Changeleaf for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Changeleaf app for Jira Cloud and Confluence Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party, including AI services.
- It reads versions and the work items in them from your Jira to build release notes, writes a release note onto a work item only when a person saves one there, and creates or updates a Confluence page only when a person (or a space setting your admins chose) publishes a note.
- Great Work LLC cannot see your release notes, work items, templates or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Release note on a work item: the text, "leave out of release notes", the account id of who wrote it and when | The sentence readers see for that work item | A Jira issue property on that work item, until changed or cleared |
| Templates: names, audiences, titles, opening and closing text, section rules (types, labels, components, JQL), line format, field ids, who changed them and when | How notes are built | Forge app storage until changed, deleted or uninstall |
| Space settings: template, draft on release, Confluence space and parent page | Automatic drafts | Forge app storage until changed or uninstall |
| Saved notes: title, version ids, space ids, template id, hand-edited lines (work item key and text), left-out keys, the keys in the note when saved, the Confluence page id, title, link and version, history (time, account id, what happened) | To reopen, regenerate and publish notes | Forge app storage until deleted or uninstall |
| Activity log: time, account id, what happened, result | So admins can see what happened | Forge app storage; deleted after 180 days |
| Work item summaries, types, statuses, labels, components, priorities, assignee display names, parent, fix versions and the fields a template names | To build the note on screen | In memory while a note is generated; not stored (except the hand-edited lines above) |
| Published release notes | Your Confluence page | Confluence, like any page; the App does not delete pages |
The App does not read comments or attachments, and it does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Where data is stored
All App data is stored by Atlassian, in your Jira and Confluence sites or in Forge app storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Notes are generated as the person viewing them, so they contain only work items that person can browse. Saved notes are listed and opened only for people who can browse every space the note covers.
- A release note on a work item is visible to anyone who can see the work item, and only people who can edit the work item can change it.
- Pages are published as the person publishing, so Confluence applies their permissions. Automatic drafts and pages for released versions run as the App, include every work item in the version, and are published only to the space your space admins chose.
- Only Jira admins change templates; only space admins change a space's settings.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
The activity log expires automatically. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Release notes written on work items are issue properties and published pages are Confluence pages; both stay in your sites until you clear or delete them.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Atlassian sites, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. Screens read and write as the person using them, admin screens re-check permissions on every call, and the App keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company