Why this page exists
Auto PM asks for trust in three sensitive places: your product thinking, your Jira account, and possibly a database. This page explains — in plain language — exactly what leaves your browser and where it goes, so you can decide what you're comfortable connecting.
Your projects and documents
Everything you write is stored in Auto PM's managed database, in rows that are locked to your account. No other user can read them — not through the app, and not through the database API. The single exception: a PRD you explicitly share via a read-only link. Turning the link off cuts access instantly.
When the AI drafts something
When you press a drafting button (PRD, backlog, insights, documents, answers, risk maps), Auto PM sends the relevant slice of that project's content to an AI model through our hosting platform's AI gateway, and writes the result back to your project. In practice that means:
- Only the project you're working in is included — never other projects.
- Only the material needed for that draft is sent, not your whole database.
- Your prompts and content are not used to train models and are not retained by the model provider beyond serving the request.
- Nothing is drafted in the background: the AI only runs when you ask it to.
Jira
- Your Jira API token is used only to create and update issues in the project you configured, and only when you press push — or when a Jira automation or plugin you installed sends an issue to Auto PM.
- Auto PM never reads your Jira account beyond the project you connect, and never deletes Jira issues.
- You can revoke the token at any time from your Atlassian account.
Connected databases
- Read-only, always. Auto PM runs only the queries you type or approve, and the app rejects anything that tries to write. It never connects to a database you haven't configured.
- Encrypted credentials. Database passwords are encrypted with AES-256-GCM before storage. They are decrypted only in memory, only on the server, and only for the moment your query runs.
- Results stay yours. Query results are stored in your project so you can chart and revisit them; they're subject to the same per-account locking as everything else.
- We recommend connecting a dedicated read-only database user with the minimum grants — the app is built so that's all it needs.
What we deliberately don't collect
- No analytics trackers, ad pixels or session recording.
- No selling or renting of any data, to anyone.
- No access to your Google account beyond your name and email at sign-in.
Deleting things
Deleting a project permanently removes everything beneath it, including saved credentials and query results. Shared links can be switched off at any time. See the privacy policy for account-level deletion.