Privacy Policy
Where the app runs
The app runs entirely on Atlassian's Forge platform, inside Atlassian's own infrastructure. We operate no servers of our own, and no Jira data is copied to any system we control.
What the app reads
When an issue is created, updated or commented on, Atlassian invokes the app with the event. If one of your rules matches, the app reads:
- issue key, summary, type, status and priority;
- the assignee's display name, and the account IDs of the assignee and reporter;
- what changed, with the previous and new values;
- the comment text and its author, for comment events;
- the list of projects on your site, and the people who can be assigned in them, so that the settings page can offer them as choices.
The app requests the Jira scopes read:jira-work and
read:jira-user. It has no write access and cannot modify or
delete anything in Jira.
What the app sends, and where
The app sends a message to the Google Chat webhook address that a Jira administrator enters in its settings. That message contains the issue fields listed above.
This is the only outbound destination. The app is restricted
at the platform level to chat.googleapis.com and cannot contact
any other host.
Once a message reaches Google Chat it is governed by Google's terms and by your organisation's own Google Workspace configuration. We have no access to it.
What the app stores
Inside Atlassian's Forge storage, scoped to your site:
- Your rules — rule names, Google Chat webhook addresses, selected project keys, selected account IDs and filter settings.
- A delivery log — the last 40 deliveries, each recording the time, the rule name, the issue key and the outcome.
Issue content is not stored. Summaries, descriptions and comment text pass through the app and are not retained anywhere.
Retention and deletion
Rules and the delivery log live in Forge storage for as long as the app is installed. Uninstalling the app removes them along with the installation. You can also delete any rule at any time from the settings page.
Sub-processors
- Atlassian — hosts and runs the app, and stores its data.
- Google — receives the messages you configure the app to send.
We use no other sub-processor. We run no analytics, tracking or telemetry of our own, on this website or in the app.
Your rights
Because the app stores no personal data beyond Atlassian account identifiers used for filtering, requests to access or erase personal data are usually satisfied by uninstalling the app or removing the relevant rule. For anything more specific, write to support@winnowtools.com and we will respond within 30 days.
Changes
If this policy changes materially, the date at the top changes and the previous version remains available on request.