Privacy Policy

What Queuebird stores, and what it never stores.

Effective date: 2026-07-29

What Queuebird stores

Queuebird stores PR metadata (owner/repo/number, title, age, size, CI state, review and approval state, resolved-thread counts), GitHub logins, Slack user/channel/workspace IDs, Queuebird-native review state (looks, snoozes, SLA timers), and minimal usage events (which feature was used and when — never any content). To operate each installation, Queuebird also stores workspace connection data: the workspace's Slack bot token (encrypted at rest with AES-256-GCM), install metadata (the installing user's Slack ID, bot IDs, granted scopes), and the ID of the connected GitHub App installation. This data is used solely to provide and improve the review queue and is never sold, shared with third parties, or used for anything else — except where legally compelled.

Queuebird never stores your source code, your diffs, or the bodies of your Slack messages. It only keeps the booleans and metadata it derives — for example, when a PR is mentioned with a note, only a has_note flag is kept; the note text is parsed in memory and never stored.

The waitlist

The only data the waitlist collects today is your email address and an ISO timestamp, stored in Cloudflare Workers KV. It is used solely to notify you at launch, is never sold or shared, and is deletable on request — email [email protected]. The legal basis is your consent (GDPR Art. 6(1)(a)), given when you submit the form and withdrawable at any time by requesting deletion.

Subprocessors

OVHcloud — application hosting: the Queuebird service and its database run on OVHcloud infrastructure in Warsaw, Poland (EU). Cloudflare — for this site: Pages hosting, Workers KV, Turnstile anti-abuse, Email Routing, and cookie-free Web Analytics (see "Analytics" below); for the app: DNS and TLS in front of Queuebird's API endpoint. This policy will be updated before any new subprocessor is put in use.

Hosting & data location

Workspace data — the PR metadata and review state described above — is stored on OVHcloud infrastructure in Warsaw, Poland, inside the EU, and does not leave it. Your waitlist email lives in Cloudflare Workers KV on Cloudflare's global edge network, which is not EU-pinned; those transfers outside the EEA are protected by Cloudflare's certification under the EU-U.S. Data Privacy Framework and additionally by the EU Standard Contractual Clauses incorporated in Cloudflare's data-processing terms.

Children

Queuebird is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email [email protected] and we will delete it.

Analytics

This site runs cookie-free Cloudflare Web Analytics at launch — privacy-friendly, with no cross-site tracking.

Data retention

Workspace data (the PR metadata and review state described above) is kept while Queuebird is installed in your workspace and deleted within 14 days of uninstall, or sooner on request. The workspace's Slack token is wiped immediately on uninstall or token revocation — it never waits for the 14-day purge. Waitlist emails are kept until the launch notification is sent, then deleted, or removed earlier on request. Aggregate, non-identifying site analytics are retained by Cloudflare per its Web Analytics terms.

No LLM training

Queuebird does not use your Slack or GitHub data to train machine-learning models.

Your rights & contact

For the waitlist and site analytics, the data controller is Ernestas Zabarauskas, an independent software developer registered for individual activity in Lithuania. For data processed inside an installed workspace (PR metadata and members' Slack/GitHub identifiers), your workspace is the controller and Queuebird acts as its processor — handling that data only to provide the service, on the workspace's instructions. You have the right to access, rectify, erase, restrict, object to the processing of, and port your data, and to withdraw consent at any time. To exercise any of these — or for anything else — email [email protected]. You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (vdai.lrv.lt) or your local supervisory authority.

Changes to this policy

When this policy changes, this page and its effective date are updated; material changes will be noted here.

Your team's PR reviews, finally in one queue — in Slack.

© 2026 Queuebird. Not affiliated with Slack or GitHub.