1. The short version
- The App is built natively on Atlassian Forge and runs entirely within Atlassian’s cloud infrastructure.
- We operate no external servers that receive your Atlassian data (a model sometimes described as “no egress” or “Runs on Atlassian”).
- We do not sell your data, do not use it for advertising, and do not use it to train machine-learning models.
2. Data the App accesses
To perform the bulk operations you request, the App accesses Jira data through Atlassian’s APIs, under the permissions (scopes) granted at installation: read and write Jira work and read Jira user, and subject to each user’s own Atlassian permissions. This may include work item (issue) identifiers and field values, workflow and status information, project metadata, and the Atlassian account identifiers of users involved in an operation.
This data may incidentally include personal data (for example, a user’s display name or account ID, or personal data your organization has entered into issue fields). The content of your Atlassian instance is controlled by your organization; the App accesses it only as needed to provide its functionality, and only when you direct it to act.
3. Data the App stores
The App stores only the operational data required to function: the operations you define (their JQL, the chosen operation, and its parameters), run records, and a per-issue audit trail of the changes the App made on your behalf. This data is stored using Atlassian Forge storage, which resides within Atlassian’s cloud infrastructure. The App does not store the content of your Jira issues beyond the identifiers and field values needed to perform and audit an operation you explicitly requested.
Within those stored run and audit records, the App identifies users only by their Atlassian account ID, including for user fields such as assignee or reporter, and for the person who launched each run. It does not store display names, usernames, user keys, email addresses, pictures, or locations. Display names are shown only in the live preview and in the people pickers, by resolving them from Jira at the moment they are displayed, and are never written to storage.
Run history and audit data are retained for 7 days on the free plan or 90 days on the paid plan, after which they are automatically purged. All App data is deleted automatically when you uninstall the App.
4. Where data is processed
All processing occurs within Atlassian’s Forge platform. We do not transmit your Atlassian data to Magrathea-operated servers or to any third party. Data residency follows Atlassian’s data residency arrangements for your instance.
5. Our role under data protection law
For personal data within your Atlassian instance, your organization is the data controller and Magrathea is a data processor, processing such data only to provide the App and only on your organization’s instructions. Atlassian acts as a sub-processor by providing the underlying Forge platform on which the App runs and stores data.
Because the controller is your organization, data-subject requests (access, deletion, etc.) concerning your instance’s data are best directed to your organization, which we will support as processor. Enterprise customers requiring a Data Processing Addendum (DPA) can contact us at the address below.
6. Sharing
We do not share App data except with Atlassian as the platform provider on which the App runs and stores data (including billing and licensing, which Atlassian handles for paid apps), where required by law, or to protect rights and safety. We do not receive or store your payment details; billing is handled entirely by Atlassian.
7. Security
The App relies on Atlassian Forge’s security model: it runs within Atlassian’s infrastructure, authenticates through Atlassian, and operates only under the permissions you grant. Background operations act as the user who launched them, so the App can only change what that user could change manually. Because we do not export your data to external systems, the exposure surface is intentionally minimal.
8. Changes
We may update this notice from time to time. We’ll revise the “Last updated” date above when we do, and reflect material changes in the App’s Marketplace listing where appropriate.
9. Contact
Magrathea Software, LLC
Missouri, USA
Email: hello@magratheasoftware.com