an Organization, we collect:
When you use the Service, you may submit:
When you visit the Service, we automatically collect:
This data is collected for analytics, security, and service improvement purposes and is not linked to your user account.
We use the following browser storage mechanisms:
| Name | Type | Purpose |
|---|---|---|
| AuthToken | HttpOnly Cookie | Authentication session (JWT token). Expires after 7 or 30 days. |
| OrganizationAuthToken | HttpOnly Cookie | Organization-scoped authentication session. |
| pb_theme | localStorage | Your display theme preference (light, dark, or system). |
| pb_recent_orgs | localStorage | Recently accessed organizations for quick navigation. |
| pb_tutorial | localStorage | Onboarding tutorial progress. |
Our authentication cookies are HttpOnly and Secure, meaning they cannot be accessed by JavaScript and are only transmitted over HTTPS. We do not use third-party advertising or tracking cookies.
If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number or banking details. We store only:
Stripe's handling of your payment data is governed by the Stripe Privacy Policy.
We use the information we collect to:
We do not sell your personal information. We share your data only in the following circumstances:
We use the following service providers to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Customer ID, subscription data |
| SendGrid | Transactional email | Email addresses, names, email content |
| Sentry | Error monitoring | Error logs, request data, user context for debugging |
| Amazon S3 | File storage | Uploaded files (avatars, ticket attachments) |
Ticket content may be sent to AI services (currently Groq) for spam detection and relevancy scoring. This processing is automated and used solely to help you filter and prioritize feedback. No personal account information is sent — only ticket content (title and description).
When you or your Organization administrator connects a third-party integration, ticket data (titles, descriptions, status, comments) is shared with that platform. Currently supported integrations include:
Integration connections are initiated by you and can be disconnected at any time. Each integration platform has its own privacy policy governing how they handle your data. Integration credentials (OAuth tokens and API keys) are stored in encrypted form and used solely to maintain the connection.
If you enable review aggregation, we poll public review platforms (App Store, Trustpilot) for reviews related to your product and import them as tickets. This involves reading publicly available review data — we do not share your data with these platforms.
We may disclose your information if required by law, legal process, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of CmSoftware, our users, or the public.
We implement the following security measures to protect your data:
While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information. To make a request, contact us at the email above.
If you are in the EEA, our legal bases for processing your data include: performance of a contract (providing the Service), legitimate interests (improving and securing the Service), and consent (where applicable). You have the right to lodge a complaint with your local data protection authority.
Your data may be processed and stored in the United States or other countries where our service providers operate. By using the Service, you consent to the transfer of your data to these jurisdictions, which may have different data protection laws than your country of residence.
The Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal data from anyone under 18, we will take steps to delete that information promptly. If you believe a minor has provided us with personal data, please contact us.
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of these third parties. We encourage you to review their privacy policies before providing them with your information.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice on the Service and update the "Last updated" date at the top of this page. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: