Kwest Roadmap

Privacy Policy

Last updated · June 2, 2026

The short version

Roadmap is a planning tool for product engineering teams, operated by Kwest Group LLC. It is distributed privately to authorized organizations via Apple Business Manager and is not available on the public App Store.

We collect the minimum data needed to make the product work: your email address, your name, your job title, your work-item assignments, and the changes you make to schedules. We do not sell your data, we do not show advertising, we do not track you across other apps or websites, and we do not use third-party analytics.

What we collect

When you use Roadmap, the following information is stored on our servers:

  • Account profile. Your email address, name, job title, the role you’ve been granted in the app (Developer, Manager, Conductor, or Admin), and an optional profile photo you choose to upload.
  • Work-item activity. The products and items you create, assign, schedule, reorder, archive, or spotlight, and the dates and times those changes occur. Date changes append to an immutable history; the app does not destroy data.
  • Session information. When you sign in via magic link, we store a hashed session token so you stay signed in. On iOS, the token is held in the system Keychain. On the web, it is held in an httpOnly cookie.
  • Sign-in audit log. The time, IP address, and user-agent string of each magic-link request and sign-in attempt. This exists to detect abuse and help diagnose account issues.

What we don’t collect

  • Your location.
  • Microphone, camera, contacts, or any iOS sensor data. Avatar photos come from your photo library only when you tap to upload one; the app does not access photos otherwise.
  • Device identifiers used for cross-app tracking (no IDFA).
  • Behavioral analytics. Roadmap ships with no Google Analytics, Mixpanel, Segment, Amplitude, PostHog, Sentry, or comparable tracker.
  • Any data from third-party social or advertising networks.

How your data is used

The information above exists solely to operate the Roadmap product for your team: showing you the right schedule, letting you assign work, surfacing slips and creep, and signing you back in across sessions. We do not use it for any other purpose. We do not sell it. We do not share it with advertisers. We do not use it to train AI models.

Where your data is stored

Roadmap data is hosted on infrastructure operated by the following providers:

  • Neon (Postgres database, United States). Stores your account, work items, and audit log.
  • Vercel (web application hosting). Serves the web app and the API the native app talks to.
  • Resend (transactional email). Delivers magic-link sign-in emails. Receives your email address and display name; nothing else.
  • Cloudflare R2 (object storage). Stores profile photos when avatar upload is configured. Receives the image bytes you choose to upload; nothing else.

Each provider is bound by its own data-processing agreement and is used only for the purpose listed above.

How your data is secured

  • All connections are encrypted in transit (HTTPS / TLS 1.2+).
  • Magic-link tokens and session tokens are stored as SHA-256 hashes, never as plaintext. Even Kwest’s engineers cannot recover a token from the database.
  • On iOS, session tokens live in the device Keychain, which is encrypted by the operating system and unavailable to other apps.
  • Access to production data is restricted to a small group of Kwest engineers who need it to operate the service.

Retention and deletion

Roadmap is an audit-friendly planning tool, so the default is to keep work-item history (including archived items) indefinitely. This lets teams review past schedules and measure how dates have moved.

If you would like your account and personal data removed, email roadmap@kwestgroup.com. We will delete your profile, your sessions, your audit-log entries, and any photos you uploaded within 30 days. Anonymized references to past assignments (e.g. “Unassigned” placeholders) may remain on historical items to preserve the integrity of the team history.

Children

Roadmap is a workplace tool intended for use by adults. We do not knowingly collect information from anyone under 16. If you believe a minor has signed up, email roadmap@kwestgroup.com and we will remove the account.

Changes to this policy

If we change the data Roadmap collects, the providers it uses, or how the data is handled, we will update this page and the “Last updated” date at the top. Material changes will be communicated to signed-in users in-app.

Contact

Kwest Group LLC
roadmap@kwestgroup.com