Auditwell for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Auditwell app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It records actions people take on Jira work items in the spaces your Jira admins choose, at the level of detail they choose, and keeps that log in Forge storage on your own site for a limited time (7 to 730 days).
- It records nothing until a Jira admin finishes setup, which requires writing a notice for everyone on the site and confirming that people have been told.
- Great Work LLC cannot see your log, your work items or your settings.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| One row per recorded action: the person's Atlassian account id, the action (for example "changed status", "commented", "viewed"), the time, the work item id and key, the space id and key, and a short detail (names of the fields that changed, the from and to status, the new assignee's name, a work log's time spent, an attachment's file name, a deleted work item's summary) | The activity log admins asked for | Forge SQL on your site. Kept for the retention period the admin sets (default 90 days, 7 to 730), then deleted nightly |
| The same rows at a lower detail level when the admin chooses one: "daily totals" keeps the person, space, action and day only; "team totals" keeps the space, action and day only (no person) | Aggregate modes | Forge SQL, as above. Lowering the level rewrites stored rows to the new level |
| Work item views (who opened which work item, at most one row per person and work item per 30 minutes) | Only if an admin turns views on | Forge SQL, as above |
| Access log: who searched the log, exported it, listed people or changed settings, when, and whose activity a search named | Accountability for the people who read the log, and so people can see when their activity was looked at | Forge SQL; kept at least 400 days (or the retention period if longer) |
| Settings: detail level, views on or off, retention, recorded spaces, excluded people (account ids) and groups (ids and names), the audit group (id and name), the notice text, who finished setup and when; the resolved member list of excluded groups; a random key used to de-duplicate views | To apply your admins' choices | Forge app storage on your site |
| The signed-in person's Jira admin status and group membership | To decide who may read the log | Not stored |
The App never stores field values, descriptions, comment text, attachment contents, email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts. It does not record sign-ins, searches, board or dashboard views, or exports made in Jira.
3. Where data is stored
All App data is stored by Atlassian in Forge storage (Forge SQL and Forge app storage) on your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- The full log, people and inactive-people reports, CSV export and the access log: Jira admins, and members of one audit group a Jira admin may choose. Every search, export and settings change is written to the access log.
- Everyone on the site: the admin's notice, a plain description of what is recorded, and (unless an admin turns it off) their own recorded activity and the times someone searched or exported their activity, with that person's name.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Rows older than the retention period are deleted every night. Shortening the retention deletes older rows at once. Adding a person or group to the exclusions deletes everything already stored about them and stops recording them. Lowering the detail level removes the more detailed parts of stored rows at once. Pausing recording keeps what is stored until it expires. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, including the App's log, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; the App's personal view lets each person see what is recorded about them, and a Jira admin can delete a person's rows by excluding them. Your organization is responsible for having a lawful basis for recording and for informing the people it records. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage, checks who is asking on every request, lets only Jira admins and the chosen audit group read the log, records every read in the access log, and has no outbound network access. It keeps no credentials.
9. Changes
We will post changes to this policy at its listing URL and update the effective date. Material changes will also be noted in the App's release notes.