Accessroll for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Accessroll app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- The App reads people, groups, projects and project roles in your Jira site and changes group memberships and project roles (and, only when an admin turns it on, removes people from Jira) when a Jira admin previews and confirms a batch.
- The App stores batches, an audit log, settings and two working lists (project roles, user scan) in its storage on Atlassian's platform for your site.
- Great Work LLC cannot see your users, your batches or your audit log.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| CSV text an admin uploads or pastes | To build a preview | In memory while the preview is built; the resulting lines are stored as below, not the file |
| Batches: title, source, who created and confirmed it and when, per line the person's account ID, display name, email address (only when Jira shows it), account type and status, the group or project role, the planned and actual result, Jira's error message | To show the preview, run the batch in steps, retry and undo | Forge app storage for your site; deleted automatically 365 days after the last change |
| Access snapshot for each person removed from Jira: their group names and project roles at that moment | So Undo can restore them after a re-invite | Inside the batch record, same retention |
| Audit log: time, admin account ID, batch ID, action, the person's display name and account ID, target, result, detail | So admins can see who changed what | Forge app storage, the latest 12,000 entries |
| User scan: per account the account ID, display name, email address (only when Jira shows it), account type, status, group names, Jira products and whether they updated an issue in the chosen window or ever | For the People filters and export | Forge app storage, replaced by the next scan, deleted automatically after 30 days |
| Project-role index: per project and role, the account IDs and group names in it | For copy access, offboarding and removal snapshots | Forge app storage, deleted automatically after 1 day |
| Settings: protected group names, two on/off switches, a line limit | To apply your admins' choices | Forge app storage until changed or uninstall |
Email addresses come from Jira and follow each person's profile visibility settings; the App never asks Atlassian for hidden email addresses. The App does not collect passwords, API tokens, IP addresses, payment information or analytics. It sets no cookies and loads no third-party scripts. It does not read issue content: the activity check only asks Jira whether an issue updated by the person exists.
3. Where data is stored
All App data is stored by Atlassian in Forge app storage for your Jira site, encrypted at rest by the platform and subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors for the App.
4. Who can see it
Only Jira admins on your site, through the App's admin page. The App checks the Administer Jira permission on every request. Great Work LLC has no access.
5. Retention and deletion
Retention is listed in section 2. Uninstalling the App deletes its storage according to Atlassian's Forge data lifecycle. Changes the App made in Jira (group memberships, project roles, removals) stay in Jira, as they would if made by hand.
6. Support requests
If you email us or use our help desk, we receive what you send (your name, email address and message). We use it only to answer you and keep it for up to 24 months. Please do not send passwords, API tokens or user lists we do not need.
7. Your rights
Your Jira site's admins control the App's data and can delete batches by uninstalling the App. For anything else, including access, correction or deletion requests about support correspondence, write to hello@greatwork.company. If you are in the EU, UK or California you have the rights your local law gives you; we will answer within 30 days.
8. Changes
We will post changes here with a new effective date and note material changes in the App's release notes.