Public trust
Simple rooms deserve clear boundaries.
Refinement Pointer is a personal project for short planning-poker sessions. This page explains what the app stores, who can see it, how to use it safely, and how to report a problem. It was last reviewed on .
Privacy
Short-lived room data, without accounts or advertising.
Use a display name or initials. Do not enter passwords, secrets, regulated information, or confidential work details that are not needed for estimation.
What a room stores
- A random room code, round and reveal state, and activity timestamps.
- Participant display names, join timestamps, and a one-way hash of each member credential.
- The selected estimation scale, current round's Fibonacci points or T-shirt sizes, and readiness state. Reset deletes stored estimates.
Who can see it
A room link is an invitation capability, not account-based access control. Anyone with the link can view the selected scale, participant names, readiness, and estimates after reveal. Before reveal, other participants cannot see your estimate. Anyone who joins can reveal estimates, or reset the round.
Browser storage
The browser uses one strictly necessary, room-scoped member cookie so you can remain joined. It is never used for analytics or advertising, JavaScript cannot read it, and the server stores only its one-way hash. The current tab stores your display name and an estimate waiting to synchronize so a reload can recover them. A theme preference is stored only after you intentionally choose one.
Retention and hosting
A live room becomes eligible for deletion after 8 hours without a join, vote, reveal, reset, or departure. Read-only polling does not extend the room. Cleanup runs periodically, so deletion may occur shortly after the cutoff rather than at an exact moment. Leaving removes that participant's live record and estimates.
Restricted Azure recovery backups may retain an earlier copy for up to 7 days after live deletion. They are not available to room participants, and restored data is cleaned before application traffic resumes.
Microsoft Azure processes hosted service data in East US 2.
Logs, analytics, and deletion limits
Google Analytics is disabled. The app loads no Google tag, sends no browser request to Google, and creates no Google Analytics cookie or analytics-choice record.
After a new participant successfully joins, the server emits one
session.joined operational event with no event-specific fields. Once Azure
collection is configured, this makes successful joins countable. Its standard envelope
contains only the timestamp, level, event name, version, deployment, environment,
component, and outcome. It has no room code, URL, request ID, display name, member
identifier, story, scale, estimate, network address, browser, or device detail. The app
does not intentionally link this signal to Google Analytics, and they carry no shared
identifier; only aggregate trends should be compared. Neither signal is an audit trail
or proof that a visitor is human.
Other application logs are designed not to record IP addresses, room codes, concrete room URLs, names, story labels, estimates, cookies, headers, or request bodies. Hosting infrastructure still processes network and request data to deliver and protect the service. Google Analytics automatically excludes known bots where it can, but traffic and join counts remain indicators of likely use rather than identity verification.
Sanitized application events and enabled Azure operational log streams are retained for up to 30 days. Access is restricted to the operator and used for reliability, abuse, and security response.
There are no accounts, so the operator cannot find a room from a person's name or email address. A live room can be removed when the exact room code is provided through the configured private support channel. If managed backups are enabled, earlier copies cannot be selectively edited and instead age out with the configured recovery window.
Acceptable Use
Use the room with the same care as the team conversation.
- Share room links only with people authorized to see the work being discussed.
- Do not enter secrets, regulated data, or unnecessary confidential details.
- Do not impersonate, harass, disrupt, automate abusive traffic, or attempt unauthorized access.
- Do not test against another team's room or use the service for unlawful activity.
Refinement Pointer is a temporary collaboration aid, not a system of record or a guaranteed service. Keep authoritative backlog information in the team's normal work system. The operator may remove rooms, limit traffic, or temporarily disable the service to address abuse, security, cost, or reliability problems.
Accessibility
Designed toward WCAG 2.2 Level AA.
The interface uses semantic controls, visible keyboard focus, text alongside status colors, reduced-motion support, and light, dark, and high-contrast themes. Formal conformance is not claimed while automated, keyboard, zoom, screen-reader, forced-colors, and real-device verification remains incomplete.
To report a barrier, include the page or action, browser, device, and assistive technology when relevant. Do not include a room link or room content. Barriers that prevent creating, joining, voting, revealing, resetting, or leaving a room receive the highest priority.
Contact
Support, privacy, accessibility, and room removal.
Email contact@refinementpointer.com. The mailbox provider processes the address and message so the operator can respond.
For early room removal, include only the room code in the private message body. Do not place it in the subject, and do not include participant names, the story label, estimates, cookies, screenshots, or database details. The operator cannot verify a room through an account because the service has no accounts.
Security reporting
Report vulnerabilities privately and with minimal data.
Send security or abuse reports to security@refinementpointer.com. Include the minimum reproduction detail and do not include room content belonging to another person or team.
This reporting guidance does not grant permission to access another user's room, retain room data, degrade the service, automate high-volume testing, or bypass access controls. Reports are handled on a reasonable-effort basis without a published SLA.