Privacy Policy

Last updated: July 2026

Panelforge ("the app") is an Atlassian Forge application for Jira Cloud, developed by Oliver Masson ("we"). This policy describes what data the app handles and where it lives. The short version: your data stays inside Atlassian's infrastructure — the app sends nothing anywhere else.

What the app stores

  1. Panel definitions — the widget code (HTML/CSS/JS), targeting rules, and settings that your Jira administrators create, plus their revision history. These are stored in Atlassian Forge hosted storage, scoped to your Jira site. They never leave Atlassian's infrastructure.
  2. Audit metadata — the Atlassian account ID of the administrator who saved or deleted a panel, stored alongside the panel for change-history purposes.
  3. Per-issue widget data — some panels (e.g. checklists) store their state in Jira custom fields on your own issues, via Jira's standard APIs, as the acting user. This data lives in your Jira site like any other issue data and is covered by your existing Jira permissions, history, and backups.

What the app accesses (but does not store)

To render panels, the app reads issue fields on behalf of the viewing user — a viewer never sees more through a panel than Jira already shows them. Field writes requested by a panel are validated server-side against admin-configured allowlists and executed as the acting user.

What the app does NOT do

Data retention and deletion

Panel definitions remain in Forge storage until an administrator deletes them (a trash + purge flow) or the app is uninstalled. Uninstalling the app permanently deletes all panel definitions per Atlassian's Forge storage lifecycle. Per-issue widget data in custom fields is ordinary Jira data and follows your site's own retention.

Data residency

Because the app uses Forge hosted storage and compute exclusively, data residency follows your Atlassian host product's residency configuration.

Security

Widget code authored by your administrators executes in a restricted browser sandbox with no access to Jira APIs, credentials, or storage. All privileged operations are validated server-side. See the documentation for the full security model.

Contact

Questions, requests, or security reports: olivermasson7@hotmail.com.