Zum Inhalt springen
← Back to homepage

Privacy Policy

Last updated: August 2026

This is a courtesy translation. In case of any discrepancy between this English version and the German version, the German version prevails. The authoritative text is available at app.agile-forge.com/datenschutz.

1. Controller

The controller within the meaning of the GDPR is:
Philip Müller
Bandelstraße 5, 10559 Berlin
Email: info@agile-forge.com

Philip Müller is a small business owner pursuant to Section 19 UStG (German VAT Act).

2. Two Roles: Controller and Processor

For your account and subscription data (name, email, subscription status, payment transactions), we act as the controller in our own right — this privacy policy fully governs this category.

For your project content (decisions, risks, stakeholder details, requirements, change requests, and other free-text entries in the project record), you or your organization are the controller, and we act as a processor pursuant to Art. 28 GDPR. This applies in particular when you enter personal data of third parties (e.g. names or contact details of stakeholders or team members) — you yourself are responsible for the lawfulness of these entries (such as information obligations towards the affected third parties).

3. What Data We Process

When you visit and use Anvio (app.agile-forge.com), we process the following personal data:

  • When creating an account: name, email address, chosen password (encrypted)
  • When using the tools: inputs you make in the tools (e.g. team size, methodology, descriptions). These are transmitted to Anthropic for AI-assisted output generation.
  • When purchasing a subscription: payment data (credit card, SEPA), billing address. These are processed directly by Stripe — we do not receive or store complete payment data.
  • Technical data: IP address, browser type, device, pages visited, time spent (via Vercel Analytics — cookieless and without cross-device recognition, but only after your statistics consent).

Your name, email address and — when taking out a subscription — payment data are required in order to enter into the contract. Without them, we cannot provide an account or a subscription. All other information, in particular the content of your project record, is provided voluntarily.

4. Purpose of Processing

We process your data to:

  • Provide and improve Anvio
  • Authenticate you and manage your account
  • Process payments and subscriptions
  • Manage the waitlist and grant beta access, including notifying you when you are admitted
  • Analyze usage to improve the product (anonymized)
  • Fulfill legal obligations

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) or pre-contractual measures taken at your request for the waitlist, compliance with legal obligations (Art. 6(1)(c) GDPR) for retention required under tax and commercial law, consent (Art. 6(1)(a) GDPR) for analytics and all cookies that are not technically necessary, and legitimate interests (Art. 6(1)(f) GDPR) for technical operation and the prevention of abuse (e.g. server logs).

5. Storage Period

Account data is stored for as long as your account is active. Via the "Delete data" button in your account settings, you can delete your data yourself at any time; upon full account deletion, a deletion cascade removes your data from all systems we use (project record, history, integration connections, inbox, preferences), unless statutory retention obligations apply (e.g. invoices: 10 years).

Server logs: When you access our application, technical log data is generated at our hosting provider (IP address, timestamp, requested path, status code). It serves operation, troubleshooting, and defense against attacks (Art. 6(1)(f) GDPR) and is automatically deleted after 1 day. In our own application logs, we do not use real names or email addresses, but exclusively pseudonymous identifiers. For technical reasons, these logs are not part of the deletion cascade; due to the short retention period, they expire within 1 day anyway.

Inbox: Emails you forward to your personal Anvio inbox address remain in a queue for up to 30 days until you confirm or discard them; after that, they are automatically deleted. They may contain details about third parties (e.g. senders or persons mentioned in the text). The legal basis is our legitimate interest in project documentation (Art. 6(1)(f) GDPR); content is only adopted once you explicitly confirm it.

Waitlist: Your email address is stored until you are admitted or you unsubscribe, but no longer than the end of the beta phase. You can unsubscribe at any time, informally, at info@agile-forge.com.

No automated decision-making: Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place. AI-generated outputs are suggestions and working aids; content enters your project record only if you explicitly confirm it.

6. Disclosure to Third Parties — Processors

To provide our service, we use the following third-party providers. The respective data processing agreement (DPA) status is noted directly for each provider:

Anthropic PBC — AI processing (DPA concluded)

Processing of tool inputs for output generation. Registered in: USA. Transfer: Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR. Anthropic stores inputs for up to 30 days for safety purposes. Under the currently applicable Commercial Terms, Anthropic does not use these inputs to train its AI models; this assurance is based on the contractual agreement and is not technically enforced by us. anthropic.com/privacy

Vercel Inc. — hosting, infrastructure & analytics (DPA concluded)

Hosting and performance analysis via Vercel Analytics & Speed Insights (cookieless, without cross-device recognition; nevertheless only loaded after your statistics consent). Registered in: USA. Application region: Frankfurt (EU, fra1). Transfer: SCC. vercel.com/legal/privacy-policy

Clerk Inc. — authentication & user management (DPA concluded)

Registered in: USA. Transfer: SCC. clerk.com/privacy

Stripe Inc. — payment processing (DPA concluded)

Registered in: USA. Transfer: SCC. stripe.com/privacy

Upstash Inc. — data storage (history, sessions, settings) (DPA concluded)

Storage of tool history, project profile, session data (e.g. Planning Poker), and settings. Registered in: USA. Data storage region: Frankfurt (EU). Transfer: EU-US Data Privacy Framework. upstash.com/trust/privacy.pdf

Neon Inc. — database for the project record (DPA concluded)

Storage of structured project record entries (decisions, risks, stakeholders, requirements). Region: Frankfurt (EU). neon.com/dpa

Resend — email sending and receiving (DPA concluded)

Sending: reminder and quick-capture emails that you trigger yourself. Receiving: emails you forward to your personal Anvio inbox address are received by Resend and transmitted to us. These emails may contain details about third parties (senders, persons mentioned in the text); they then remain in our queue for up to 30 days until you confirm or discard them (see Section 5). Transfer: EU-US Data Privacy Framework. resend.com/legal/dpa

Pusher — real-time communication (DPA concluded)

Transmission of live session data for Planning Poker (participant names, estimates — no project content). pusher.com/legal/data-protection

Slack Technologies — team integration (only relevant if the integration is enabled)

Sending AI-generated status updates to a Slack channel you connect, incoming messages via the /anvio slash command. Registered in: USA. Transfer: SCC. slack.com/terms-of-service/data-processing

Microsoft Corporation (Azure Bot Service) — Teams integration (only relevant if the integration is enabled)

Sending AI-generated status updates and incoming messages via a Microsoft Teams bot. Transfer pursuant to the Microsoft data processing agreement. aka.ms/DPA

Atlassian Corporation (Jira) — project integration (only relevant if the integration is enabled)

Import of Jira boards/issues into the project record, export of requirements and change requests as Jira issues. Registered in: USA/Australia. atlassian.com/legal/data-processing-addendum

Google Ireland Ltd. — Google Analytics 4 (DPA concluded)

Purpose: reach measurement for SEO and marketing analysis. Legal basis: exclusively your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act)). Without consent, Google Analytics is not even loaded technically — no cookies are set and no data is transmitted to Google. Withdrawal: at any time via "Cookie settings" in the footer; the measurement stops immediately, without you having to reload the page. Recipients: Google Ireland Ltd. (contracting party, Ireland) and Google LLC (USA). Third-country transfer: a transfer to the USA takes place. Google LLC is certified under the EU-US Data Privacy Framework; the transfer is based on the adequacy decision of the EU Commission of 10 July 2023 (Art. 45 GDPR). Storage period: the retention of user and event data in Google Analytics is limited to 2 months. IP anonymization is active server-side by default in GA4; IP addresses are not stored permanently. Cross-device tracking ("Google Signals") is disabled, as is the collection of location data at city level and the sharing of data with Google for its own purposes. business.safety.google/privacy

Google Ireland Ltd. — Google Ads (DPA concluded)

Purpose: measuring the success of our advertisements and — with the corresponding consent — personalized advertising. Our Analytics account is linked to a Google Ads account. Legal basis: exclusively your consent in the "Marketing" category (Art. 6(1)(a) GDPR, Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act)). This consent is separate from the statistics consent: if you only allow "Statistics", no advertising signals are transmitted for you. Implementation: we use Google Consent Mode v2. Without marketing consent, the signals ad_storage, ad_user_data, and ad_personalization remain permanently set to "denied"; without any consent, no Google script is loaded at all. Withdrawal: at any time via "Cookie settings" in the footer, individually per category. Third-country transfer: Google LLC (USA), based on the adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR). business.safety.google/privacy

7. Your Rights

You have the right to:

  • Access to your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR). The lawfulness of processing carried out until withdrawal remains unaffected.
  • Lodge a complaint with a supervisory authority — the competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information)

Notice of your right to object: Where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR — in our case the server logs and the inbox queue), you may object to that processing at any time on grounds relating to your particular situation. A message to info@agile-forge.com is sufficient; no particular form is required.

You can retrieve most of your data yourself at any time: in the settings, under "Export data", you will find a complete download of your project record, your history, your open items, and your master data (Art. 15 and Art. 20 GDPR).

For all other requests regarding your rights, contact: info@agile-forge.com. We respond to requests within the statutory period of one month (Art. 12(3) GDPR).

8. Cookies

We distinguish three categories:

  • Necessary — always active, permitted without consent (Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act)): session cookie for login via Clerk, your language setting, the storage of your cookie decision itself, and unfinished tool inputs so that an interrupted dialogue can be resumed. These drafts are stored exclusively in your browser, are not transmitted to us, and are discarded automatically after 24 hours.
  • Statistics — only with your consent: Google Analytics 4 as well as Vercel Analytics and Speed Insights for reach and performance measurement.
  • Marketing — only with your consent: measurement of advertising success and personalized ads via the link with Google Ads.

On your first visit, we show you a cookie banner in which you can opt in or out of "Statistics" and "Marketing" individually. Consent to one category is not consent to the other. You can change or fully withdraw your choice at any time via the "Cookie settings" link in the footer; your previous selection is pre-filled there, so you can revoke individual purposes without losing the others.

If you decline both categories, no Google script is loaded — in that case, no connection to Google is established at all. If you only allow "Statistics", we explicitly signal via Google Consent Mode v2 that no advertising consent has been given. A withdrawal takes effect immediately, without you having to reload the page.

9. Changes to This Privacy Policy

We reserve the right to update this privacy policy as needed. The current version is always available at app.agile-forge.com/datenschutz.

Legal notice (German) · Privacy · Terms (German) · Beta terms · © 2026 Agile Forge