Attachwell for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Attachwell app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It reads, renames and deletes attachments, and saves categories on work items, only through your own Jira site's APIs and, for anything a person does, as that person.
- Great Work LLC cannot see your files, your work items or your audit log.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Attachment details: id, file name, size, file type, upload date, uploader account id and display name, the work item and project it is on | To list, filter, flag, rename and delete files, and to build the storage report | In memory while processing. The storage report keeps totals, plus the 50 largest files (id, name, size, date, uploader account id, work item key) |
| File contents | Only when someone renames a file: the bytes are copied from Jira and uploaded back to the same work item under the new name | In memory for the length of the rename; never stored by the App |
| Rendered description and comments of a work item | To tell whether a file is shown inline (so rename and delete leave it alone) | In memory while processing; never stored |
| Categories picked by hand and rename history (old name, who renamed, when, original uploader and date) | To show the category and "renamed from" on the work item | A Jira issue property (attachwell) on that work item, visible to people who can see the work item |
| Audit log: time, account id of the person, action, result, work item id and key, attachment id, file name, size, uploader account id, a short detail | So admins and users can see who did what | Forge SQL for your site; kept for the retention an admin sets (default 365 days, 30 to 3,650) |
| Delete previews: the list of files a person is about to delete | To make sure exactly the previewed files are deleted | Forge app storage, removed when the delete finishes or after 15 minutes |
| Admin settings: categories, rules, report group id and name, limits | To apply your admins' choices | Forge app storage |
| The signed-in person's permissions and group membership | To check what they may delete and whether they may see the storage report | Not stored |
The App does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Where data is stored
All App data is stored by Atlassian in Forge storage (Forge SQL and Forge app storage) and in Jira issue properties on your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Everyone sees only files on work items they can already see in Jira; the App searches and reads as the signed-in person.
- Renaming and deleting run as the signed-in person, so Jira's own Create attachments, Delete own attachments and Delete all attachments permissions apply.
- The storage report reads every project (as the App) and is shown only to Jira admins and the one group a Jira admin chooses.
- The audit log: each person sees their own entries; Jira admins see everyone's on the admin page.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Audit entries are deleted once older than the retention set by your Jira admin. Delete previews expire after 15 minutes. The storage report is replaced each time someone builds it. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process; issue properties stay on the work items until removed. Files deleted through the App are deleted by Jira permanently, as with any Jira delete.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage, acts as the signed-in person for every change, checks every search with Jira's strict query checker, previews every delete, asks for a typed confirmation, re-reads each file before deleting it and records every change. It keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company