Privacy
This describes how Fervio handles your data when you connect GitHub or Linear, at fervio.co. It is written from the code that actually runs, not from intent. Last updated 26 September 2026.
What Fervio stores
Everything below lives with Cloudflare, in the region Cloudflare assigns: most of it in Cloudflare's key-value storage, and the account record in Cloudflare's SQL database (D1). Nothing else is kept.
| What | Why | How long |
|---|---|---|
| Your GitHub and Linear access tokens, and the refresh tokens that renew them | To read and write your issues on your behalf. They stay on the server and are never sent to the browser. Each signed-in browser session also holds a copy of the access token it signed in with, but not the refresh token. | Until you sign out on any device, and no longer than 7 days after Fervio last used them. A session's copy lasts until that browser signs out, and no longer than 7 days |
| A note that you signed out | So that a request still running when you sign out cannot put back the tokens that signing out discarded. It holds only the time you signed out, filed under a one-way hash of your account rather than your username. | 7 days after you sign out |
| Your GitHub and Linear usernames, and the IDs that do not change when you rename | To show who you are, to recognise you when you sign in again, and to record who owns and who was invited to a map. | Until you ask for deletion |
| Your account record | To sign you in and to show what you agreed to: when the account was created, which version of the terms you accepted and when, and which GitHub or Linear identity signs in to it. | Until you delete the account |
| One email address, so Fervio can reach you | For messages about the account itself: a sign-in from a device you have not used before, billing, and changes to the terms or the service. Read from GitHub or Linear when you sign in. Product news is a separate switch that stays off until you turn it on. Change the address, or remove it, in settings. | Until you remove it, or delete the account |
| Your maps: their names, which repositories or teams they read, and the card order | The map layout is Fervio's own; GitHub has nowhere to keep it. | Until the map is deleted |
| Who you invited, and their role | To decide who may open or edit a map. | Until the member is removed or the map is deleted |
| When you signed in, and how many times | To know how many people are using Fervio. The username of the newest account is also kept with whether the team was told about it. | Until you ask for deletion. The newest account's username: until the next account is created |
| A share snapshot, if you publish one | So that a share link opens without a sign-in. This is a copy of the map as it stood when you published it: each card's number, title, state, assignee, labels, estimate, start and due dates, sub-task progress, repository or team, the cards it waits on, where it sits on the map, and a link to the issue; the names and dates of the journeys, steps, sprints and release rows, and each release row's description; the card order; and your username as the person who shared it. Issue descriptions are never included. How many times the link was opened is counted alongside. | 90 days, or until the link is revoked |
| Each AI client you connect | So that it can read your maps and leave proposals. Fervio keeps the client's name and web address, when you allowed it, and a hashed form of each token it holds, never the token itself. | Until you disconnect it in Settings, and no longer than 90 days after it last renewed its access |
| A proposal from your AI client, if it leaves one | So that you can review it before anything is written. It holds the client's name, its summary and reasons, the titles it proposes for new journeys, steps and cards and the descriptions for new cards, and the number and title of each existing card or step it would move. Only you can see it. | Until you apply or dismiss it, and no longer than 14 days |
| Your plan, and AI usage this month | To apply the limits of your plan, including which maps stay editable and who holds an editor seat. A purchase made through GitHub Marketplace is also recorded with your GitHub username and the plan's name; a payment notice from Polar that Fervio cannot match to an account is kept with the email address Polar sent, so that it can be matched by hand. | Plan: until it changes. Purchase and unmatched payment records: one year. AI count: resets monthly, and each month's count is kept for about two months |
| That you asked to hear when Pro opens, if you did | So that Fervio can write to you once, when Pro goes on sale. The record is the date you asked; the address comes from the contact address above. | Until you leave the list, or Pro opens |
| Short-lived working records | To finish a step in progress: the state of a sign-in or connection round trip, a link sent by email to confirm deleting the account, and answers from GitHub kept briefly so they are not asked twice — which repositories an installation covers, and your permission level on a repository — and a note that GitHub has just refused to renew a token. | Minutes; an hour at most |
What Fervio never touches
- Your source code. Fervio is a GitHub App without permission to read file contents, so no token it holds can reach your code, and GitHub's consent screen lists the permissions it does have. The permissions page explains each one.
- A lasting copy of your issue content. Titles, states and descriptions are read from GitHub and Linear each time you open a map or a card, and are not kept, with two exceptions: a share snapshot you publish yourself, and the titles of the cards and steps a proposal from your AI client would move, kept with that proposal for at most 14 days.
- Analytics. There are no trackers, no advertising pixels and no usage-measurement services. A Content-Security-Policy blocks the page from calling any external host.
Cookies
Two, both strictly necessary, neither used for tracking. A session cookie identifies your sign-in for 7 days, and a short-lived cookie guards the sign-in round trip for 10 minutes. Both are HttpOnly, so scripts on the page cannot read them.
Who else is involved
- GitHub and Linear — the source of every issue you see, and an identity you can sign in with.
- Cloudflare — serves the site and holds the storage described above.
- Polar — handles payment if you subscribe. Fervio never sees your card; Polar tells Fervio only which account changed plan.
- Anthropic — receives the text you type into the AI panel, and only that text, and only when you press the button. Your issues are not sent automatically.
- Resend — delivers the messages above. It receives your email address and each message; open and click tracking are turned off.
Deleting your data
Deleting a map removes its layout, its member list and any share snapshot. Signing out ends the session, discards the access and refresh tokens Fervio holds for your account, and asks GitHub or Linear to invalidate them. A browser where you are still signed in elsewhere keeps its own session until it signs out or its 7 days run out, and asks you to sign in again before it opens a map. To remove everything at once, use Delete account at the bottom of Settings — it erases your spaces, connections, AI client connections, proposals, share links and sign-in record from Fervio. Your issues and boards on GitHub and Linear are not touched. Removing a connection — or deleting the account — also revokes Fervio's access at that provider, so it disappears from your authorized applications. If that step fails, we tell you, and you can revoke it yourself from GitHub (Settings → Applications) or Linear (Settings → API). If anything is left that you want gone, write to [email protected].
Changes
Fervio is still changing. When what is stored changes, this page and the summary on the home page are updated together. The list above is meant to be complete, so anything new has to appear in it.