Formtide for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Formtide app for Jira Cloud and Jira Service Management (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It stores the field rules your Jira admins create, and registers them with Jira so Jira can apply them on screens. It stores no field values.
- Great Work LLC cannot see your rules, your work items or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Rules your admins create: names, notes, the projects, work types and request types they apply to, the fields and values they check (option ids and names, account ids picked as values, group ids and names, statuses, typed text) and what they change | The App's purpose | Forge app storage, and a copy of each rule in Jira's own UI modification records so Jira can run it |
| Who changed a rule and when (Atlassian account id, time, action, rule name), last 300 changes | The change log on the admin page | Forge app storage |
| Result of the last time rules were applied to Jira | The admin page and the audit | Forge app storage |
| Short-lived caches (project, work type and field lists, option lists, request types) | Speed | Forge app storage; expire after 2 to 5 minutes |
| Last license state seen | To stop changes while the subscription is inactive | Forge app storage |
While a person uses a create, transition or work item screen, the App's screen script reads the values of the fields on that screen in their browser to decide what to show, hide, require or fill in. Those values are used on the spot and never stored or sent anywhere. When a rule checks the work item's status or the person's groups, the script asks your Jira for them, as that person. The rule tester on the admin page works on values the admin types in, and keeps nothing. The App does not read descriptions, comments or attachments outside the open screen, and it does not collect IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Where data is stored
All App data is stored by Atlassian, in Forge app storage for your site and in your Jira site's UI modification records, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Rules, the audit and the change log: Jira admins, on the admin page.
- People using screens: the effect of the rules (a field shown, hidden, required), not the rules.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Rules stay until an admin deletes them; deleting a rule removes its registration from Jira. The change log keeps the last 300 changes. Caches expire on their own. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process, and Jira stops running its rules.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can edit or delete rules and uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. Every admin-page action checks that the signed-in person is a Jira admin. Rules are registered with Jira as the App, and only the App can read or change its own registrations. On screens, the App can only change the fields its rules name, and only in the ways Jira allows apps to (visibility, required, read-only, value, options, label and help text). Hiding a field is not a security control: the value is still visible in search, exports and the API to anyone with access to the work item. The App keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company