LineGuard
How it works Features Use cases Pricing Docs
Sign in Add to Linear

Privacy Policy

Effective 1 August 2026 Yogabox Tech LLP, Chennai, India [email protected]

The short version. LineGuard reads Linear webhooks to decide whether a rule should fire, then writes back to Linear. Issue titles, descriptions, comment bodies and attachments pass through memory during that check and are never written to our database. What we keep is the metadata needed to run your rules and show you an audit trail: identifiers, field names, and outcomes.

  1. Who we are
  2. What we store, at a glance
  3. Data we collect
  4. What we never store
  5. How we use data
  6. Legal bases
  7. Subprocessors and where data lives
  8. Retention and deletion
  9. Security
  10. Cookies and the website
  11. Your rights
  12. Children
  13. Changes to this policy
  14. Contact

1. Who we are

LineGuard is a product of Yogabox Tech LLP, Chennai, Tamil Nadu, India ("LineGuard", "we", "us"). We are the data controller for the personal data described here. LineGuard is an independent product and is not affiliated with, endorsed by, or sponsored by Linear Orbit, Inc.

We build, operate and support LineGuard ourselves — it is not outsourced, resold or white-labelled, and no third party administers it on our behalf. Production access is tightly restricted and granted on a least-privilege basis; the security section below sets out the controls.

2. What we store, at a glance

CategoryStored?Detail
Issue titles & descriptionsNoProcessed in memory during rule evaluation, never persisted
Comment bodies & attachmentsNoNever read into storage; attachments are never fetched
Issue identifiersYesLinear issue id and key (e.g. ENG-412) in the audit log
Field namesYesWhich fields were missing (e.g. "estimate"), never their values
Workspace & user recordsYesLinear org id/name; user name, email, Linear user id
Workflow metadataYesCached team, workflow state and label names, to build rules against
Your rulesYesRule definitions, including any comment templates you write
OAuth tokensYesEncrypted at rest with AES-256-GCM

3. Data we collect

From your Linear workspace, when an admin installs LineGuard

  • Your Linear organisation id and name.
  • OAuth access and refresh tokens for the workspace, and their expiry and granted scopes. Tokens are encrypted at rest.
  • The Linear user id of the admin who installed the app, and the installation timestamp.
  • The identity LineGuard itself acts as in your workspace, so it can recognise and ignore its own writes.

About people who sign in

  • Linear user id, display name, email address, whether the account is a workspace admin, and the last sign-in time. This comes from Linear's OAuth response, not from a form you fill in.

Workflow metadata, cached so you can build rules

  • Teams (id, key, name), workflow states (id, name, type, position), and labels and label groups (id, name, parent). These are names and identifiers, not issue content.

Rules you create

  • Rule name, target team, priority, enabled state, and the full rule definition: triggers, conditions and actions. If a rule posts a comment, the template text you author is stored as part of that rule. Do not put confidential information in a comment template.

The audit log

Every time a rule matches, we record: the rule id and its name at the time, your workspace, the Linear issue id and identifier, the webhook delivery id, whether the trigger matched, the condition outcome as { matched, missingFields } — a list of field names only — and per-action outcomes as { type, ok, error }. No field values, and no issue text, are recorded.

Operational logs

Our server logs record webhook delivery ids, event types and actions, workspace ids and error messages, for debugging and abuse prevention. They do not contain issue content. They are short-lived and not used to build any profile of you.

Payments

Paid plans are handled by Dodo Payments as our merchant of record. Dodo is the seller on record for your subscription: they take the payment, issue the invoice, and handle sales tax, VAT and GST in your jurisdiction.

Your card details go directly to Dodo and never reach us. We do not see, receive or store a card number at any point. Checkout, the billing portal, invoices and payment-method changes are all pages hosted by Dodo, not by us.

What we store is the minimum needed to know what your workspace has paid for: your Dodo customer and subscription identifiers, your plan, and its status. Your billing name, address and any tax identifiers are held by Dodo under their own privacy policy. Because Dodo is the merchant of record rather than a vendor acting on our instructions, they are an independent controller of that payment data — their policy, not this one, governs it.

4. What we never store

Linear webhooks are delivered with a snapshot of the changed issue, which does include the title and description. LineGuard reads that payload in memory to evaluate your rules, and then discards it. It is never written to the database, never copied to a third party, and never included in the audit log. We do not fetch attachments, do not read comment threads, and do not run analytics over your issue content. We do not sell personal data, and we do not use your data to train machine-learning models.

5. How we use data

  • To run the service: evaluate your rules against incoming events and write the resulting changes back to Linear as the actions you configured.
  • To show you what happened: render the audit log and rule history in the dashboard.
  • To authenticate you: sign you in and scope you to your workspace.
  • To keep the service working: debug failures, prevent abuse, and reason about capacity.
  • To contact you: service notices such as a revoked OAuth token, a breaking Linear API change, or a material change to these terms. We will not add you to a marketing list without your consent.

6. Legal bases

Where the GDPR applies, we rely on: performance of a contract (running the service your workspace installed), legitimate interests (security, abuse prevention, debugging, and service communications), and legal obligation where we must retain records. Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data for the legitimate purpose for which you provided it when installing and using LineGuard.

7. Subprocessors and where data lives

LineGuard runs entirely in the United States: the application is hosted on Render in their US West region, and the database is hosted by Neon on AWS in us-east-1 (N. Virginia). The company operating LineGuard is based in India, so personal data is accessible from India for support and operations.

SubprocessorPurposeLocation
RenderApplication hosting — runs the service that processes your webhooksUS West (USA)
NeonManaged PostgreSQL database — all stored dataAWS us-east-1 (USA)
Amazon Web ServicesUnderlying compute, storage and network for the databaseus-east-1 (USA)
Linear Orbit, Inc.The platform LineGuard integrates with; the source and destination of all issue dataPer Linear's own terms
CloudflareWeb Analytics on the public marketing pages — counts page views without cookies or fingerprinting. Not loaded in the dashboard, and it receives none of your Linear dataGlobal edge network
Dodo PaymentsMerchant of record for paid plans — takes payment, issues invoices, handles tax. Receives your card and billing details directly; receives none of your Linear dataPer Dodo's own terms

We will update this list before adding a subprocessor that handles personal data. For transfers out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses. If your organisation needs a Data Processing Agreement, email [email protected] and we will sign one.

We disclose data to no one else, except where we are legally compelled to. If we receive a lawful demand for your data, we will notify you unless we are legally barred from doing so.

8. Retention and deletion

  • Audit log: retained for 7 days on the Free plan. Paid plans retain it for the longer period published for that plan. Entries older than the retention window for your plan are deleted.
  • Rules, workspace, users and cached metadata: retained for as long as LineGuard is installed in your workspace.
  • Uninstalling: when LineGuard is removed from your Linear workspace, or you ask us to delete it, we delete your workspace record and everything linked to it — rules, users, cached metadata and audit log — within 30 days. OAuth tokens are invalidated immediately.
  • Operational logs and backups: retained no longer than 30 days, after which they age out.
  • Invoices and financial records: Indian company and tax law requires us to keep books of account and the invoices behind them for up to 8 years. Those records survive deletion of everything else, because we are not permitted to erase them. They contain your billing details and what you paid — not your rules or your audit log.

9. Security

  • Linear OAuth access and refresh tokens are encrypted at rest with AES-256-GCM. They are never logged or displayed in the dashboard.
  • Every incoming webhook is verified against Linear's HMAC-SHA256 signature and a timestamp check; unsigned or stale deliveries are rejected before any processing.
  • All traffic to LineGuard is served over TLS.
  • We request the narrowest OAuth scopes the product needs — read, write and comments:create. We deliberately do not request Linear's admin scope, so LineGuard cannot change your workspace settings, billing or membership.
  • Session cookies are HTTP-only, SameSite=Lax, Secure in production, and cryptographically signed. Every API request is scoped to the caller's workspace.
  • Production access is tightly restricted and granted on a least-privilege basis, over authenticated, encrypted connections.

LineGuard does not currently hold a SOC 2 or ISO 27001 certification, and we would rather say so than imply otherwise. If you become aware of a vulnerability, please report it to [email protected]; we will acknowledge within 2 business days. If a breach affects your data, we will notify affected workspace admins without undue delay and, where required, within 72 hours of becoming aware of it.

10. Cookies and the website

The LineGuard dashboard sets exactly one cookie, lg_session, which keeps you signed in for up to 30 days. It is strictly necessary for the service to function; there is no way to use the dashboard without it. We use no advertising cookies, no analytics cookies, and no cross-site trackers on this website or in the app. The dashboard itself loads no analytics at all.

These public marketing pages load Cloudflare Web Analytics, which counts page views without setting a cookie, without fingerprinting your browser and without building any profile of you. Loading it means your IP address is visible to Cloudflare as part of that request; we do not receive it, and we cannot identify you from anything the tool reports back to us. It is the only third-party request this website makes — the typefaces are served from our own domain rather than from a font CDN.

11. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, object to or restrict our processing, and withdraw consent. Email [email protected] and we will respond within 30 days. We will not charge you for this or make you use a special form. The one limit on erasure is the statutory financial-records retention in section 8, which we are not free to waive.

Much of this you can do yourself: workspace admins can delete rules from the dashboard, and uninstalling the app from Linear starts the deletion described in section 8. Audit-log entries age out automatically on your plan's retention schedule.

If you are in the EEA or UK you may lodge a complaint with your local supervisory authority. If you are in India, you may raise a grievance with us first at the address above; our contact email is also our grievance channel under the Digital Personal Data Protection Act, 2023.

If your organisation is our customer, we act on that organisation's instructions for the workspace data. If you are an employee of a customer, ask your workspace admin first — they can usually resolve it faster than we can.

12. Children

LineGuard is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.

13. Changes to this policy

We may update this policy as the product changes. The effective date at the top always reflects the current version. For material changes — a new subprocessor, a new category of stored data, a shorter retention window — we will email workspace admins at least 30 days before the change takes effect.

14. Contact

Yogabox Tech LLP, Chennai, Tamil Nadu, India.
Privacy and legal: [email protected]
Product support: [email protected]

LineGuard — workflow rules for Linear.
Pricing Docs Required fields Writing
LineGuard is an independent product, not affiliated with or endorsed by Linear.
Terms Privacy For AI Support