Skip to content

Security & Privacy

DubPlanner sits alongside your issue tracker rather than replacing it. Your issue tracker stays the source of truth, and DubPlanner keeps only the small amount of data it needs to plan on top of it.

This page explains, in plain terms, what we store, what we never store, and how you can review or remove it.

Your issue tracker stays the source of truth

Section titled “Your issue tracker stays the source of truth”

The single most important thing to know: DubPlanner does not keep a copy of your issues.

  • Issue titles, descriptions, comments, estimates, labels, status, assignees, projects and milestones are read live from your issue tracker each time you use DubPlanner
  • None of that content is written to DubPlanner’s own storage
  • When you schedule a ticket into a week, that scheduling is written back to your issue tracker as a label on the issue — so the plan lives in your tracker, not locked inside DubPlanner

If you stopped using DubPlanner tomorrow, your issues and your plan would still be in your issue tracker, intact.

  • Organization name and domain
  • Which issue tracker workspace you’ve connected
  • Optional details you choose to provide, such as industry, company size and a contact email
  • Setup progress, so we don’t ask you to complete onboarding twice

For each member: name, email, avatar image link, role (admin or member), whether they’re active, and when they joined and were last seen. These are copies of what your issue tracker or sign-in provider gives us, kept so the app can show people on the board without asking your tracker again every time.

This is work that has no home in your issue tracker, so DubPlanner keeps it:

  • Availability and time off — start and end dates, the type of absence, an optional title, and optionally which project it applies to
  • Custom views — the view’s name and which projects or initiative it draws from
  • What-if scenarios — the scenario name, and the changes you’ve made inside it (moved weeks, reassignments, milestone changes, removed tickets) plus any placeholder tickets you’ve sketched in
  • Preferences — your favourite projects and view settings

The only free text DubPlanner stores here is text you typed into DubPlanner yourself: scenario and view names, absence titles, and placeholder ticket titles.

  • Your plan, trial dates, subscription status and renewal date
  • Reference IDs that link your account to our payment provider
  • An encrypted access token for your issue tracker, so DubPlanner can act on your behalf
  • Short-lived sign-in codes that are used once and then discarded

If you contact us through the app, we keep your message, your email, your workspace name and the IP address the request came from, so we can respond and prevent abuse.

While you and your teammates have a project open, DubPlanner passes small real-time signals between browsers — who’s currently viewing, and that a given ticket moved. These carry identifiers and scheduling fields only, never ticket titles or descriptions, and they aren’t retained after the session.

  • Your password. You sign in through your issue tracker using OAuth. Your password is never entered into DubPlanner and never reaches us.
  • Your card or bank details. Checkout and billing are handled entirely by our payment provider. Card numbers never touch DubPlanner.
  • Your issue content. No titles, descriptions, comments or attachments are saved to our storage.
  • Files or documents. DubPlanner has no file uploads.
  • Your messages or emails. DubPlanner doesn’t read or record communications.

DubPlanner acts as you, not as a superuser:

  • You can only see and change what your issue tracker account already lets you see and change
  • If you can’t edit an issue in your tracker, you can’t edit it in DubPlanner
  • Team and project access is enforced by your issue tracker’s own permission model

Your organization’s data is kept separate from every other organization’s, and requests that reach across that boundary are rejected.

All data is encrypted in transit between your browser and DubPlanner, and encrypted at rest in storage. Access tokens are additionally encrypted before they are stored, and are only ever used server-side — they are never sent to your browser.

  • Your data is retained while your account is active
  • Real-time collaboration signals are transient and expire on their own
  • Backups are kept for a short period for disaster recovery, then rotated out
  • You can ask us to delete your data at any time by contacting support@dubplanner.com

You can cut off DubPlanner’s access at any time from your issue tracker’s account settings, under authorized or connected applications. Find DubPlanner and revoke access.

Once revoked, DubPlanner can no longer read or write anything in your tracker, and the stored token becomes useless.

You can also disconnect from inside the app:

  1. Open DubPlanner
  2. Go to Settings
  3. Click Disconnect
  4. Confirm

This removes the stored token from DubPlanner.

If you believe you’ve found a security vulnerability, please report it privately to support@dubplanner.com rather than in a public channel. We appreciate responsible disclosure and will acknowledge your report.

  • ✅ Your issues stay in your issue tracker — DubPlanner keeps no copy
  • ✅ Your plan is written back to your tracker, so it’s yours to keep
  • ✅ No passwords, no card details, no file uploads, no message logs
  • ✅ DubPlanner only ever does what your own tracker permissions allow
  • ✅ Data is encrypted in transit and at rest
  • ✅ You can revoke access or request deletion at any time