← Accruewell

Accruewell for Jira: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Accruewell app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.

1. Summary

  • The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
  • Leave types and policies, locations and holiday calendars, settings and approval delegations are stored in your site's Forge key-value storage. The people directory, leave requests, balance adjustments and the audit trail are stored in your site's Forge SQL database. Both are hosted by Atlassian.
  • Balances are not stored: they are worked out from the policy, approved leave and adjustments each time they are shown.
  • Notifications are sent by Jira itself (Jira's "notify" email on a work item your admin picks), under Jira's normal email settings. The App sends no email itself.
  • CSV exports are built in your browser from your site's data; nothing is uploaded.
  • Great Work LLC cannot see your leave data.

2. What the App processes

DataWhyWhere it lives
Leave types and accrual policies (names, rules, the locations a policy covers)To work out balances and check requestsForge key-value storage, until deleted or uninstall
Locations: name, time zone, working days, public holiday calendar and your own daysTo count working days and to know "today" for people thereForge key-value storage
Settings: tracking start, leave admin group ids, HR approver account ids, team limits, the notification work item key, reminder and retention settingsTo run the AppForge key-value storage
People directory: Atlassian account id, manager's account id, location, team name, start and end date, FTE, own working daysFor balances (pro-rating, FTE), approvals (the manager) and the team calendarForge SQL, until removed or uninstall
Leave requests: account id, leave type, dates and half days, working days at the time, the note the person wrote, status, who decided and when, the decision comment, warnings shownThe request and its recordForge SQL, until uninstall
Balance adjustments and opening balances: account id, leave type, date, days, reason, who made it and whenPart of the balance historyForge SQL, until removed or uninstall
Approval delegations: manager's account id, delegate's account id, first and last daySo a delegate can approve while the manager is awayForge key-value storage, until removed
Audit trail: time, who acted, whose leave, the action and a short description (which can include a note or comment)So admins can see what happenedForge SQL, for the retention period in Settings (default 730 days)
Display names, group membership of the signed-in person, the Jira admin permissionTo show names and decide who may see or change whatIn memory only
Email addresses typed into a CSV importTo find the matching Jira userIn memory only; only the account id is stored
A license-state record (active or not, and when it was seen)So the daily job knows whether the subscription is activeForge key-value storage

Health information: a "sick leave" request records only that a person was away and on which days, with an optional note the person writes. Admins can mark a leave type private so colleagues see it only as "Away". Advise people not to put medical details in notes.

The App does not read work items, comments or attachments, and does not collect IP addresses, passwords, API tokens, payment details or analytics. It sets no cookies and loads no third-party scripts or fonts.

3. Where data is stored

All App data is stored by Atlassian in Forge storage for your site. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors. Data residency follows what Atlassian offers for Forge storage and Forge SQL (UNVERIFIED at time of writing: confirm coverage on Atlassian's current Forge data residency page before stating it in the listing).

4. Who can see what

  • Everyone with access to the App sees their own balances, history and requests.
  • Managers see the balances, history and requests of the people below them in the directory, and approve their requests (delegates while the delegation is active).
  • HR approvers and leave admins (Jira admins and members of the groups set in Settings) see everyone's balances and requests, and leave admins change policies, people and balances.
  • The team calendar shows approved leave to everyone using the App (or only to managers and admins, if set). Private leave types show as "Away" to colleagues; pending requests show only to the person, their managers and admins.
  • Great Work LLC: no access. If you open a support request, we see only what you send us.
  • Atlassian: as the platform operator, under Atlassian's privacy policy.

5. Retention and deletion

Policies, locations, settings, the directory and adjustments stay until an admin deletes them. Requests stay for the life of the installation, because they are the leave record. The audit trail is deleted after the retention period set in Settings. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Notification emails that Jira sent are outside the App.

6. Support requests

If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.

7. Your rights

Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; leave admins can export a person's requests and balances as CSV and remove them from the directory. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.

8. Security

The App uses only Atlassian-hosted compute and storage, takes the signed-in person from Atlassian's invocation context (never from what the page sends), re-checks on the server who may see or change each person's leave, keeps leave admin groups by id and refuses deleted ones, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.

9. Children

The App is a business tool and is not directed to children under 16.

10. Changes

We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.

11. Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company