Okaystep for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Okaystep app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- Approval policies, settings, away windows and the manager directory are stored in your site's Forge key-value storage. Approval requests, decisions and the audit trail are stored in your site's Forge SQL database. Both are hosted by Atlassian.
- Notifications are Jira comments that @mention people; Jira delivers them under each person's notification settings. The App sends no email itself.
- Great Work LLC cannot see your policies, your work items, your approvals or the audit trail.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Policies: name, statuses, project and work type ids, scope JQL, steps (name, rule, approver sources: Atlassian account ids, group ids and names, project role ids and names, user picker field ids and names), fallback approver account ids, reminder and escalation hours, options | To know which moves need approval and who approves | Forge key-value storage, until deleted or uninstall |
| Settings: comments on or off, comment visibility role, admin overrides, comment commands | To run the App | Forge key-value storage |
| Away windows: account id, first and last day, delegate account id, an optional note | So delegates and fallback approvers can cover | Forge key-value storage, until the person removes it or uninstall |
| Manager directory: pairs of account ids (person, manager) | For steps that ask the reporter's manager | Forge key-value storage, until removed or uninstall |
| Approval requests: work item id, key and summary, project id, policy name, target status, the requester's account id, the approvers' account ids at each step, every decision (who, for whom, approve or reject, the comment, the time), reminder and escalation times | The approval itself and its record | Forge SQL, until uninstall |
| Audit trail: time, work item key, action, the account ids involved, a short description (which can include a decision comment) | So admins and approvers can see what happened | Forge SQL, until uninstall |
The okaystep work item property: approval status, account ids of pending approvers, step and policy names, request date, number of requests | So people can search approvals with JQL | On the work item in Jira, visible to anyone who can see the work item through Jira's REST API |
| Comments the App posts: who is asked to approve (as @mentions), decisions and their comments, reminders | Notifications through Jira | Jira comments on the work item, visible like any other comment (or limited to a project role you choose) |
| The work item being moved or approved: key, summary, project, work type, status, reporter, and the user picker fields a policy uses | To decide whether the move needs approval and who approves | In memory during the request; summary also stored with the request |
| Comments that start with /approve or /reject: the text and author | To record a decision made by comment | In memory; the decision comment is stored with the request |
| Group members, project role members and display names | To resolve approvers and show names | In memory; resolved approver account ids are stored with the request |
| A license-state record (active or not, and when it was seen) | So background functions know whether the subscription is active | Forge key-value storage |
The App does not read descriptions or attachments, and does not collect IP addresses, passwords, API tokens, payment card details or analytics. It sets no cookies and loads no third-party scripts or fonts.
3. Where data is stored
All App data is stored by Atlassian in Forge storage for your site. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors. Data residency follows what Atlassian offers for Forge storage and Forge SQL (UNVERIFIED at time of writing: confirm coverage on Atlassian's current Forge data residency page before stating it in the listing).
4. Who can see what
- Jira admins create and change policies, settings and the manager directory, and can read the site-wide audit trail and export it.
- Anyone who can see a work item sees its Approvals panel: the requests, decisions and the work item's audit trail.
- Each person sees what waits on them, and their own requests, under Apps > My approvals, and sets their own away window.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Policies, settings, away windows and the manager directory stay until an admin or the person
deletes them. Requests and the audit trail stay for the life of the installation, because they
are the approval record. Uninstalling the App removes its Forge storage according to Atlassian's
Forge data deletion process. Comments the App posted and the okaystep work item property are
Jira data and stay with the work item unless you delete them.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage, re-checks Jira admin permission on the server for every admin change, validates policy JQL with Jira's strict parser before saving, never trusts the work item property for decisions (approvals are read from the App's own storage), and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company