Translations are provided for convenience. If a translated version differs from the English version, the English version controls.
Scope
This notice covers Troodo's website, hosted workspace, demo, support, and product analytics. An organization may also provide its own notice for how it uses engineering data and member information; contact your workspace owner about that organization's decisions.
Account and service data
Troodo processes account identifiers such as name, email address, avatar, authentication provider identifiers, sign-in events, workspace membership and role. It also processes workspace configuration, plan and billing status, feature usage, audit events, diagnostics, approximate request information, and support messages you choose to send.
Connected-system data
When authorized, Troodo normalizes engineering and product metadata such as repositories, pull or merge requests, commits, reviews, deployments, ownership, work items, product plans, and aggregate outcome metrics. The exact data depends on the provider and permissions. Browser-direct GitLab and GitHub Enterprise modes keep access tokens in the browser; manual Linear, Mixpanel, and New Relic credentials are used for that sync request and are not persisted.
How data is used
Data is used to authenticate members, isolate workspaces, operate integrations, generate dashboards and exports, provide AI-assisted reports and answers, manage subscriptions, prevent abuse, troubleshoot failures, improve the product, and meet legal obligations. Troodo does not sell personal information or use workspace content for third-party advertising.
Service providers and disclosures
Troodo relies on service providers including Supabase for authentication and database services, Vercel for hosting, OpenAI for AI features, Stripe for billing, Sentry for error monitoring, Resend for authentication email delivery, and Mixpanel when Troodo product analytics is configured. Connected GitHub, GitLab, Linear, Mixpanel, and New Relic services process requests that workspace administrators initiate. Data may also be disclosed when legally required or needed to protect users and the service.
AI and product analytics
AI requests are limited to relevant stored evidence and are sent with response storage disabled; do not place credentials or unnecessary personal data in prompts. Privacy-conscious product analytics excludes names, email addresses, repository identifiers, prompts, URLs, and tokens, and uses pseudonymous workspace and user identifiers when enabled.
Cookies and credentials
Troodo uses necessary cookies for authentication, workspace selection, security, and language preference. Browser-direct provider tokens can optionally remain in session storage for the current tab and are not sent to Troodo servers. Third-party checkout and authentication pages apply their own cookie and privacy practices.
Retention and deletion
Troodo keeps account, workspace, and normalized integration data while needed to provide an active workspace and for reasonable security, billing, backup, dispute, and legal purposes. Retention periods can differ by data type and provider. Workspace deletion is currently handled after a verified request from an authorized workspace owner; backups and legally required records may expire later.
Security
Troodo uses tenant-scoped row-level access controls, role-based permissions, server-only service credentials, signed webhook validation, transport encryption, rate limits, and operational monitoring. No system is completely secure, so report suspected exposure through the private route described on the Security page.
Choices and privacy rights
Workspace owners and administrators can manage member access and connected providers. You may ask for access, correction, export, restriction, objection, or deletion where applicable by using Support. We verify the requester and workspace authority before acting. Local law may provide additional rights and a right to contact a regulator.
International processing
Troodo and its service providers may process data in countries other than yours. Applicable provider agreements and legally required transfer mechanisms govern those transfers. A customer that needs specific residency or transfer terms should agree them in writing before connecting production data.
Children
Troodo is a business service and is not directed to children. Do not create an account or submit a child's personal information unless your organization has a lawful, documented reason and appropriate authorization.
Changes to this notice
Material updates will be posted on this page with a revised date and may also be announced in the product or through the workspace contact. Earlier versions can be requested through Support when available.
Privacy requests
Use the Support page to start a privacy request through a private channel. Include the workspace name and the type of request, but do not send credentials, source code, or unrelated personal data.