Portfold for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Portfold app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- Project field definitions, values, change history, saved views and settings are saved in your site's Forge storage, hosted by Atlassian.
- The register and CSV downloads are created in the browser and saved to the user's device.
- Great Work LLC cannot see your projects, field values or history.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Field definitions (names, types, descriptions, options and colors, flags) | To show and edit project fields | Forge app storage until uninstall |
| Field values per project, including people chosen in person fields (Atlassian account id and display name) | The project page, register, CSV and JQL | Forge app storage until uninstall or until cleared |
| Change history per project: time, Atlassian account id and display name of the person, field name, old and new value as text | The History tab | Forge app storage, the latest 300 changes per project |
| Saved views (name, owner account id and display name, columns, filters, sort, grouping, shared flag) | Saved and shared register views | Forge app storage |
| Settings (who can edit) and the last license state seen | To run the App | Forge app storage |
| Project id, key, name, category, lead, type and avatar read from Jira | To show the register and project page | In the browser and in memory during the request |
| CSV files Jira admins import | To fill field values | In memory during the import |
| Your account id and permissions | To decide what you may see and change | In memory only |
The App does not read work items, comments or attachments. The JQL function returns project ids to Jira; Jira then applies each person's permissions. The App does not collect IP addresses, passwords, API tokens, payment card details or analytics. It sets no cookies and loads no third-party scripts or fonts.
3. Where data is stored
All App data is stored by Atlassian in Forge app storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Anyone who can browse a project can see its field values and history. The register only lists projects the signed-in person can browse.
- Editing values needs the permission your Jira admin chose (project admins by default); fields marked admin-only need a Jira admin. Field definitions, settings and CSV import are limited to Jira admins.
- Shared saved views are visible to everyone on the site; personal views only to their owner (Jira admins can manage all views).
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Values and history stay until a Jira admin clears them or the App is uninstalled, after which Atlassian deletes the App's Forge storage according to its Forge data deletion process. Files you downloaded are under your organization's control.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request. Please send only what we need to help.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage, reads Jira as the signed-in person for everything a person sees, re-checks every permission on the server, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company