Tracestitch: Requirements and Traceability for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Tracestitch app for Jira Cloud and Confluence Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party. It uses no AI service.
- When a space admin turns the App on for a Jira space, the App reads the work items of the chosen requirement types, keeps a copy of their text (summary, description and any fields the admin chose) each time it changes, and records which linked work items were reviewed against which version.
- Great Work LLC cannot see your requirements, your Jira data or your settings.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Space settings: requirement types, ID prefix, test and defect type names, link types, extra text fields, default folder, the account id of the admin who saved them | To decide what is a requirement and how links count | Forge SQL for your site, until changed or the App is uninstalled |
| Requirements: work item id and key, the requirement ID, folder, title, status, version number, coverage verdict, counts of trace and suspect links | To show the tree, lists, matrix and coverage | Forge SQL, until the App is uninstalled (a requirement deleted in Jira is kept as "retired" so baselines and history stay readable) |
| Versions: the requirement's title and text as plain text at each change, a content hash, the status at that time, when it changed and the account id of who changed it | Version history, diffs, baselines, the Confluence macro | Forge SQL, until the App is uninstalled |
| Link reviews: requirement and linked work item ids and key, the version reviewed, the account id of the reviewer and when | Suspect links | Forge SQL, removed when the link is removed |
| Folders and baselines: names, notes, scope, who took a baseline and when, and per requirement in the baseline its ID, key, version, title, status, folder path, coverage and linked work item keys with their role and status | Tree and baselines | Forge SQL, until a space admin deletes the baseline or the App is uninstalled |
| Activity log: time, account id, action, short detail | So space admins can see who did what | Forge SQL |
The tracestitch work item property (requirement ID, version, coverage, suspect and trace counts) | JQL (reqId, reqCoverage, ...) | On your Jira work items, managed by the App |
| Last license state seen, schema marker | Licensing and upgrades | Forge app storage |
The App does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. What the App reads but does not store
The App asks Jira for the signed-in person's permissions in a space, which work items a
Confluence reader can browse, work item types, link types and text field names. It reads the
gherkit work item property (written by Great Work's Gherkit app, if installed) to count BDD
scenarios. None of this is stored.
4. Where data is stored
All App data is stored by Atlassian in Forge storage (Forge SQL and Forge app storage) for your site, subject to Atlassian's data residency settings. Jira is the App's required product, so all of its data is stored in your Jira site's data residency location, per Atlassian's multi-app rules. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
5. Who can see what
- Everyone who can browse a Jira space can open its Requirements page; every list, matrix and baseline is filtered to the work items that person can see in Jira.
- People who can edit work items in the space can arrange folders, take baselines and mark links reviewed. Space admins change settings, delete baselines and read the activity log.
- In Confluence, a reader sees a requirement in the macro only when Jira says they can browse it.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
6. Retention and deletion
Requirement history is kept so that versions and baselines stay comparable. Space admins can
delete baselines. Uninstalling the App removes its Forge storage according to Atlassian's Forge
data deletion process; the tracestitch work item properties stay on work items until removed
by an admin through Jira.
7. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
8. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Atlassian site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
9. Security
The App uses only Atlassian-hosted compute and storage, checks the person's Jira permissions on every request, filters every list to the work items the person can see, and logs every settings change, baseline and review. Report vulnerabilities to hello@greatwork.company.
10. Children
The App is a business tool and is not directed to children under 16.
11. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
12. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company