← Frontpane

Frontpane for Jira Service Management: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Frontpane app for Jira Service Management Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.

1. Summary

  • The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
  • It reads the Jira fields and links your admins choose and shows them, read-only, to people who can open the request. It stores only its settings, per-person column choices and a health record per portal panel in Atlassian's app storage for your site. It stores no request data.
  • Great Work LLC cannot see your requests, your customers or your settings.

2. What the App processes

DataWhyWhere and how long
Settings: per portal, the request types, field ids and labels to show, the linked-work projects and link types; site-wide request list columns and limits; who last changed a portal's settings (account id) and whenTo know what to showForge app storage for your site, until changed or uninstall
Per person: the list columns they hid (keyed by account id)So their list looks the way they left itForge app storage, until they show the columns again or uninstall
Health: per portal panel, when it last answered and the last error messageThe admin status pageForge app storage, overwritten as it runs
Request fields and links an admin chose, request lists from JSMRead from Jira on each view and shown to the personIn memory only, never stored
Account id, account type and permissions of the person using the AppTo check what they may seeIn memory only

The App does not collect email addresses, IP addresses, passwords, API tokens, payment card data or analytics. It never returns email addresses to the portal (people are shown by display name). It sets no cookies and loads no third-party scripts or images. CSV exports are built for the person who asked and shown to them only; the App keeps no copy.

3. Where data is stored

All App data is stored by Atlassian in Forge app storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.

4. Who can see what

  • Portal customers and other people using the portal: on requests Jira Service Management lets them open, the fields and linked work the admin chose (only links into projects the admin listed); in the request list, only requests JSM already lists for them, with the columns the admin chose. Anonymous visitors see nothing.
  • Jira admins (and project admins for their own project): the settings, a preview of what a customer would see on a request, and the status page.
  • Great Work LLC: no access. If you open a support request, we see only what you send us.
  • Atlassian: as the platform operator, under Atlassian's privacy policy.

5. Retention and deletion

Settings stay until an admin changes them or the App is uninstalled. Uninstalling removes the App's Forge storage according to Atlassian's Forge data deletion process. The App writes nothing to your Jira issues, so nothing is left behind there.

6. Support requests

If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.

7. Your rights

Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete data in the App or uninstall it. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.

8. Security

The App uses only Atlassian-hosted compute and storage. Before showing anything on a request it asks Jira Service Management, as the signed-in person, whether they can open that request (for Atlassian accounts without a JSM license, it checks the request's reporter, participants and organizations, the people JSM shows a request to). Which request is being viewed comes from Atlassian's signed invocation context, never from the browser. Fields that hold comments, work logs or other internal data can't be chosen, and are skipped at read time if a field changes. Settings changes are re-checked against Jira's admin or project admin permission on the server. It keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.

9. Children

The App is a business tool and is not directed to children under 16.

10. Changes

We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.

11. Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company