Rulewell for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Rulewell app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- Rule settings are stored by Jira on your workflow transitions. The App's own storage (Forge key-value storage, hosted by Atlassian) holds a run log, round-robin counters, the last usage scan and a license-state record.
- Great Work LLC cannot see your rules, your work items or your run log.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Rule settings: the kind of rule, field ids and names, values to compare, link type names, status ids, group names, project role ids, JQL, messages, summary and comment templates, labels, user field ids, sometimes Atlassian account ids (watchers) | To run the rule | On the workflow transition, stored by Jira (like any workflow setting) |
| Run log: time, work item key, rule kind and label, outcome, a short description (for example "assigned OPS-12 to Ana Silva" or "no comment") | So admins can see what post functions did and which checks refused a move | Forge key-value storage, deleted automatically after 90 days |
| Round-robin counters: a number per "Assign by rule" post function | To assign in turn | Forge key-value storage, until uninstall |
| Usage scan: workflow names, transition names, status names, project ids, keys and names, rule summaries | The admin page's usage list and the license switch | Forge key-value storage, replaced every hour |
| License-state record (active or not, and when it was seen) and a development-install marker | So background functions know whether the subscription is active | Forge key-value storage |
The rulewell-license project property ({"off": true}) | Switches Rulewell's validators and conditions off while the subscription is inactive | On projects that use a Rulewell rule, only while inactive |
| Work item data read while a rule runs: key, summary, status, parent, children and their statuses, links and linked items' statuses, attachments' file names, assignee, reporter, labels, components, the fields a rule names, the comment typed on the transition | To evaluate the rule or do the action | In memory during the request (Jira evaluates expression rules itself) |
| Group and project role members, display names | To assign by rule and show names | In memory |
The App does not collect IP addresses, passwords, API tokens, payment card details or analytics. It sets no cookies and loads no third-party scripts or fonts.
3. Where data is stored
All App data is stored by Atlassian, in Jira and in Forge storage for your site. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors. Data residency follows what Atlassian offers for Forge storage.
4. Who can see what
- Jira admins add, change and remove rules (in Jira's workflow editor or on the App's admin page) and see the usage list and the run log.
- People who move work items see the messages your rules show and the changes post functions make, like any other Jira change.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Rule settings stay on your workflows until an admin removes the rule or the workflow. The run log
is deleted after 90 days. Uninstalling the App removes its Forge storage according to Atlassian's
Forge data deletion process. Work items the App created or changed, its comments and the
rulewell-license property are Jira data and stay unless you delete them.
6. Support requests
If you contact support by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage, re-checks Jira admin permission on the server before any workflow change, validates JQL with Jira's strict parser before saving, never places text you type into the code Jira evaluates (it is passed as data), and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company