---
title: "Privacy policy / Data policy"
canonical: "https://support.appfire.com/space/POKERADO/148308012/Privacy%20policy%20%2F%20Data%20policy"
format: markdown
---
We take data security very seriously so we use only trusted service providers with the highest security standards. On this page, you will find details on how we secure our customers' data. If you think something is missing or you have any security related questions please let us know - [supportazure@appfire.com](mailto:supportazure@appfire.com)

# Services providers

> Macro (toc)

[sub-processor] - providers with this label are our data sub-processors as defined by European General Data Protection Regulation (GDPR).

## Google Firebase

[sub-processor] Firebase is a real-time shared database. We use it to synchronise Planning Poker game data between the users in the real time.

### Stored data

- Azure DevOps organization key
- Project key
- Sprint Id
- Session Id (internal identifier of the browser's tab with ADO content loaded)
- Account Ids of the users who participate in the game or configure it
- Work item Ids (items selected for the game, voted item, items selected in the filter)
- Estimation votes (per user per work item)
- Game state (e.g. in progress / finished)

## Google Cloud Platform

[sub-processor] We store application logs to troubleshoot and analyze incidents.

**Logs might contain:**

- Instance ids
- Project ids
- User ids

Retention period is 30 days.

### Security

Firebase database is secured using Firebase security rules. Each user within your Azure DevOps organization has access to all data listed in *Stored data* section for all your Planning Poker games. Anonymous users and users from other Azure DevOps organization/project does not have access to your data. 

We store daily backups of this database for last 30 days.

> ℹ️ ### We store the minimal amount of data needed to provide our service.
> ℹ️ 
> ℹ️ We don't store work items' title, description, comments nor other sensitive information. We don't store users' full names nor e-mails but we access user keys provided by Azure DevOps which may contain them.

## Bugsnag

[sub-processor] Bugsnag is a tool for reporting frontend errors from the user's browser. It allows us to spot and react to product issues before our customers report them to us.

### Stored data

- Organization & Project Id
- User Id
- User browser information (browser, version, locale, operating system, user agent)
- User IP address
- User language
- Error details

## Keen.io Analytics

[sub-processor] With Keein.io we collect anonymous statistics of the extension usage to better understand customers behavior. It's one of the inputs to product development plan. We do **not** collect any information about users, content of work items, comments, or any identifiable information about the Azure DevOps organization itself.

The table below is intended to provide a complete understanding of the policy that we use to collect analytics data. This table is **not** intended to list all the possible events collected by the extension.

| **Data type** | **Comments** |
| --- | --- |
| User interface and usage | Displaying and interacting with the components and pages **added by Planning Poker extension** including:<br>- Games dashboard
- Game activities
- Game's creation and configuration pages
- Estimation activities on work item details page<br>Interacting means clicking on the components or changing their state. |
| Flags and statistics | We collect boolean flags and statistic numbers from the inputted data. This applies to data gathered via extension components or pages (including configuration and usage pages). For example:<br>- Type of game's scope (by sprint / by query / custom work items)<br>Flags and statistics **do not** contain any user generated content. |
| Context | We collect a few general context values from Azure DevOps, e.g.<br>- License type (evaluation / paid)<br>Context parameters **do not** contain any user generated content. |