Sumtree for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Sumtree app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It reads work items (numbers such as story points, estimates, time spent and the number fields your admins choose, plus status, work type and parent) and writes totals into the custom fields your admins create from its field type. It writes nothing else.
- Great Work LLC cannot see your work items, your totals or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Work item facts: id, key, summary, parent, project, work type, status, and the values of the fields a rollup is configured to read (story points, original estimate, time spent, remaining estimate, chosen number fields) | To compute the totals | In memory while a calculation runs; not stored by the App |
| Rollup values (numbers) | The App's output | In your Jira, in the custom fields created from the App's field type, like any other field value |
| Rollup settings per field context (what to add up, filters, units, display suffix) | To apply your admins' choices | Stored by Jira against the field context |
| Admin settings: largest tree size, story point field choice, daily catch-up on or off | To apply your admins' choices | Forge app storage until uninstall |
| Activity log: time, trigger (event, job, manual), work item ids, counts of values updated, error text | So admins can see what the App did | Forge app storage; deleted automatically after 30 days |
| Background jobs: the JQL an admin entered, the admin's Atlassian account id, progress counts | To run "Recalculate" and the daily catch-up in the background | Forge app storage; deleted automatically after 30 days |
| Short-lived caches: the field list and field context settings | Speed | Forge app storage; deleted automatically after 5 minutes |
The App does not read descriptions, comments, attachments or worklog text, and it does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Where data is stored
All App data is stored by Atlassian, in your Jira site (field values and field context settings) or in Forge app storage for your site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Rollup field values are visible to everyone who can see the work item, like any Jira field.
- The Rollup breakdown panel reads as the person viewing it, so it lists only child work items that person can see.
- Jira admins see the admin page, its activity log and jobs.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Activity entries, jobs and caches expire automatically (see section 2). Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Fields created from the App's field type disappear from Jira when the App is uninstalled and come back with their data if it is reinstalled within 30 days (Atlassian's rule for Forge custom fields).
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can delete the App's fields or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. It can write only to fields of its own field type (Jira enforces this), the breakdown panel reads as the viewing user, and admin functions check the Jira admin permission on every call. It keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company