Privacy Policy
Last updated: April 6, 2026
1. Overview
TEAMPLOT LTD (company number 15569561) ("we", "us", "our") is the data controller and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use TeamPlot ("Service").
2. Information We Collect
Account Information
When you sign up, we collect your name, email address, and profile photo via Google or Microsoft SSO. We store OAuth tokens (encrypted) to access calendar and messaging integrations on your behalf.
Organization Data
Organization name, email domain, and integration connection metadata (e.g. which Slack workspace or Teams tenant is connected).
Team Member Data
Names, email addresses, role titles, and messaging platform user IDs for team members added by managers.
Messaging Activity Metadata
We collect messaging activity metadata including: message counts, timestamps, channel names, and content hashes. We do not store message content. Raw message text is fetched on-demand during AI briefing generation and is not persisted in our database.
Code Activity Metadata
When you connect a code platform (GitHub, GitLab, or Azure DevOps), we collect commit metadata (timestamps, repository names, line counts), pull request metadata (titles, open/merge/close timestamps, addition/deletion counts), and code review events. We do not read or store source code, diffs, or commit message bodies beyond the first 120 characters.
Calendar Data
We access calendar events to detect upcoming 1:1 meetings. We store event IDs, titles, attendee email addresses, and scheduled times.
3. How We Use Your Information
- To detect behavioural signals from messaging and code activity metadata
- To generate AI-powered 1:1 briefings
- To identify upcoming 1:1 meetings from calendar data
- To send notifications (email or messaging DM) when briefings are ready
- To manage your account and subscription
- To improve the Service
4. AI Processing
We use Anthropic's Claude API to generate briefings. During generation, recent messages are fetched on-demand from your connected messaging platform, and code activity metadata (PR titles, commit summaries, review events) is included for context. This data is sent to the AI for processing and discarded after the briefing is created. Message content is never stored in our database. Source code is never sent to the AI provider. The AI provider processes data according to their data usage policy and does not train on API inputs.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Anthropic — for AI briefing generation (on-demand message content and code metadata, not stored)
- Stripe — for payment processing
- Infrastructure providers — for hosting and database services
We may disclose data if required by law or to protect our rights.
6. Data Security
All OAuth tokens are encrypted at rest. Data is transmitted over TLS. We follow industry-standard security practices including regular access reviews, encrypted backups, and minimal data retention.
7. Data Retention
- Activity metadata (message counts, timestamps, code events): 90 days, then automatically deleted
- Signals and briefings: retained while your account is active
- Calendar events: 30 days of future events, refreshed periodically
- Account data: retained until you delete your account
8. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your data in a standard format
- Disconnect integrations at any time via Settings
9. Cookies
We use essential cookies for authentication and session management. We do not use third-party tracking cookies or advertising cookies.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email. Continued use after changes constitutes acceptance.
11. Contact
For privacy-related questions or data requests, contact us at privacy@teamplot.com.
TEAMPLOT LTD, company number 15569561.