Privacy Policy
Last updated September 17, 2026
Gamify reads activity from services you connect and turns it into points. That means we handle data about what you do in other tools, which is exactly the kind of thing you should expect a clear answer about. This page is that answer: what we collect, why, who else sees it, and how to get a copy of it or get rid of it. Questions go to gamifysaas@gmail.com.
1.Who we are
Gamify is operated by [LEGAL ENTITY NAME], [REGISTERED POSTAL ADDRESS]. For the purposes of the UK GDPR and the EU GDPR, [LEGAL ENTITY NAME] is the data controller for the personal data described in this policy.
This policy covers the Gamify web application, its public read API, and the embeddable leaderboard. If you have any question about it, write to gamifysaas@gmail.com.
2.What we collect
We collect only what the product needs in order to work. That is:
- Account details. Your email address, the display name you choose, and your password. Passwords are handled entirely by our authentication provider and are stored only as a salted hash — we never see or store the password itself.
- Workspace membership. Which workspace you belong to, whether you are an administrator of it, and — if you joined by invitation — a record that the invitation was redeemed.
- Connected account credentials. When you connect a service, we store the access and refresh tokens it issues, along with your username or account identifier on that service. Tokens are encrypted before they are written to the database.
- Activity data. The events we read from the services you connect — see the next section for exactly what this means.
- Scores derived from that activity. Your point transactions and the rule or adjustment behind each one, your current and longest streak, the badges you have earned, and the level those points add up to.
- API and embed keys. If an administrator creates one, we store a hash of the key, the name given to it, and when it was last used. The key itself is shown once at creation and never stored.
- Technical logs. Our hosting provider records standard server logs — IP address, timestamp, requested URL, user agent — for security and debugging.
We do not run advertising trackers, third-party analytics, or any profiling beyond the points, levels, and badges the product visibly exists to calculate.
3.Activity from the services you connect
Gamify works by reading activity from tools you already use and turning it into points. You choose which services to connect, one at a time, and you can disconnect any of them whenever you like. Today those services are: GitHub, Strava, Trello, Todoist, Linear, Slack, Jira (Atlassian) — plus any custom API connector your workspace administrator configures.
Access is read-only. We request the narrowest permissions each service offers for reading your recent activity. We never post, comment, commit, create, or modify anything on your behalf.
For each event we read, we keep the original response from the service alongside a normalized record of it: what kind of event it was, when it happened, its identifier on the source service, and the fields your workspace rules are scored against. We keep the original because a scoring rule may change later and we need to be able to re-score accurately without asking the service for your history again.
When you disconnect a service, we delete its stored tokens immediately and stop reading from it. Activity already collected, and the points earned from it, remain unless you ask us to delete them — see your rights below.
4.How we use it
- To create and maintain your account and sign you in.
- To read activity from the services you have connected and apply your workspace's scoring rules to it.
- To show you your points, level, streak, and badges, and to rank members of a team workspace on a leaderboard.
- To send you account email — confirming your address and resetting your password.
- To operate the public read API and leaderboard embed, if your administrator enables them.
- To keep the service secure, diagnose faults, and prevent abuse.
We do not sell your personal data. We do not share it with advertisers. We do not use it to train machine learning models.
5.What other people can see
This depends on the kind of workspace you are in, and it is worth being precise about.
In an individual workspace, you are the only member. Nobody else sees your points, activity, or connected accounts.
In a team workspace, every member can see every other member's display name, total points, and level on the shared leaderboard. Administrators of that workspace can additionally see your activity history, your individual point transactions, which services you have connected, and the username you use on them. Administrators can also adjust your points manually. They cannot see your password or the contents of your connected-account tokens.
If an administrator creates an embed key, the leaderboard — display names, points, and levels — can be displayed on any page that key is placed on, including pages visible to people outside your workspace.
6.Legal bases for processing
If you are in the UK or the European Economic Area, we rely on the following legal bases:
- Performance of a contract. Running your account, reading the activity you asked us to read, and calculating the scores that are the entire point of the service.
- Consent. Each service you connect is a separate, explicit choice made through that service's own authorization screen. You may withdraw it at any time by disconnecting the service.
- Legitimate interests. Keeping the service secure, preventing abuse, and diagnosing faults — balanced against your rights, and limited to what those purposes actually require.
8.How long we keep it
- Account details, points, streaks, and badges: for as long as your account exists.
- Connected-account tokens: until you disconnect that service, at which point they are deleted.
- Raw and normalized activity events: for as long as your account exists, because they are what points can be recalculated from if a rule changes.
- Server logs: retained by our hosting provider on their standard schedule, which is currently about 30 days.
When an account is deleted, the personal data associated with it is deleted within 30 days, except where we are required to retain something longer by law.
9.Your rights and choices
You have the right to:
- Access the personal data we hold about you, and receive a copy of it in a portable format.
- Correct anything inaccurate — your display name is editable in the app, and we will correct anything else on request.
- Delete your account and the data associated with it.
- Withdraw consent for any connected service, at any time, by disconnecting it under Connections.
- Object to or ask us to restrict processing based on our legitimate interests.
- Complain to your data protection authority — in the UK, the Information Commissioner's Office.
You can disconnect a service yourself at any time from the Connections page. For account deletion, data access, or a data export, email gamifysaas@gmail.com from the address on your account and we will action it within 30 days. We do not charge for this.
10.How we protect it
- Connected-account tokens are encrypted at rest with AES-256-GCM, using a key held outside the database. A copy of the database alone does not yield a usable token.
- Workspaces are isolated at the database level by row-level security, so a query made on behalf of one workspace cannot return another workspace's rows even if the application asks it to.
- API keys are stored as hashes, never in a form we could read back or reveal to anyone, including you.
- All traffic is encrypted in transit over HTTPS.
No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please write to gamifysaas@gmail.com rather than disclosing it publicly, and we will respond as quickly as we can.
12.International transfers
Our infrastructure providers operate globally, so your data may be processed in a country other than your own, including the United States. Where data is transferred out of the UK or the EEA, it is covered by the transfer mechanisms those providers maintain, such as the European Commission's Standard Contractual Clauses.
13.Children
Gamify is not intended for children. You must be at least 16 years old to create an account. If you believe a child has given us personal data, write to gamifysaas@gmail.com and we will delete it.
14.Changes to this policy
If we change this policy we will update the date at the top of this page. Where a change materially affects how we handle your data — a new category of data, a new purpose, or a new subprocessor — we will email account holders before it takes effect rather than relying on you to notice.
15.Contact
For any privacy question or to exercise any of the rights above, write to gamifysaas@gmail.com.
[LEGAL ENTITY NAME]
[REGISTERED POSTAL ADDRESS]
See also our Terms of Service.