Privacy Policy
Last Updated: June 2026
1. Introduction
Welcome to Simarlo. This Privacy Policy explains how we collect, use, and protect your information when you use our website and Atlassian Marketplace applications ("Apps"). We are committed to ensuring your privacy is protected.
2. Data Collection and Usage
Our Apps are built on Atlassian Forge and operate entirely within Atlassian's cloud infrastructure. We do not collect, transmit, or store your data on any external servers.
- No Issue Data Storage: Our Apps do not extract, transmit, or store sensitive customer issue data (such as summaries, descriptions, or comments) on our own external servers. All processing of such data happens within the Atlassian infrastructure or directly in your browser.
- Configuration Metadata: Our Apps may temporarily process configuration metadata required for functionality (e.g., project keys, field IDs, workflow names). This data is processed in-memory during operations and is not stored persistently outside your Atlassian instance.
- OAuth 2.0 Credentials: When a user authorizes the App to perform cross-site operations, Atlassian OAuth 2.0 access and refresh tokens are stored encrypted at rest using Atlassian Forge KVS (Key-Value Secure Storage) with AES-256 encryption. These tokens are scoped to the minimum required permissions, are never exposed in the browser, and are managed securely by the Forge platform.
- Job History: Provisioning job records (job status, project keys, step results, timestamps) are stored in Forge Storage within your Atlassian tenant. Job history does not contain personal data or sensitive project content.
- User Account IDs: During operations, our Apps may read Jira user account IDs from the Jira API (e.g., to resolve a project lead). This data is used only for the duration of the operation and is not persisted.
3. What We Do NOT Collect
- We do not collect, store, or process Jira issues, comments, attachments, or any issue-level data.
- We do not collect personal information such as names, email addresses, or IP addresses.
- We do not use analytics, tracking pixels, or cookies within our Apps.
- We do not transmit any data to servers outside of Atlassian's infrastructure.
4. Third-Party Services
We do not sell, trade, or otherwise transfer your information to outside parties. Our Apps communicate exclusively with:
- api.atlassian.com — Atlassian's REST API for Jira operations
- auth.atlassian.com — Atlassian's OAuth 2.0 token endpoint for authentication
No third-party services, subprocessors, or external APIs are used by our Apps.
5. Security
We implement a variety of security measures to maintain the safety of your information:
- Encryption at rest: OAuth 2.0 tokens and configuration data are encrypted using Forge KVS (AES-256).
- Encryption in transit: All API communication uses HTTPS/TLS.
- No external attack surface: Our Apps run entirely within Atlassian's Forge sandbox with no external endpoints.
- Scoped permissions: Our Apps request only the minimum Jira API scopes required for their functionality.
6. Data Residency
Because our Apps run entirely on Atlassian Forge, they inherit Atlassian's data residency controls. All data is stored in the same region as your Atlassian Cloud instance. No data leaves Atlassian's infrastructure.
7. Data Retention
- OAuth 2.0 tokens are retained until manually revoked by the user, their Atlassian account authorization expires, or until the App is uninstalled.
- Job history is retained in Forge Storage while the App is installed. It is automatically deleted when the App is uninstalled.
- Configuration data processed during operations is held in-memory only and is not retained after the operation completes.
8. GDPR Compliance
Personal Data: Our Apps do not collect or store personal data. User account IDs may be temporarily read from the Jira API during operations but are not persisted.
Right to Erasure: If an App is uninstalled from a Jira site, all associated Forge Storage data (including job history and stored credentials) is automatically deleted by the Atlassian Forge platform.
Data Portability: Job history data can be viewed within the App's interface. No personal data is stored that would require portability.
9. Your Rights
Since all data resides within your Atlassian tenant, you maintain full control over it at all times. You can:
- Remove stored credentials via the App's admin settings page
- Uninstall the App to delete all associated data
- Contact us at any time to request information about data handling
10. Atlassian Marketplace
When you install our Apps via the Atlassian Marketplace, Atlassian may collect information in accordance with their own Privacy Policy. We have no access to your Atlassian billing information or payment details.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected with an updated "Last Updated" date at the top of this page. Continued use of our Apps after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have any questions regarding this Privacy Policy or your data, you may contact us at: support@simarlo.com.