Privacy Policy

What Queuebird stores, and what it never stores.

Effective date: 2026-08-30

What Queuebird stores

Queuebird stores PR metadata (owner/repo/number, title, age, size, CI state, review and approval state, resolved-thread counts), GitHub logins, Slack user/channel/workspace IDs, Queuebird-native review state (looks, snoozes, SLA timers, and a per-PR activity history: who parked, hid, restored, marked a PR urgent, or re-added a tracked PR, which reminders were sent or withheld — and why — and when review cycles started), and minimal usage events (which feature was used and when — never any content). To operate each installation, Queuebird also stores workspace connection data: the workspace's Slack bot token (encrypted at rest with AES-256-GCM), install metadata (the installing user's Slack ID, bot IDs, granted scopes), and the ID of the connected GitHub App installation. This data is used solely to provide and improve the review queue and is never sold, shared with third parties, or used for anything else — except where legally compelled.

Queuebird never stores your source code, your diffs, or the bodies of your Slack messages. It only keeps the booleans and metadata it derives — for example, when a PR is mentioned with a note, only a has_note flag is kept; the note text is parsed in memory and never stored. In channels it has been invited to and set up in, Queuebird processes messages to spot PR links and notes; the /qb backfill command, which that channel's maintainers or a workspace admin can run, additionally reads its recent history on demand, solely to find untracked PR links — the messages themselves are never kept.

Billing

Paddle is our merchant of record. Paddle sells the subscription to you, runs the checkout, and handles payment, tax and invoicing. Your card details and billing address go to Paddle directly, which collects them as its own controller — they never reach Queuebird, which never sees or stores a card number. Paddle's handling of that data is covered by Paddle's privacy policy.

What Queuebird itself stores about a subscription is only what it needs to run seats and entitlements: the Paddle customer and subscription IDs, the billing cycle and renewal date, the seat count and unit price, the subscription status, and the raw subscription webhooks Paddle sends us, which can carry the purchasing user's Slack ID. Those webhook records are deleted on the same 90-day schedule as other telemetry, and their contents are emptied immediately if the workspace they belong to has already been deleted.

The waitlist

The only data the waitlist collects today is your email address and an ISO timestamp, stored in Cloudflare Workers KV. It is used solely to notify you at launch, is never sold or shared, and is deletable on request — email support@queuebird.dev. The legal basis is your consent (GDPR Art. 6(1)(a)), given when you submit the form and withdrawable at any time by requesting deletion.

Subprocessors

OVHcloud — application hosting: the Queuebird service and its database run on OVHcloud infrastructure in Warsaw, Poland (EU). Cloudflare — for this site: Pages hosting, Workers KV, Turnstile anti-abuse, Email Routing, and cookie-free Web Analytics (see "Analytics" below); for the app: DNS and TLS in front of Queuebird's API endpoint. This policy will be updated before any new subprocessor is put in use.

Hosting & data location

Workspace data — the PR metadata and review state described above — is stored on OVHcloud infrastructure in Warsaw, Poland, inside the EU, and does not leave it. Your waitlist email lives in Cloudflare Workers KV on Cloudflare's global edge network, which is not EU-pinned; those transfers outside the EEA are protected by Cloudflare's certification under the EU-U.S. Data Privacy Framework and additionally by the EU Standard Contractual Clauses incorporated in Cloudflare's data-processing terms.

Children

Queuebird is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email support@queuebird.dev and we will delete it.

Analytics

This site runs cookie-free Cloudflare Web Analytics at launch — privacy-friendly, with no cross-site tracking.

Data retention

Workspace data (the PR metadata and review state described above) is kept while Queuebird is installed in your workspace and deleted within 14 days of uninstall, or sooner on request. On top of that, closed-out data expires on a rolling basis while you're installed: archived team PRs and their history, archived personal tracking entries, and usage events, are deleted after 90 days. The workspace's Slack token is wiped immediately on uninstall or token revocation — it never waits for the 14-day purge. Waitlist emails are kept until the launch notification is sent, then deleted, or removed earlier on request. Aggregate, non-identifying site analytics are retained by Cloudflare per its Web Analytics terms.

No LLM training

Queuebird does not use your Slack or GitHub data to train machine-learning models.

Your rights & contact

For the waitlist, billing and site analytics, the data controller is Ernestas Zabarauskas, an independent software developer registered for individual activity in Lithuania. For data processed inside an installed workspace (PR metadata and members' Slack/GitHub identifiers), your workspace is the controller and Queuebird acts as its processor — handling that data only to provide the service, on the workspace's instructions. Where Queuebird is the controller, the legal bases are performance of our contract with you (running the service you installed and its subscription), your consent (the waitlist), and our legitimate interests in keeping the service secure and working (minimal, content-free usage telemetry). Where your workspace is the controller, Queuebird processes on its instructions under the workspace's own basis. You have the right to access, rectify, erase, restrict, object to the processing of, and port your data — for portability, run /qb export in Slack for the PRs and review history you can see — and to withdraw consent at any time. To exercise any of these — or for anything else — email support@queuebird.dev. You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt) or your local supervisory authority.

Changes to this policy

When this policy changes, this page and its effective date are updated; material changes will be noted here.

Your team's PR reviews, finally in one queue — in Slack.

© 2026 Queuebird. Not affiliated with Slack or GitHub.