Privacy policy

Last updated August 18, 2026

1. Introduction

Northset ("we," "us," or "our") builds software that helps engineering managers spot sprint execution drift by analyzing signals from GitHub, Jira, and Slack. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it.

For workspace data pulled from your connected tools, Northset acts as a data processor. Our customers, meaning the organizations that use Northset, are the data controllers. We process workspace data only on their instructions, under the terms of our customer agreement.

2. Information We Collect

Workspace Data

When an administrator connects Northset to your tools via OAuth, we ingest:

  • GitHub: repository names; pull request data including titles, descriptions, authors, assigned reviewers, open/close timestamps, and size; review activity including who reviewed and when; and the connecting account's GitHub username. This data arrives both through API reads and through webhook events GitHub sends us.
  • Jira: sprint configuration (name, start date, end date, duration); ticket data including keys, summaries, story points, assignee names, status, and blocked-by links; mid-sprint additions; and board and field names. During team detection, we also read the custom fields configured in your Jira. Because those fields are defined by your organization, their contents are under your control and may include personal data you have chosen to store there.
  • Slack: workspace member names and IDs, and profile details such as display name and timezone, used to deliver alerts to the right people; and channel metadata needed to route alerts to the selected channel.

This data identifies individuals, including ticket assignees, pull request authors and reviewers, and Slack members, and we link a person's identity across connected tools where that is needed to deliver alerts correctly.

What we deliberately do not collect

  • We record that a Jira ticket changed without reading who made the change.
  • We never ingest the contents of your CODEOWNERS files.
  • The product contains no advertising trackers, third-party analytics, or session recording.

Usage Data

Server logs and error logs needed to operate the service. These can include usernames that appear in the events being processed.

3. How We Use Your Information

  • Delivering the Northset service and surfacing alerts.
  • Improving the service.
  • Security monitoring and abuse prevention.
  • Customer support and account communication.

Reporting is at the team level: Northset does not produce individual performance scores, rankings, or comparisons. Individual alerts may name the people involved in the work they describe (for example, an alert about an unreviewed pull request names its reviewer) because delivering the alert requires it.

We do not use your workspace data to train generative AI models. Customer GitHub, Jira, and Slack content is never sent to third-party LLM providers for training and is never used to train foundation models of our own.

4. Data Sharing

We share data only with subprocessors needed to run the service:

  • Render: cloud hosting and PostgreSQL database.
  • Sentry: error monitoring. Error reports are scrubbed before sending, but may include workspace identifiers such as repository names or ticket keys.

We do not sell personal information. We do not share data with advertisers and do not run advertising on the product.

5. Data Retention

We retain workspace data for as long as your organization is connected to Northset. Raw Jira and GitHub event payloads are redacted within hours of processing and deleted within 30 days.

When your organization offboards, or upon a verified deletion request, we permanently delete your organization's data from production systems. Verified requests are honored within 30 days.

Upon deletion, we revoke our own access to your GitHub and Slack. Atlassian does not provide a mechanism for applications to revoke their own access. Your administrator must remove Northset from your Atlassian account's connected applications, including any Forge app or webhook installed in your Jira. These steps are included in our deletion confirmation.

The following persist after deletion: a single audit record of the organization's creation and deletion; events queued at the moment of deletion, which are cleared within the next processing cycle; alerts already delivered to your Slack workspace; and copies in service logs and database backups until they expire on their respective schedules.

6. Security

  • Encryption in transit via HTTPS/TLS.
  • Encryption at rest using AES-256-GCM for all stored OAuth tokens.
  • Per-organization credential isolation: no cross-tenant data access.
  • OAuth secrets stored as environment variables, never in source code.

7. International Transfers

Northset is hosted on Render's infrastructure in the United States, so customer data is processed and stored in the US. For customers subject to GDPR, we support transfers under Standard Contractual Clauses; contact us to put them in place.

8. Your Rights

Subject to applicable law, you have the following rights over your personal data:

  • GDPR: access, deletion, portability, restriction, rectification, and objection.
  • CCPA/CPRA: the right to know, delete, and opt out of the sale or sharing of personal information. Northset does not sell personal information.

To exercise any of these rights, email privacy@northsetapp.com. If you are an end user of a Northset customer, please contact that customer first; we will assist them in responding.

9. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 30 days notice by email and in-product before the changes take effect.

10. Contact

Questions, requests, or concerns about this policy can be directed to:

privacy@northsetapp.com