Legal

Privacy Policy

What Jev for Jira stores, where it is stored, how long it is kept, and who else can see it. In short: the app runs on Atlassian Forge, we operate no infrastructure of our own, and the only external service it contacts is OpenRouter, which routes classification requests to TypeSafe.

Draft — not yet publishedApplies from the Marketplace listingVersion 0.1
01

Who we are

Jev for Jira is published by We The Folks, based in Poland. The app is currently in private testing. Distribution through the Atlassian Marketplace is planned.

We do not operate our own servers for this app. All application code runs inside Atlassian Forge, on Atlassian's infrastructure.

02

What this policy covers

This policy covers the Jev for Jira app and this website. It does not cover Jira itself, which is governed by Atlassian's own privacy policy and your agreement with Atlassian.

03

Processor, not controller

For issue data processed by the app, the customer organisation is the data controller and We The Folks acts as a processor on its instructions. Those instructions are the rules an administrator configures: the prompt, its Jira variables, the outcomes and the actions.

For the administrator account references stored with rules and activity, and for contact details sent to us directly, we act as controller.

04

What the app stores

Full issue bodies, expanded action values, attachments and provider credentials are not stored in activity.

Rules
Project key, prompt template, outcome names and descriptions, configured actions, trigger settings, enabled state, and the Atlassian account ID of the administrator who last saved the rule.
Activity
Issue key and ID, rule and outcome labels, timestamp, model scores, action statuses and sanitized error messages.
Execution receipts
Event identifiers used to prevent duplicate execution and self-triggering loops.
Installation settings
Whether a site administrator has authorized external AI processing.
05

Credentials

We The Folks supplies and pays for the OpenRouter credential used for classification. It is stored as an encrypted Forge environment variable, is read only by the app backend, and is never sent to the browser. Customers do not supply, view or replace it.

06

Where data is stored

Rules, activity and receipts are stored in Forge storage, isolated per installation and per project. Data residency for Forge storage follows Atlassian's platform behaviour for your site.

Classification requests leave Atlassian and are processed by OpenRouter and TypeSafe. We do not control their processing regions.

07

How long it is kept

Activity
Hidden after 14 days from the original run creation time and configured to expire in Forge storage. Physical cleanup can lag behind expiry.
Execution receipts
Expire 14 days after the original run creation time. Progress updates and retries do not extend this deadline.
Rules
Kept until an administrator deletes them, or until the app is uninstalled.
Uninstall
Removing the app removes its Forge storage according to Atlassian's platform behaviour.
08

What is sent to the model

When a rule runs or is tested, the app sends the prompt and outcome descriptions after variable expansion, configured outcome labels, and the Jira values those templates reference.

Values used only inside action templates are expanded locally and are not part of the model request. The app caps the expanded request at 30,000 UTF-8 bytes; oversized input fails instead of being truncated.

No model request is made until a site administrator has authorized external AI processing. Disabling the authorization stops new requests; it cannot recall data already sent.

09

Sub-processors

The app does not enforce provider zero retention, no training on submitted data, or a fixed processing region. Provider retention follows their own policies.

Atlassian
Forge platform, application runtime and storage.
OpenRouter
Routing of classification requests.
TypeSafe
The jev-1.13 model that produces the classification.
10

Logs and our access

Forge developer logs may briefly contain operational information such as identifiers, statuses and error text. We do not log issue content, prompt bodies or credentials.

We do not have standing access to a customer's Jira data. Access for support requires the customer to share information with us deliberately.

11

What we do not do

No advertising, no sale of data, no profiling of end users, no automated decisions about individuals. The app classifies issues, not people.

The app does not search other Jira issues, does not generate free-form replies and does not choose actions beyond those an administrator configured.

12

This website

This site is a product page. It sets no advertising or analytics cookies and does not build visitor profiles. Fonts are loaded from Google Fonts, which receives the request metadata needed to serve them.

13

Security

Every backend operation checks permissions; hidden controls are not treated as an authorization boundary. Activity entries are shown only to viewers who can access the referenced issue.

When a Jira write cannot be confirmed, the run is marked Needs review rather than repeated automatically. Report a suspected vulnerability to [email protected].

14

Your rights

Data subjects should contact the customer organisation that installed the app, as controller of the issue data. We support that organisation in responding.

A scheduled job reports stored administrator account references and removes those Atlassian marks as closed or updated. Hashed erasure markers prevent in-flight jobs from restoring removed references.

Where we act as controller, you can request access, correction, erasure, restriction or portability, and you can complain to your supervisory authority.

15

International transfers

Classification requests may be processed outside the European Economic Area. Where that happens, transfers rely on the mechanisms our providers make available. The specific mechanisms will be named in the data processing terms published with the Marketplace listing.

16

Changes to this policy

Material changes will be announced on this page with a new version number and effective date before they take effect. This draft is versioned 0.1 and has no effective date yet.

Contact

We The Folks, Poland. Privacy questions, data requests and security reports: [email protected].

Registered company details, the data protection contact and the support address will be listed here before the app is published.