Last updated: June 1, 2026
When you create an account, we collect your username, email address, and a hashed version of your password. We never store your password in plain text. When you use ScrumPM, we store the project data you create — stories, sprints, risks, team members, and related content.
Your data is stored in MongoDB Atlas, a cloud-hosted database. Data is scoped strictly to your account — no other user can access your projects. We use compound unique indexes to enforce this at the database level.
ScrumPM uses a single session cookie to keep you logged in. This cookie is HTTP-only (not accessible to JavaScript), uses SameSite=Lax to prevent cross-site request forgery, and is Secure when served over HTTPS.
We do not sell, rent, or share your personal data with third parties for marketing purposes. We use third-party infrastructure (MongoDB Atlas, Railway) to run the platform — these providers have their own privacy policies.
You can delete any project from the Projects page. To delete your account entirely, contact us at the address below and we will remove all associated data within 30 days.
For privacy questions, contact us via the Contact Us page.