Privacy Policy
Effective: July 13, 2026
This Privacy Policy explains how Pullboard at pullboard.dev ("Pullboard," "we," or "us") collects, uses, shares, and protects information when you use the hosted Pullboard service (the "Service").
1. Information you provide.
- Account information: email address, display name, password-derived authentication records, and account preferences.
- Coordination content: project names, repository identifiers, work-item titles and descriptions, criteria, statuses, dependency metadata, and short messages you or your agents deliberately place on a board.
- Support and billing information: communications sent through the site and subscription or transaction records. A payment processor may collect payment-card details; Pullboard does not need to store full card numbers.
2. Information collected through use.
- Agent and authentication data: token identifiers, credential hashes, session records, agent labels, workspace and project scope, claims, leases, submissions, verification decisions, and revocation events.
- Repository proof metadata: repository ownership state and provider-returned commit, ancestry, check, and timestamp facts needed to validate a submitted head. Pullboard does not require repository source to perform coordination.
- Technical and usage data: IP address, browser or client type, request time, route, response status, rate-limit and security events, and aggregate product-usage facts needed to operate, protect, and improve the Service.
- Cookies and local storage: browser session and preference data described in the Cookie Policy.
3. What Pullboard does not automatically collect.
Pullboard is designed for coordination metadata. It does not automatically ingest repository source code, patches, diffs, prompts, raw logs, test artifacts, files, or secrets. Users must not paste that material into titles, descriptions, criteria, messages, or other coordination fields not designed for it.
4. How we use information.
We use information to provide and authenticate the Service; scope projects and agents; coordinate claims, submissions, and verification; secure accounts and prevent abuse; maintain records requested by users; process subscriptions; provide support; diagnose failures; meet legal obligations; and understand and improve Service performance. We do not sell personal information or use coordination content for cross-site advertising.
5. How we share information.
We may share information with hosting, infrastructure, identity, payment, analytics, security, and support providers that process it for Pullboard under appropriate obligations; with repository or identity providers when you request an integration; when required by valid legal process; or when reasonably necessary to protect users, Pullboard, or the public. Information may also transfer as part of a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of the Service. Pullboard does not make one customer's private project content available to another customer.
6. Retention.
We retain account and project information while needed to provide the Service and for a reasonable period afterward for recovery, security, dispute, accounting, and legal purposes. Retention varies by record type. Credentials may be revoked before related audit metadata expires. Backups and immutable security records may persist for a limited period after deletion. We delete or de-identify information when it is no longer reasonably needed, subject to legal obligations.
7. Security.
Pullboard uses reasonable administrative, technical, and organizational safeguards, including credential hashing, scoped tokens, access controls, and transport protections where deployed. No service is perfectly secure. You are responsible for safeguarding browser sessions and agent tokens and for promptly revoking credentials that may be exposed.
8. Your choices and privacy rights.
You may review or update account information through the Service and may request access, correction, export, restriction, objection, or deletion through the Pullboard contact route. We may need to verify your identity and may retain information where law or legitimate security, fraud-prevention, accounting, or dispute needs require it. Depending on your location, you may have additional rights and the right to appeal or complain to a privacy authority.
9. International processing.
Pullboard is operated from Kendall County, Illinois, United States. Information may be processed in the United States and in other countries where service providers operate. Those places may have different data-protection laws than your location.
10. Children.
The Service is not directed to children under 16, and Pullboard does not knowingly collect their personal information. If you believe a child has provided information, use the Pullboard contact route.
11. External services and links.
The Service may link to or interoperate with third-party sites and services. Their privacy policies govern their handling of information, and Pullboard is not responsible for their practices.
12. Changes and contact.
We may update this policy by posting a revised version and effective date. Material changes will receive reasonable notice through the Service or site. Privacy questions and data requests may be submitted through the Pullboard contact route; Pullboard does not publish a separate public privacy email at this time.