Invalid Date
Privacy Policy
IdeaRoost, LLC Lafayette, Louisiana idearoost.com
Effective Date: April 20, 2026 Last Updated: April 20, 2026
Overview
IdeaRoost, LLC (“IdeaRoost,” “we,” “us,” or “our”) is committed to protecting the privacy of our clients and users. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our services, including:
- The Sprint Planning Agent — an AI-powered Azure DevOps extension and web application
- The IdeaRoost website at idearoost.com
- Any related tools, APIs, or services provided by IdeaRoost
By using our services, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Information You Provide
When you contact us through our website or engage IdeaRoost for services, we may collect:
- Name and email address submitted through contact forms
- Company name and role
- Information provided during discovery calls or engagements
1.2 Azure DevOps Data
When you use the Sprint Planning Agent, the application accesses the following data from your Azure DevOps organization via the Azure DevOps REST API, using permissions you explicitly grant:
- Work item titles, descriptions, and metadata from your project backlog
- Sprint history and velocity data
- Team capacity information
- User identity information (display name, email) to verify Project Administrator group membership
IdeaRoost does not store your Azure DevOps backlog data. Data is retrieved at the time of your request, processed, and returned to you. It is not written to any IdeaRoost database or retained after your session ends.
1.3 Authentication Information
- Azure AD / Microsoft Entra ID — when signing in via Microsoft authentication, we receive your Microsoft account display name, email address, and user identifier. This is used solely to verify your identity and Azure DevOps group membership.
- Azure DevOps Extension SDK — when using the extension inside Azure DevOps, your user identity and organizational context are provided automatically by the Azure DevOps platform. We do not store this information beyond the current session.
1.4 Usage Information
We may collect standard web server logs including IP addresses, browser type, and pages visited on idearoost.com for security and operational purposes. We do not use third-party analytics tracking on our website.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Sprint Planning Agent and related services
- Verify that users have appropriate Azure DevOps Project Administrator permissions before allowing access to sprint planning functions
- Transmit your Azure DevOps data to the Anthropic Claude API for AI analysis (see Section 3)
- Respond to inquiries submitted through our website contact form
- Communicate with clients about their engagements
- Comply with legal obligations
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Third-Party AI Services — Anthropic Claude API
The Sprint Planning Agent uses the Anthropic Claude API to perform AI analysis on your backlog data, retrospective notes, and code review submissions.
What this means for your data:
- Work item data, retrospective content, and code submitted for review is transmitted to Anthropic’s API servers for processing
- Anthropic’s data handling and privacy practices apply to data transmitted to their API
- IdeaRoost uses Anthropic’s API under their standard commercial terms
- You can review Anthropic’s privacy policy at anthropic.com/privacy
What IdeaRoost does:
- We transmit only the data necessary to fulfill your specific request
- We do not transmit sensitive credentials, secrets, or access tokens to the Anthropic API
- We do not use your data to train AI models
- We implement rate limiting to minimize unnecessary data transmission
If your organization has data residency requirements or restrictions on transmitting data to third-party AI services, please discuss this with IdeaRoost before deploying the Sprint Planning Agent.
4. Data Storage and Retention
Azure DevOps backlog data — not stored by IdeaRoost. Retrieved on demand and returned to you.
Contact form submissions — retained for a reasonable period to respond to your inquiry and for business records. We do not retain contact information indefinitely.
Authentication tokens — stored in your browser’s session storage during your active session only. Cleared when you close your browser or log out.
Engagement records — IdeaRoost retains business records related to client engagements (contracts, invoices, communications) in accordance with standard business and legal requirements.
5. Data Security
IdeaRoost takes reasonable technical and organizational measures to protect your information, including:
- All secrets and API keys stored in Azure Key Vault or GitHub Secrets — never in application code
- HTTPS encryption for all data in transit
- Azure DevOps Personal Access Tokens scoped to minimum required permissions
- Access to client systems limited to the duration of the engagement and revoked upon completion
No method of transmission or storage is 100% secure. We cannot guarantee absolute security but commit to promptly notifying affected parties in the event of a data breach involving personal information.
6. Your Rights and Choices
Depending on your location, you may have rights regarding your personal information, including the right to access, correct, or request deletion of information we hold about you.
To exercise these rights or ask questions about your data, contact us at:
We will respond to verifiable requests within 30 days.
7. Children’s Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us and we will promptly delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date at the top of this page. We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes your acceptance of the updated policy.
9. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
IdeaRoost, LLC Lafayette, Louisiana Email: privacy@idearoost.com Website: idearoost.com
This privacy policy was last reviewed on April 20, 2026. IdeaRoost recommends consulting a licensed attorney to ensure this policy meets all applicable legal requirements for your jurisdiction.