The short version. LineGuard reads Linear webhooks to decide whether a rule should fire, then writes back to Linear. Issue titles, descriptions, comment bodies and attachments pass through memory during that check and are never written to our database. What we keep is the metadata needed to run your rules and show you an audit trail: identifiers, field names, and outcomes.
LineGuard is a product of Yogabox Tech LLP, Chennai, Tamil Nadu, India ("LineGuard", "we", "us"). We are the data controller for the personal data described here. LineGuard is an independent product and is not affiliated with, endorsed by, or sponsored by Linear Orbit, Inc.
We build, operate and support LineGuard ourselves — it is not outsourced, resold or white-labelled, and no third party administers it on our behalf. Production access is tightly restricted and granted on a least-privilege basis; the security section below sets out the controls.
| Category | Stored? | Detail |
|---|---|---|
| Issue titles & descriptions | No | Processed in memory during rule evaluation, never persisted |
| Comment bodies & attachments | No | Never read into storage; attachments are never fetched |
| Issue identifiers | Yes | Linear issue id and key (e.g. ENG-412) in the audit log |
| Field names | Yes | Which fields were missing (e.g. "estimate"), never their values |
| Workspace & user records | Yes | Linear org id/name; user name, email, Linear user id |
| Workflow metadata | Yes | Cached team, workflow state and label names, to build rules against |
| Your rules | Yes | Rule definitions, including any comment templates you write |
| OAuth tokens | Yes | Encrypted at rest with AES-256-GCM |
Every time a rule matches, we record: the rule id and its name at the time, your workspace, the Linear issue id and identifier, the webhook delivery id, whether the trigger matched, the condition outcome as { matched, missingFields } — a list of field names only — and per-action outcomes as { type, ok, error }. No field values, and no issue text, are recorded.
Our server logs record webhook delivery ids, event types and actions, workspace ids and error messages, for debugging and abuse prevention. They do not contain issue content. They are short-lived and not used to build any profile of you.
Paid plans are handled by Dodo Payments as our merchant of record. Dodo is the seller on record for your subscription: they take the payment, issue the invoice, and handle sales tax, VAT and GST in your jurisdiction.
Your card details go directly to Dodo and never reach us. We do not see, receive or store a card number at any point. Checkout, the billing portal, invoices and payment-method changes are all pages hosted by Dodo, not by us.
What we store is the minimum needed to know what your workspace has paid for: your Dodo customer and subscription identifiers, your plan, and its status. Your billing name, address and any tax identifiers are held by Dodo under their own privacy policy. Because Dodo is the merchant of record rather than a vendor acting on our instructions, they are an independent controller of that payment data — their policy, not this one, governs it.
Linear webhooks are delivered with a snapshot of the changed issue, which does include the title and description. LineGuard reads that payload in memory to evaluate your rules, and then discards it. It is never written to the database, never copied to a third party, and never included in the audit log. We do not fetch attachments, do not read comment threads, and do not run analytics over your issue content. We do not sell personal data, and we do not use your data to train machine-learning models.
Where the GDPR applies, we rely on: performance of a contract (running the service your workspace installed), legitimate interests (security, abuse prevention, debugging, and service communications), and legal obligation where we must retain records. Where India's Digital Personal Data Protection Act, 2023 applies, we process personal data for the legitimate purpose for which you provided it when installing and using LineGuard.
LineGuard runs entirely in the United States: the application is hosted on Render in their US West region, and the database is hosted by Neon on AWS in us-east-1 (N. Virginia). The company operating LineGuard is based in India, so personal data is accessible from India for support and operations.
| Subprocessor | Purpose | Location |
|---|---|---|
| Render | Application hosting — runs the service that processes your webhooks | US West (USA) |
| Neon | Managed PostgreSQL database — all stored data | AWS us-east-1 (USA) |
| Amazon Web Services | Underlying compute, storage and network for the database | us-east-1 (USA) |
| Linear Orbit, Inc. | The platform LineGuard integrates with; the source and destination of all issue data | Per Linear's own terms |
| Cloudflare | Web Analytics on the public marketing pages — counts page views without cookies or fingerprinting. Not loaded in the dashboard, and it receives none of your Linear data | Global edge network |
| Dodo Payments | Merchant of record for paid plans — takes payment, issues invoices, handles tax. Receives your card and billing details directly; receives none of your Linear data | Per Dodo's own terms |
We will update this list before adding a subprocessor that handles personal data. For transfers out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses. If your organisation needs a Data Processing Agreement, email [email protected] and we will sign one.
We disclose data to no one else, except where we are legally compelled to. If we receive a lawful demand for your data, we will notify you unless we are legally barred from doing so.
read, write and comments:create. We deliberately do not request Linear's admin scope, so LineGuard cannot change your workspace settings, billing or membership.SameSite=Lax, Secure in production, and cryptographically signed. Every API request is scoped to the caller's workspace.LineGuard does not currently hold a SOC 2 or ISO 27001 certification, and we would rather say so than imply otherwise. If you become aware of a vulnerability, please report it to [email protected]; we will acknowledge within 2 business days. If a breach affects your data, we will notify affected workspace admins without undue delay and, where required, within 72 hours of becoming aware of it.
The LineGuard dashboard sets exactly one cookie, lg_session, which keeps you signed in for up to 30 days. It is strictly necessary for the service to function; there is no way to use the dashboard without it. We use no advertising cookies, no analytics cookies, and no cross-site trackers on this website or in the app. The dashboard itself loads no analytics at all.
These public marketing pages load Cloudflare Web Analytics, which counts page views without setting a cookie, without fingerprinting your browser and without building any profile of you. Loading it means your IP address is visible to Cloudflare as part of that request; we do not receive it, and we cannot identify you from anything the tool reports back to us. It is the only third-party request this website makes — the typefaces are served from our own domain rather than from a font CDN.
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a portable copy, object to or restrict our processing, and withdraw consent. Email [email protected] and we will respond within 30 days. We will not charge you for this or make you use a special form. The one limit on erasure is the statutory financial-records retention in section 8, which we are not free to waive.
Much of this you can do yourself: workspace admins can delete rules from the dashboard, and uninstalling the app from Linear starts the deletion described in section 8. Audit-log entries age out automatically on your plan's retention schedule.
If you are in the EEA or UK you may lodge a complaint with your local supervisory authority. If you are in India, you may raise a grievance with us first at the address above; our contact email is also our grievance channel under the Digital Personal Data Protection Act, 2023.
If your organisation is our customer, we act on that organisation's instructions for the workspace data. If you are an employee of a customer, ask your workspace admin first — they can usually resolve it faster than we can.
LineGuard is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.
We may update this policy as the product changes. The effective date at the top always reflects the current version. For material changes — a new subprocessor, a new category of stored data, a shorter retention window — we will email workspace admins at least 30 days before the change takes effect.
Yogabox Tech LLP, Chennai, Tamil Nadu, India.
Privacy and legal: [email protected]
Product support: [email protected]