← Pairwell

Pairwell for Jira: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Pairwell app for Jira Cloud (the "App") processes, where it is kept, who can see it, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.

1. Summary

  • The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
  • Settings are stored in your site's Forge key-value storage. The people directory, 1:1s, private notes, review cycles and reviews, feedback, goals and the audit trail are stored in your site's Forge SQL database. Both are hosted by Atlassian.
  • Each person's records are visible only to that person, the managers above them in the App's directory and the HR admins your site names. Private notes are visible only to their author.
  • Notifications are sent by Jira itself (Jira's "notify" email on a work item your admin picks), under Jira's normal email settings. They never contain review, feedback or note content.
  • CSV exports are built in your browser from your site's data; nothing is uploaded.
  • Great Work LLC cannot see your data.

2. What the App processes

DataWhyWhere it lives
Settings: HR admin account ids and group ids, the notification work item key, the default project for action items, privacy switches, reminder and retention settingsTo run the AppForge key-value storage, until changed or uninstall
People directory: Atlassian account id, manager's account id, team name, job titleTo know who manages whom, which decides who can read whatForge SQL, until removed or uninstall
1:1s: the two account ids, title, schedule; per meeting the date, talking points (with who added them), shared notes, action items (text, owner, due date, linked work item key)The 1:1 record both people keepForge SQL, until uninstall
Private notes: the author's account id, what the note is about (a meeting, a review or a person) and the textThe author's own notesForge SQL, until uninstall
Review cycles: name, questions, rating scale, due dates, peer settings, teams in scope and the people reviewedTo run reviewsForge SQL, until deleted (drafts) or uninstall
Reviews: reviewee, author, kind (self, manager, peer), answers and ratings, state, shared and acknowledged times, a decline reasonThe review recordForge SQL, until uninstall
Feedback: sender, recipient, praise or suggestion, who may read it, the text, an optional work item key, the timeContinuous feedbackForge SQL, until deleted or uninstall
Goals: owner, title, what success looks like, due date, progress, state, linked work item keysPersonal development goalsForge SQL, until deleted or uninstall
Audit trail: time, who acted, whose record, the record type and id, the action (read, refused, changed) and a short descriptionSo HR admins can see who read and changed what, and each person can see who opened their recordsForge SQL, for the retention period in Settings (90 to 3,650 days, default 730)
Display names, the signed-in person's group membership, the Jira admin permission, titles of linked work itemsTo show names, decide who may see or change what, and show linked workIn memory only, fetched from Jira each time
Email addresses typed into a CSV importTo find the matching Jira userIn memory only; only the account id is stored
A license-state record (active or not, and when it was seen)So the daily job knows whether the subscription is activeForge key-value storage

Performance reviews, private notes and feedback can contain sensitive information about people. Your organization decides what its people write; advise them not to include health or other special-category details.

When a person turns a 1:1 action item into a Jira work item, the App creates it in Jira as that person, with only the action item's text and due date. From then on it is a normal Jira work item under your Jira permissions.

The App does not collect IP addresses, passwords, API tokens, payment details or analytics. It sets no cookies and loads no third-party scripts or fonts.

3. Where data is stored

All App data is stored by Atlassian in Forge storage for your site. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors. Data residency follows what Atlassian offers for Forge storage and Forge SQL (UNVERIFIED at time of writing: confirm coverage on Atlassian's current Forge data residency page before stating it in the listing).

4. Who can see what

The App checks on the server, for every read and every change, who is asking. Who is asking comes from Atlassian's platform, never from what the page sends.

  • The person sees their own goals, feedback sent to them (unless it was for their managers only), their own reviews, manager reviews once shared with them, and peer reviews if the cycle shares them (with or without the reviewers' names).
  • Managers (everyone above the person in the directory) see the person's submitted reviews, feedback and goals. They do not see the person's 1:1s with other people.
  • HR admins (people or group members named in Settings) see submitted reviews, feedback, goals and review completion for everyone, and the audit trail. They see 1:1 agendas, shared notes and action items only if the site turns that on (off by default). HR admin rights never apply to records about the HR admin themselves.
  • The two people in a 1:1 see its agenda, shared notes and action items.
  • Private notes are visible only to their author: not the other person, not managers, not HR admins, not Jira admins. They are never exported or included in a notification.
  • Drafts of reviews are visible only to their author.
  • Jira admins manage the App's settings. Being a Jira admin gives no access to people's records.
  • Other Jira users see nothing about anyone else.
  • Every read of someone else's review, feedback, goals or 1:1, and every refused attempt, is recorded in the audit trail. Each person can see who opened their records, unless the site turns that off.
  • Great Work LLC: no access. If you open a support request, we see only what you send us.
  • Atlassian: as the platform operator, under Atlassian's privacy policy.

5. Retention and deletion

Settings and the directory stay until an admin changes or removes them. 1:1s, private notes, reviews and closed cycles stay for the life of the installation, because they are the record. Feedback and goals stay until deleted (feedback by its sender or an HR admin; goals by the owner, their managers or an HR admin). The audit trail is deleted after the retention period set in Settings. Removing a person from the directory keeps their reviews, feedback and goals. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Notification emails that Jira sent, and work items people created from action items, are outside the App.

6. Support requests

If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request. Please don't send review text or notes in a support request.

7. Your rights

Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; contact your organization's HR admins. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.

8. Security

The App uses only Atlassian-hosted compute and storage, takes the signed-in person from Atlassian's invocation context, re-checks on the server who may see or change each record, records reads and refusals in an audit trail, keeps HR admin groups by id and refuses deleted ones, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.

9. Children

The App is a business tool and is not directed to children under 16.

10. Changes

We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.

11. Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company