Privacy Policy
Standly is an async standups app for Microsoft Teams. This policy explains what we collect, why we collect it, and how it is stored and deleted. If you have questions, contact us at support@standly.io.
What we collect
- Teams identity. Your Microsoft 365 tenant id and your Microsoft Entra user object id, so we can associate you with the correct organization and channel.
- Profile basics. Your display name and (when available) email, shown in the config tab and digests.
- Timezone. The timezone we use to prompt you at the right local time and to post the channel digest.
- Standup responses. The answers you submit to standup questions, which are compiled into the channel digest.
- Conversation references. The Teams routing data the bot needs to message you. These are encrypted at rest.
- Optional Azure DevOps tokens. If you connect Azure DevOps, the credential (personal access token or OAuth tokens) is stored encrypted at rest using AES-256-GCM.
Why we collect it
We use this data to deliver the product: to prompt participants for their standup, to send reminders, to compile and post digests to your channel, and, when you connect Azure DevOps, to include optional work-item context in your responses. We do not use your data for advertising.
Where it is stored
Data is stored in a Neon Postgres database. Sensitive fields, specifically Teams conversation references and any Azure DevOps tokens, are encrypted at rest with AES-256-GCM before they are written. They are decrypted only in memory when the app needs to send you a message or query Azure DevOps on your behalf.
Retention and deletion
When Standly is uninstalled from your team or channel, the associated standups, participants, responses, digests, conversation references, and Azure DevOps links are removed. If you want data deleted sooner, email support@standly.io and we will handle the request.
Sub-processors
We do not sell your data. We share it only with the providers required to run the service:
- Vercel. Application hosting and the scheduler that decides when prompts and digests are sent.
- Neon. The Postgres database where the data above is stored.
- Microsoft. Teams and the Bot Framework, which deliver the prompts and digests to your chats and channels.
Azure DevOps is contacted only for teams that connect it, and only to read the activity used for pre-fill and to write back the notes you ask us to write.
Contact
Questions about this policy or your data can go to support@standly.io.