This page lists what Northset reads from each tool you connect, what it stores, and for how long. Northset only reads a tool after an administrator connects it. Retention periods apply while a tool is connected. If you disconnect a tool, its records are kept until you reconnect it or ask us to delete your data. To delete your data, see our Privacy Policy.
GitHub
Access. A GitHub App installed by your administrator, with read-only permissions. Northset never writes to your repositories.
What we read. Repository names. Pull request titles, descriptions, authors, assigned reviewers, branch names, open and close times, and size. Review activity, pull request comments, review comments, and commit messages. We check whether a repository has a CODEOWNERS file, but never store or use its contents.
What we store. The name of the GitHub organization or account the app is installed on, pull request details, and records of who reviewed or commented and when. Raw events GitHub sends us are redacted within hours and deleted within 30 days. Records of who reviewed or commented are kept for 8 weeks.
Disconnecting. Uninstall the Northset app from your GitHub organization's settings. When we delete your data, we remove the installation ourselves.
Jira
Access. Connected by your administrator with read-only scopes. Northset never changes your Jira data.
What we read. Sprint configuration (name, start date, end date, duration). Ticket keys, summaries, descriptions, story points, assignees, status, and blocked-by links. Tickets added mid-sprint. Board names, field names, and the values of custom fields your organization has configured, which may include personal data you have chosen to store there. Comments, to find commitments. Who changed a ticket's status or assignee, and who commented and when.
What we store. Ticket details needed for alerts, including the titles of tickets added mid-sprint. Records of who changed a ticket's status or assignee, and who commented and when, kept for 8 weeks. Comment text is never stored. Raw events Jira sends us are redacted within hours and deleted within 30 days.
Disconnecting. Your administrator removes Northset from your Atlassian account's connected apps, including any Forge app or webhook. Atlassian does not let apps remove their own access.
Linear
Access. A Linear API key created by your administrator.
What we read. Issue identifiers, status, due dates, and when each issue was created and last updated. For issues linked to a commitment, the history of status and due date changes. Team keys (such as "ENG"). For issues changed in the last 8 weeks, who changed each issue, who it was assigned to, and who commented and when. We never read issue titles, descriptions, or comment text.
What we store. Status and due date history, kept until your data is deleted. Team keys. Records of who changed, was assigned to, or commented on an issue, kept for 8 weeks.
Disconnecting. Delete the API key in Linear. Linear does not let apps remove their own access.
YouTrack
Access. A YouTrack permanent token created by your administrator.
What we read. Your YouTrack address. Issue IDs, state, due dates, and when each issue was created, updated, and resolved. For issues linked to a commitment, the history of state and due date changes, and, if an issue is closed as a duplicate, which issue it duplicates. Each project's list of state names. For issues changed in the last 8 weeks, who changed each issue, who it was assigned to, and who commented and when. To find due dates and status, we read an issue's custom fields, which your organization defines and which may contain personal data. We never read issue summaries, descriptions, or comment text.
What we store. Your YouTrack address, state names, state and due date history, and duplicate links, kept until your data is deleted. From custom fields, only the due date, status, and whether anyone is assigned. Records of who changed, was assigned to, or commented on an issue, kept for 8 weeks.
Disconnecting. Delete the permanent token in the YouTrack profile of the person who created it. YouTrack does not let apps remove their own access.
Slack
Access. A Slack app installed by a workspace admin. It includes permission, granted through the installing admin's account, to read public channels.
What we read. Messages in every public channel, and in private channels the Northset app is added to, to find commitments. Reactions and who reacted, and who was mentioned. Member names, IDs, display names, time zones, and whether each member is an admin, owner, or guest. Channel names and member lists. We never read direct messages or group direct messages.
What we store. Message text is not stored. We keep AI-written summaries of messages that contain commitments, and the text of alerts we send, for up to 3 years. We also keep message IDs that link back to the original in your Slack.
Disconnecting. Remove the Northset app from your Slack workspace. When we delete your data, we remove our access ourselves.
Google Calendar
Access. Read-only access, connected by your organization.
What we read. Event times, attendees, organizers, and responses, used to confirm whether scheduled commitments happened. We never read event titles, descriptions, or locations. Northset's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What we store. Event times, responses, and the email addresses of attendees and organizers.
Disconnecting. Remove Northset from your Google account's third-party access settings. When we delete your data, we remove our access ourselves.