Privacy Policy
Last updated: 11 August 2026
Projectrr is operated by Starkey Digital Ltd (“we”, “us”). This policy explains what we collect when you use projectrr.work, why, and what control you have over it.
What we collect
Account details. Your email address, and the name and avatar your identity provider gives us when you sign in with GitHub or Google. We never receive or store a password — Projectrr does not use them.
Your content. The organizations, products, projects, issues, comments, epics, notes and settings you create. This is your data; we store it so the product works.
Integration credentials. If you connect GitHub, Trello, Sentry or Anthropic, we store the access tokens needed to work with them. They are used only to perform the syncing or automation you configured, and are deleted when you disconnect the integration. A Sentry connection can be shared by more than one of your organizations; its credentials are deleted once the last of them disconnects.
Data from a Sentry connection. If you connect Sentry, we store the details of the error groups it sends us — title, culprit, level, status, counts, first and last seen, and a link back to Sentry — so rules can act on them and shipped fixes can be resolved back. We do not fetch or store the individual error events behind them, so no stack traces, request payloads or affected-user data reaches us through the integration.
Technical data. IP address, browser type and timestamps in server logs, and error reports (including stack traces and the URL where an error happened) sent to Sentry, our error-tracking provider. We use these to keep the service running and to fix faults.
Cookies. A session cookie to keep you signed in, and a preference cookie for your light/dark theme choice. No advertising or third-party tracking cookies.
Why we can use it
We process your data to provide the service you asked for (performing our contract with you), to keep it secure and working (our legitimate interests), and where the law requires it.
Who we share it with
We do not sell your data and we do not share it for advertising. We use a small number of processors to run the service:
| Provider | What for |
|---|---|
| Cloudflare | Network, DNS and traffic protection |
| Sentry | Error tracking |
| Resend | Transactional email (magic links, invites) |
| GitHub, Google | Sign-in, if you choose them |
| GitHub, Trello | Syncing, if you connect them |
| Anthropic | Claude routines, if you connect one |
We share data with them only to the extent needed to run the service, and we disclose data to authorities only where legally required.
Sentry appears twice over. We use Sentry to track faults in Projectrr itself, as listed above. Separately, you may connect a Sentry organization of your own; where that is a self-hosted install, it is your system rather than a processor of ours, and the only data we send it is the status change a rule you wrote asks for.
Claude routines. If you connect a Claude routine to a product, every rule that fires it sends that issue’s reference, title, link and description to Anthropic. Nothing goes to Anthropic unless you have configured the integration and a rule that uses it, and Anthropic processes it outside the UK and EU.
Shared links. Roadmaps and epic reports you publish as read-only links are accessible to anyone holding the link, by design. Revoking a link stops that immediately.
Where it’s stored
On servers in the UK and EU. Where a processor is outside that area, transfers rely on the appropriate safeguards.
How long we keep it
For as long as your account is open. Deleting an organization deletes its content with it — products, projects, issues, comments, epics, labels and its activity history. It also gives up that organization’s hold on any integration it had connected, and where it was the last one holding a connection, those credentials go with it. To close your account itself, email us and we’ll erase it. We keep a record that each integration delivery arrived — which provider, which event type, its id and whether we processed it — so the same one is not applied twice. That record does not include the contents of the delivery.
Server logs and error reports are kept for up to 90 days. Backups are rotated within 30 days.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop processing it. Email [email protected] and we’ll respond within 30 days. If you’re in the UK or EU and unhappy with our response, you can complain to your data protection authority — in the UK, the ICO.
Security
Traffic is encrypted in transit. Authentication is passwordless, so there are no password hashes to leak. Access to production data is limited to people who need it. No system is perfectly secure; if a breach affects you, we’ll tell you.
Children
Projectrr isn’t intended for people under 16, and we don’t knowingly collect their data.
Changes
If we change this policy materially we’ll say so in the app before the change takes effect.