Mergewell for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Mergewell app for Jira Cloud and Jira Service Management (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- The App reads the work items you choose to merge and writes copies of their comments, files, links and labels into your own Jira site, as you, with your permissions. Comment text, descriptions and file contents go from Jira to Jira; the App does not keep copies.
- The App stores merge records (work item keys, comment and attachment ids, file names, account ids, counts and results), settings and an audit log in its storage on Atlassian's platform.
- Great Work LLC cannot see your work items, your merges or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| The work items you merge: summary, description, comments, attachments, links, labels, watchers, reporter, request participants, status | To show the preview and copy them to the work item you keep | Read from Jira and written to Jira during the merge; held in memory only |
| Work item summaries in an open preview | To show the preview | App storage; blanked when the merge finishes; unstarted previews expire after 1 day |
| Merge records: the switches you chose, work item keys, the ids of comments, attachments and links the merge created, file names and sizes, account ids added as watchers or participants, the duplicate's previous status, per-step results, the account id of the person who merged | To run the merge in steps, show results, and support Retry and Undo | Forge app storage for your site; deleted automatically 30 days after the merge |
An issue property mergewell on each merged duplicate: the target key, merge id, time, account id | So JQL can find merged items (mergedInto = KEY) and a duplicate is not merged twice | In your Jira site, on the duplicate, until Undo or until you delete it |
| A property on each comment the App posts (merge id and step) | So an interrupted merge never posts the same comment twice | In your Jira site, on that comment |
| Settings: allowed group ids and names, undo window, size and count limits, default switches | To apply your admins' choices | Forge app storage until changed or uninstall |
| Audit log: time, account id, a short description (for example "Merged MRG-14, MRG-15 into MRG-13"), merge id | So admins can see who merged what | Forge app storage, the latest 1,000 entries |
| Your account id, groups and Jira permissions | To check what you may do | In memory only |
The App does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts. Duplicate suggestions are computed inside the App by comparing summary text; no AI service or outside service is used.
3. Where data is stored
All App data is stored by Atlassian in Forge app storage for your Jira site, encrypted at rest by the platform and subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Copied comments, files and links: whoever Jira lets see the target work item, with the same comment restrictions as the originals. On Jira Service Management targets, copied comments are internal notes unless the person merging chooses to keep public replies public.
- Merge records: the person who merged, and Jira admins. The audit log: Jira admins.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Merge records expire 30 days after the merge; Undo is available for 24 hours by default (up to 7 days if your admin changes it). Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Copied comments, files, links and the issue property are ordinary Jira data and stay in your site until you delete them (Undo removes them within the undo window).
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete copied content or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. Every read and write of work items runs as the person merging, so Jira's own permissions apply to every step. The App keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company