Technical guide

Data processing

What the app reads, sends, and keeps. This technical overview supports your review of Jev for Jira; it is not a contractual Data Processing Agreement.

Last updated:
01

About this document

This page describes the current technical data flows, storage, retention, and controls in Jev for Jira. It is not a Data Processing Agreement (DPA), does not establish contractual processing terms, and does not replace the Privacy Policy or App Terms.

If your organisation requires a DPA, contact We The Folks to arrange and complete the applicable agreement before using the app with data that requires one. Provider terms, transfer arrangements, and your organisation’s requirements need to be reviewed as part of that process.

Privacy Policy

App Terms

02

How classification data moves

The Forge backend reads the Jira issue using an authorized administrator identity. It expands Jira variables in the configured prompt and outcome descriptions, then sends those instructions, outcome labels, referenced Jira values, and the model identifier to OpenRouter. OpenRouter routes the request to TypeSafe’s typesafe/jev-1.13 model.

New rules send the Jira values explicitly referenced in the prompt or outcome descriptions. Older source-field rules also send their selected source field until an administrator reviews and saves their conversion to explicit variables. Values referenced only by action templates are expanded locally and are not sent merely because they appear in an action.

The model returns configured choices and probabilities. The application validates the response and plans only the actions configured by the administrator. A Test previews those actions without changing the issue; an eligible automatic run can apply them in Jira.

Issue text and administrator-authored templates can contain personal or sensitive information. Converting Jira rich text to plain text reduces embedded metadata; it does not guarantee that the text is free of personal data.

03

Application data inventory

Application records are held in installation-scoped Forge storage. Project rules and activity are also scoped by project. The publisher’s OpenRouter credential is held separately in an encrypted Forge environment variable.

Automation rules
Project, prompt templates, outcome names and descriptions, action configuration, trigger and enabled settings, legacy source field where present, timestamps, revisions, and creator/last-editor Atlassian account IDs. Kept until deletion; typed-in content can itself contain personal data.
Site consent
Authorization for external processing, configuration time, and the consenting administrator’s account ID. Removed on disconnection or when that account is reported closed or updated by Atlassian.
Activity
Issue ID/key, rule and outcome labels, probabilities, timestamps, action identities and statuses, sanitized errors, and an optional Jira move task ID. Available for up to 14 days from the original run creation time.
Execution receipts
Event/revision identifiers, an input fingerprint, classification, rule-owner account ID, app/user execution actor, durable action intents and statuses, and a limited activity snapshot. Share the activity deadline; updates do not restart it.
Pending recovery
Project, issue, rule, revision and event identifiers; event kind and changed-field identifiers; queue and retry times; attempt count; and optional activity ID, issue key, rule name and safe error. No issue field values, prompt bodies, API credentials, or explicit account-reference fields. Expire 14 days after the original queue time.
Recovery checkpoints
Scan cursors, bounded references to pending work, and a synthetic-health timestamp. No issue content or account references. Cleared on completion and subject to a fixed storage expiry.
Privacy inventory
Explicit stored account IDs, oldest reference time, next report time, and resumable scan progress. Orphan inventory entries are removed after a completed scan.
Erasure markers
SHA-256 hashes of account IDs, status and time, used to prevent stale workers from restoring removed references. These are pseudonymous data and currently have no automatic expiry.
Rule-edit locks
Random lock-owner tokens and acquisition times, without administrator account IDs. Normally removed when an operation ends; interrupted operations can require controlled maintenance.
Provider credential
The publisher supplies and funds the OpenRouter key. It remains in an encrypted Forge environment variable until rotated or removed and redeployed. Customer resolvers cannot set or return it.
04

Retention and deletion boundaries

Activity and execution receipts expire no later than 14 days after their original run creation time. For a recovered event, the earlier deadline of 14 days from its original queue time also applies. Retries, progress updates, and move continuations do not renew these deadlines.

Expired activity and receipts are excluded from application access immediately. Storage expiry and cleanup remove stored records asynchronously, so physical deletion can lag the access cutoff. Deleting a rule does not retrospectively delete its earlier activity.

The account-reporting process removes explicit administrator references that Atlassian reports as closed or updated. Affected rules are disabled; affected receipts require review; consent granted by an affected account is removed. It does not find every personal detail written into arbitrary prompts, rule names, labels, or action values.

Data requests involving free text or a specific installation need an authorized, installation-specific review. Provider-side copies and Forge platform logs follow their respective service policies, not the application’s 14-day storage deadline. Uninstalling does not guarantee immediate physical deletion from every system.

05

Services involved

The Jira app and this public website use different services. Website hosting and font delivery are separate from the app’s classification path.

Atlassian - app
Jira APIs, Forge runtime, queues, application storage, and platform logging. Application data access is governed by the app’s authorization checks and the Forge platform.
OpenRouter - app
Receives and routes configured model requests, including selected Jira values and administrator-authored instructions. Uses the publisher’s account and API key.
TypeSafe - app
Provides the requested Jev decision model and processes classification inputs routed through OpenRouter.
Cloudflare - website
Hosts the public website on Cloudflare Pages and receives web request information, such as IP addresses and request headers, to deliver and protect it.
Google Fonts - website
Receives the request metadata needed to deliver this website’s fonts. The website code does not set advertising or analytics cookies.
06

External processing and consent

A Jira site administrator must authorize external processing for the installation before a model request is allowed. Project administrators configure which Jira values the classification uses. The Inputs summary in the editor helps them review those references.

Withdrawing consent blocks new classifications and tests. It cannot recall data already transmitted, cancel an accepted Jira move, or guarantee that every edit in an already-started action batch stops. Recovery rechecks current consent, permissions, and the original enabled rule revision before resuming.

The app does not enforce provider zero data retention, a no-training setting, or a fixed external processing region. Classification leaves Atlassian; this page makes no promise that all data stays in Atlassian or in a particular country. Provider handling must be assessed under the applicable provider terms and agreements.

07

Health checks and operational logs

The administration page checks service availability at opening and approximately every five minutes while it remains open. A recovery scheduler also checks availability when pending work is due. Both use fixed synthetic data and application-owned instructions, require site consent, and send no Jira issue content. They do not edit tickets or create Activity log entries.

Activity and execution receipts exclude full issue bodies, expanded action values, raw model responses, and API keys. Rule names and outcome labels copied into activity can still contain personal text.

Runtime failures use sanitized public messages. Forge operational logs may contain identifiers, statuses, and safe error information; their retention is governed by Atlassian’s service policies.

Security controls and limitations

Contact

For data-processing questions or to arrange applicable agreements before use, contact [email protected].

See the Privacy Policy for privacy requests and the support guide for safe information to share.