Gherkit for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Gherkit app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- Great Work LLC cannot see your Jira data. We do not receive, store or have access to your feature files, scenarios, test results, issues or users.
- Your own CI systems can send data to the App (feature files and test reports) through an endpoint hosted by Atlassian and protected by a token your project admins create.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Feature files (Gherkin text your team writes or imports), their paths and versions | The core function: writing, checking and exporting BDD scenarios | Forge SQL on your site, until deleted in the App |
| Scenario index: names, tags, linked issue keys, step counts | Showing scenarios on issues and the project page | Forge SQL on your site, rebuilt from the feature files |
| Step library: step wording, usage counts, notes and deprecation flags | Step suggestions and checks | Forge SQL on your site |
| Test results your CI posts: status, duration, failure message, run label, names of unmatched report entries | Showing results on scenarios and issues | Forge SQL on your site; the newest 200 runs per project are kept |
| CI token hash, hint, creator account id, created and last-used time | Authenticating CI calls | Forge SQL on your site; the token itself is shown once and never stored |
| Activity log: time, account id (or "CI") and a short description of each change | Accountability | Forge SQL on your site |
| A summary property on linked issues (scenario count, failing count, status) | JQL search (bddScenarios, bddFailing, bddStatus) | Jira issue properties on your site |
| The project permissions of the person using the App | Checked live on each action; not stored | Not stored |
The App does not collect email addresses, IP addresses, passwords, payment information or analytics. It sets no cookies and loads no third-party scripts. Test reports can contain whatever your test framework writes into failure messages; we recommend not printing secrets in test output.
3. Where data is stored
All App data is stored by Atlassian in Forge storage (Forge SQL and the app key-value store) associated with your Jira site, subject to Atlassian's data residency settings for Forge apps. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors for the App.
4. Who can access it
- People on your site: anyone who can browse a project can read its scenarios and results; people with Edit issues can change them; project admins manage the CI token. These checks use your Jira project permissions on every request. Download links made on the project page work for 10 minutes and for one feature file only.
- Your CI systems: whoever holds a project's token can download that project's feature files and post results or feature files to it. Project admins can replace or revoke the token at any time.
- Great Work LLC: no access to App storage or your Jira data. If you open a support request, we only see what you choose to send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Feature files stay until someone deletes them in the App (or a CI import in mirror mode removes them). Test runs beyond the newest 200 per project are deleted automatically. Uninstalling the App removes its app storage according to Atlassian's Forge data deletion process. Issue properties written by the App remain on issues as inert data unless removed.
6. Support requests
If you contact support through our help desk or by email, we process the information you send (name, email, message, attachments) only to answer you. Support data is kept for up to 24 months and then deleted. You may ask us to delete it sooner.
7. Your rights
Depending on where you live (for example the EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data, and to object to processing. For data in your Jira site, your site administrator can delete it in the App or by uninstalling the App; for support data, email hello@greatwork.company. We respond within 30 days.
For App data in Forge storage, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; Great Work LLC has no access to it. For support data, Great Work LLC is the controller.
8. Security
The App uses only Atlassian-hosted compute and storage, checks Jira project permissions on every action, stores only a SHA-256 hash of each CI token and compares it in constant time. See the Privacy & Security tab on the Marketplace listing for details. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes on this page and update the effective date. Material changes will also be announced in the App's release notes on the Marketplace.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company