Performalise reads what teams say and do in their work, keeps the insight and discards the conversation, and never produces a score for a person. This page lists what is read, what is stored, what is never produced, and the one exception declared in advance.

Privacy in Performalise is enforced at the data layer, not by a policy someone has to remember. That sentence is value 4 of the Coaching Constitution, and everything below follows from it.

What is read

  1. The standup and the review, via Microsoft Teams, Slack or Google Meet: what the team said it would do, what it said was blocked.
  2. The tracker, Jira, Azure DevOps or Linear: work items, sprint goals, status changes, unplanned additions. Read-only.
  3. The code and the deployments, GitHub, Vercel, Supabase: commits, pull requests, review flow, deploy cadence. Performalise never reads source code; it reads the record of activity around it.
  4. Product analytics, Microsoft Clarity, Google Analytics 4, Amplitude: whether shipped work is used, so value can be validated rather than assumed.

The coach reads what people say and do in their work. It never reads how they sound, look or move: no tone analysis, no video, no keystroke or activity monitoring.

What is stored

The insight, not the conversation. From a standup transcript Performalise keeps what it extracted (a commitment, a blocker, a said-versus-did divergence) and discards the transcript. Data has a lifecycle: retention limits during the contract, disposal at contract end, and no repurposing for any other use, including training models.

What is never produced

  1. Individual productivity scores. Signals are team-level patterns. Individual reads exist only for the individual, are private to them, and never roll up.
  2. Leaderboards or rankings of people. The coach adapts its posture to each person's readiness and never ranks, scores or compares them (constitution, value 3).
  3. Anything invisible to the people it applies to. Whatever a company configures for the coach is shown to the teams it applies to (value 8).

The one exception, declared in advance

Legal obligation or imminent risk of harm. It is the only case in which information leaves the boundary above, it is stated to every party at the contracting ceremony before coaching begins, and it is the same for every customer.

What travels up, and what stays with the team

Coaching stays with the team. Only drift from the goal, and blockers the team cannot clear itself, travel up to the manager, with the team's consent, in a support-not-judgment frame. A manager sees that a sprint goal is at risk and which objective it feeds; a manager does not see a transcript, a person, or a score.

Security posture

Hosted on AWS across multiple availability zones, encrypted in transit with TLS 1.3 and at rest, protected by WAF and DDoS controls, independently penetration-tested annually, 99.88% uptime. Performalise FZ LLC is aligned to SOC 2 Type II and ISO 27001 and pursuing formal certification; the platform operates to both frameworks' principles in the interim. Fully GDPR compliant. The full policy is on the data security page; the data processing agreement and privacy policy are the contractual texts.

Frequently asked questions

Does Performalise read our source code?

No. It reads the activity around it: commits, pull requests, review flow and deployments. No source-code access is required or requested.

Are standups recorded and kept?

The standup is one of the four streams, so what was said is read. What is kept is the insight extracted from it, not the recording or the transcript.

Can a manager see an individual's data?

No. Individual reads are private to the individual and never roll up. Managers see team-level drift from goal and blockers the team cannot clear, with the team's consent.

Is customer data used to train models?

No. Data has a lifecycle limited to the contract: retention limits, disposal at contract end, no repurposing.

Part of How Performalise works, the public record of how the product is built to behave. Last reviewed 27 August 2026. Corrections: josef@performalise.com.