LogoPublic Backlog

  • Documentation

Privacy Policy

Last updated: March 28, 2026

This Privacy Policy explains how CmSoftware ("Company", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Public Backlog platform ("Service") at app.publicbacklog.com. By using the Service, you agree to the collection and use of information in accordance with this policy.


1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Required: Email address, first name, last name, and password (stored in hashed form).
  • Optional: Phone number, profile avatar image.
  • Via Google OAuth: If you sign up with Google, we receive your email address, first name, and last name from Google.
  • Via SSO (OIDC): If your organization uses SSO (Okta, Microsoft Entra ID, Auth0, Google Workspace, or other OIDC providers), we receive your email address and external identity identifier from your identity provider.

1.2 Organization and Team Information

When you create or join an Organization, we collect:

  • Organization name and configuration settings.
  • Organization User profiles (email, name, role, join date).
  • Invitation records (invitee email address, invitation code, expiration).

1.3 User-Generated Content

When you use the Service, you may submit:

  • Tickets (feedback, bug reports, feature requests, ideas, and questions) including title, description, and custom field values.
  • Comments and replies on tickets.
  • Votes on tickets.
  • Internal notes (visible only to Organization administrators).
  • Changelog entries.
  • Roadmap configurations.
  • File attachments (images and documents uploaded to tickets or profiles).

1.4 Automatically Collected Information

When you visit the Service, we automatically collect:

  • IP address (IPv4 or IPv6).
  • User agent (browser type, version, and operating system).
  • HTTP referrer (the page that linked you to us).
  • Pages visited (request paths within the Service).
  • Timestamps of visits.

This data is collected for analytics, security, and service improvement purposes and is not linked to your user account.

1.5 Cookies and Local Storage

We use the following browser storage mechanisms:

NameTypePurpose
AuthTokenHttpOnly CookieAuthentication session (JWT token). Expires after 7 or 30 days.
OrganizationAuthTokenHttpOnly CookieOrganization-scoped authentication session.
pb_themelocalStorageYour display theme preference (light, dark, or system).
pb_recent_orgslocalStorageRecently accessed organizations for quick navigation.
pb_tutoriallocalStorageOnboarding tutorial progress.

Our authentication cookies are HttpOnly and Secure, meaning they cannot be accessed by JavaScript and are only transmitted over HTTPS. We do not use third-party advertising or tracking cookies.

1.6 Payment Information

If you subscribe to a paid plan, payment is processed by Stripe. We do not store your credit card number or banking details. We store only:

  • Stripe customer ID (a reference identifier).
  • Subscription plan and status.
  • Invoice numbers.

Stripe's handling of your payment data is governed by the Stripe Privacy Policy.

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Create and manage your account, authenticate sessions, and deliver the core feedback management features.
  • Process payments: Manage subscriptions and billing through Stripe.
  • Send transactional emails: Account verification, password resets, organization invitations, and notification digests.
  • Deliver notifications: In-app notifications for ticket status changes, comments, and other activity you subscribe to.
  • Operate integrations: Sync your data with third-party platforms you have explicitly connected.
  • AI-powered features: Analyze ticket content for spam detection and relevancy scoring to help you prioritize feedback.
  • Improve the Service: Analyze usage patterns, diagnose errors, and improve performance and features.
  • Ensure security: Detect and prevent fraud, abuse, and unauthorized access.

3. How We Share Your Information

We do not sell your personal information. We share your data only in the following circumstances:

3.1 Third-Party Service Providers

We use the following service providers to operate the Service:

ProviderPurposeData Shared
StripePayment processingCustomer ID, subscription data
SendGridTransactional emailEmail addresses, names, email content
SentryError monitoringError logs, request data, user context for debugging
Amazon S3File storageUploaded files (avatars, ticket attachments)

3.2 AI Processing

Ticket content may be sent to AI services (currently Groq) for spam detection and relevancy scoring. This processing is automated and used solely to help you filter and prioritize feedback. No personal account information is sent — only ticket content (title and description).

3.3 User-Enabled Integrations

When you or your Organization administrator connects a third-party integration, ticket data (titles, descriptions, status, comments) is shared with that platform. Currently supported integrations include:

  • Project Management: GitHub, Jira, Asana, Linear, Azure DevOps, ClickUp, Notion
  • Communication: Slack, Microsoft Teams, Discord
  • Support: Intercom, Zendesk, Help Scout, Freshdesk
  • CRM: Salesforce, HubSpot
  • Automation: Zapier, Segment, Outgoing Webhooks

Integration connections are initiated by you and can be disconnected at any time. Each integration platform has its own privacy policy governing how they handle your data. Integration credentials (OAuth tokens and API keys) are stored in encrypted form and used solely to maintain the connection.

3.4 Review Sources

If you enable review aggregation, we poll public review platforms (App Store, Trustpilot) for reviews related to your product and import them as tickets. This involves reading publicly available review data — we do not share your data with these platforms.

3.5 Legal and Safety

We may disclose your information if required by law, legal process, or government request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of CmSoftware, our users, or the public.

4. Data Retention

  • Account data: Retained as long as your account is active. Upon account deletion, personal data is soft-deleted (marked as deleted) and may be permanently purged after a retention period.
  • User-generated content: Retained as long as the associated Organization and Backlog exist. Deleted content is soft-deleted and may be retained for a period before permanent removal.
  • Visit logs: IP addresses and page visit data is retained for analytics and security purposes.
  • Audit trails: Activity logs (ticket changes, status updates) are retained for the lifetime of the Organization for accountability and compliance purposes.
  • Payment records: Subscription and invoice records are retained as required for accounting and legal obligations.

5. Data Security

We implement the following security measures to protect your data:

  • Passwords are cryptographically hashed before storage — we never store plaintext passwords.
  • Authentication uses secure, HttpOnly, encrypted JWT tokens transmitted only over HTTPS.
  • Integration credentials (OAuth tokens, API keys) are encrypted at rest using application-level encryption.
  • All data in transit is encrypted via TLS/HTTPS.
  • Role-based access control limits data access within Organizations.
  • Webhook payloads are signed using HMAC-SHA256 for integrity verification.

While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data (subject to legal retention requirements).
  • Portability: Request your data in a structured, machine-readable format.
  • Objection: Object to the processing of your data for certain purposes.
  • Restriction: Request that we limit the processing of your data.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.

6.1 California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of its sale. We do not sell personal information. To make a request, contact us at the email above.

6.2 European Economic Area Residents (GDPR)

If you are in the EEA, our legal bases for processing your data include: performance of a contract (providing the Service), legitimate interests (improving and securing the Service), and consent (where applicable). You have the right to lodge a complaint with your local data protection authority.

7. International Data Transfers

Your data may be processed and stored in the United States or other countries where our service providers operate. By using the Service, you consent to the transfer of your data to these jurisdictions, which may have different data protection laws than your country of residence.

8. Children's Privacy

The Service is not intended for anyone under the age of 18. We do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal data from anyone under 18, we will take steps to delete that information promptly. If you believe a minor has provided us with personal data, please contact us.

9. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of these third parties. We encourage you to review their privacy policies before providing them with your information.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice on the Service and update the "Last updated" date at the top of this page. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

  • Email: [email protected]
  • Website: publicbacklog.com

Public Backlog

  • Home
  • Features
  • About us
  • Contact us

Information

  • Terms of Service
  • Privacy Policy
  • About us
  • Jobs

Support

  • FAQ
  • Contact
  • Disscusion

2026 © Public Backlog

Select your color