Configmark for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Configmark app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It reads your Jira configuration (workflows, schemes, screens, custom fields and options, field schemes, statuses, work types, space settings, project role members, boards) and keeps snapshots of it in your site's Forge storage.
- It does not read work items, comments or attachments.
- Great Work LLC cannot see your configuration, your snapshots, the audit log or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Snapshots: the configuration listed above, including names, descriptions, workflow rules and their parameters, scheme grants and notifications | Compare and restore | Forge SQL for your site, compressed; kept for the periods your admins set (default 30 days for scheduled snapshots, 365 days for others), or until deleted |
| Atlassian account IDs that appear in configuration: space leads, users in project roles, users named in permission grants or workflow conditions | Part of the configuration being snapshotted and restored | Same as snapshots |
| Audit log: time, account ID of the admin, action, result, item name and ID, snapshot and restore run | Accountability | Forge SQL; kept for the period your admins set (default 730 days) |
| Settings, snapshot progress, restore previews (15 minutes) and restore runs | To run the App | Forge app storage |
| Display names of people in Jira's audit log records and in the App's audit log | Shown on screens ("changed by") | In memory while a screen loads; not stored |
Jira's own audit log is read when two snapshots are compared, to show who changed an object. Those records are shown and not stored by the App.
The App does not collect email addresses, IP addresses, passwords, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Downloaded files
An admin can download a snapshot as a JSON file. The file is built in that admin's browser from data in your site; it is not sent to Great Work or anyone else. Once downloaded, the file is in your organization's control. Imported files are stored like snapshots.
4. Where data is stored
All App data is stored by Atlassian, in Forge app storage and Forge SQL for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
5. Who can see what
- Only Jira admins can open the App (it is a Jira settings page) and every call re-checks the Administer Jira permission.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
6. Retention and deletion
Snapshots are removed automatically after the retention periods set in the App, or when the storage limit is reached (oldest first), except snapshots marked Keep and the latest one. Admins can delete any snapshot. Audit entries are deleted after their retention period (90 to 3,650 days). Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process.
7. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request. Please don't send snapshot files unless we ask; send the audit log line instead.
8. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete snapshots or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
9. Security
The App uses only Atlassian-hosted compute and storage. Restores run as the signed-in Jira admin and need a preview and a typed confirmation; the versions they change are saved first. Report vulnerabilities to hello@greatwork.company.
10. Children
The App is a business tool and is not directed to children under 16.
11. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
12. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company