Changetrail for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Changetrail app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It reads the change history of the issues a person searches for, using that person's own Jira permissions to decide which issues are included, and stores the results for a limited time so the person can browse and download them.
- Great Work LLC cannot see your issues, your search results or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Search results: for each matching change, the time, issue id, key, summary, type and project key, who made the change (Atlassian account id, display name, account type), the field and its old and new values as Jira recorded them, and the change id | To show and export the results | Forge app storage for your site, readable only by the person who ran the search; deleted automatically after the retention your admin sets (1 to 30 days, default 7), or sooner when the person deletes the search |
| Issue ids and keys returned by the person's JQL search | To read their history in the background | Forge app storage, same retention as above |
| Search settings and summary counts (JQL, filters, counts by field, person and day, progress, any error message) | To run and show the search | Forge app storage, same retention as above |
| Saved audits: name, owner (account id and display name), shared flag, filters, project key, last run time | So people can rerun searches | Forge app storage until deleted or uninstall |
| Admin settings: allowed group names, retention, size caps | To apply your admins' choices | Forge app storage until uninstall |
| Your account id, display name, groups and admin permission | To decide whether you may use the App | In memory only |
The App does not read issue descriptions, comments or attachments except where the change history itself records a field's old and new value (for example a changed description), and it does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts. CSV files are created in your browser and saved to your device; the App does not send them anywhere.
3. Where data is stored
All App data is stored by Atlassian in Forge app storage for your Jira site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Search results: only the person who ran the search.
- Saved audits: the owner; shared audits are visible to everyone allowed to use the App, but running one produces results only from issues the runner can browse.
- Jira admins: settings, and they can delete any saved audit. They cannot open other people's search results through the App.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Search results expire automatically (section 2). People can delete their searches and saved audits at any time. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. CSV files you downloaded are under your organization's control.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can shorten retention or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. It finds issues with Jira's own search run as the signed-in person, reads history only for the issues that search returned, keeps each person's results private to them, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company