Last updated: July 2026
Panelforge ("the app") is an Atlassian Forge application for Jira Cloud, developed by Oliver Masson ("we"). This policy describes what data the app handles and where it lives. The short version: your data stays inside Atlassian's infrastructure — the app sends nothing anywhere else.
To render panels, the app reads issue fields on behalf of the viewing user — a viewer never sees more through a panel than Jira already shows them. Field writes requested by a panel are validated server-side against admin-configured allowlists and executed as the acting user.
Panel definitions remain in Forge storage until an administrator deletes them (a trash + purge flow) or the app is uninstalled. Uninstalling the app permanently deletes all panel definitions per Atlassian's Forge storage lifecycle. Per-issue widget data in custom fields is ordinary Jira data and follows your site's own retention.
Because the app uses Forge hosted storage and compute exclusively, data residency follows your Atlassian host product's residency configuration.
Widget code authored by your administrators executes in a restricted browser sandbox with no access to Jira APIs, credentials, or storage. All privileged operations are validated server-side. See the documentation for the full security model.
Questions, requests, or security reports: olivermasson7@hotmail.com.