← Pivotwell

Pivotwell for Jira: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Pivotwell app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.

1. Summary

  • The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
  • Great Work LLC cannot see your Jira work items, worklogs, reports or anything the App shows.
  • The App's own storage, hosted by Atlassian for your site, holds saved report definitions, short-lived results of pivots per person, and records of background runs.

2. What the App processes

DataWhyWhere it lives
Saved reports: name, description, JQL, chosen fields, measures, filter values (for example label names, option values, account ids of picked people), display options, owner and editor account ids, shared group ids and namesTo reopen, share and show reports on dashboardsForge app storage for your site, until the report is deleted
Pivot results for one person: row and column labels (for example assignee display names, status names, epic keys and summaries) and the numbers in each cell, plus the JQL behind themSo reopening a report or a dashboard widget is fast, and so large pivots computed in the background can be shown when they finishForge app storage for your site, per person; used for up to the cache time an admin sets (default 60 minutes) and deleted after 2 days
Background run records: the person's account id, the pivot settings, progress and any error messageTo compute large pivots on Atlassian's servers as that person and show progressForge app storage for your site; deleted after 1 day
Work item fields and worklogs returned by Jira (only the fields a pivot needs)To compute the pivot and list the work items behind a cellRead in memory during one request or one background run, as the person who ran it; never stored item by item
The person's Atlassian account id with a count of pivots run and whether they dismissed the review promptTo ask for a review at most onceForge app storage for your site; expires after 365 days
Site settings (result cache time)Admin choiceForge app storage for your site

CSV and Excel files are created in your browser and saved to your device; they are never uploaded. The App does not collect email addresses, passwords, API tokens, payment information, IP addresses or analytics. It sets no cookies and loads no third-party scripts.

3. Where data is stored

All App data is stored by Atlassian in Forge storage associated with your Jira site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors for the App.

4. Who can access it

  • People on your site: every pivot reads Jira as the person viewing it (or, for background runs, as the person who started the run), so they only ever see work items and worklogs that person can see. Results are cached per person and never shown to anyone else.
  • Report owners, editors and viewers: see the report's definition as it was shared with them.
  • Jira admins: can see every saved report's name, owner and sharing, change its owner or delete it.
  • Great Work LLC: no access. If you open a support request, we see only what you send us.
  • Atlassian: as the platform operator, under Atlassian's privacy policy.

5. Retention and deletion

Reports remain until their owner, an editor with permission or a Jira admin deletes them. Cached results are deleted after 2 days, run records after 1 day, the review flag after 365 days. Uninstalling removes Forge app storage according to Atlassian's Forge data deletion process.

6. Support requests

If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.

7. Your rights

Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete reports or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.

8. Security

The App uses only Atlassian-hosted compute and storage, requests read-only Jira access plus its own app storage, acts as a person for every Jira request (so Jira permissions always apply), checks every JQL query with Jira's strict parser before running it, quotes every value it adds to a query, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.

9. Children

The App is a business tool and is not directed to children under 16.

10. Changes

We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.

11. Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company