Unstep for Jira: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Unstep app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.
1. Summary
- The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
- It reads an issue's history to find the last status change and changes the issue back only when a person with the right Jira permissions asks it to.
- Great Work LLC cannot see your issues, your audit log or who used the App.
2. What the App processes
| Data | Why | Where it lives |
|---|---|---|
| Issue facts: key, summary, status, resolution, project, and the issue's change history (who changed which field, when, old and new values) | To find the last transition and show what an undo would change | In memory while the dialog or a bulk job runs; not stored |
| Audit log entries: time, issue id and key, project key, who undid it (Atlassian account id and display name), from and to status, who made the original change and when, names of fields put back or that failed, bulk job id | So admins can see every undo | Forge app storage for your site; deleted automatically after the retention you set (30 to 365 days, default 365) |
| Bulk undo jobs: the JQL and filters, the admin who started it, issue ids and keys, per-issue result text | To run the job in the background and show results | Forge app storage; deleted automatically after 90 days |
| Redo marks: issue id and the change-history id of the last undo | So the next click on that issue reads "Redo" | Forge app storage; deleted automatically after 30 days |
| Admin settings: project roles, group names and ids, project keys, time limit, comment and retention choices | To apply your admins' choices | Forge app storage until uninstall |
| Your account id, display name, project roles, groups and permissions | To decide whether you may undo a change | In memory only |
| Workflow definitions (admin page only) | To show which statuses have a way back and add or remove the App's hidden transitions when a Jira admin confirms | In memory only; changes are made in your Jira |
The App does not read issue descriptions, comments or attachments beyond what appears in the change history, and it does not collect email addresses, IP addresses, passwords, API tokens, payment information or analytics. It sets no cookies and loads no third-party scripts.
3. Where data is stored
All App data is stored by Atlassian in Forge app storage for your Jira site, subject to Atlassian's data residency settings. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors.
4. Who can see what
- Any user who opens the undo dialog sees the last status change on that issue and the fields it changed (the same information as the issue's History tab).
- If comments are turned on, the comment the App adds after an undo is visible to everyone who can see the issue, like any Jira comment.
- Jira admins see the full audit log and all bulk jobs; project admins see the audit log entries for their project and their own bulk jobs.
- Great Work LLC: no access. If you open a support request, we see only what you send us.
- Atlassian: as the platform operator, under Atlassian's privacy policy.
5. Retention and deletion
Audit entries, bulk jobs and redo marks expire automatically (see section 2). Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process. Status changes, field changes and comments the App made are ordinary Jira changes and stay in your issues and their history.
6. Support requests
If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.
7. Your rights
Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf; your admins can shorten the audit retention or uninstall the App. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.
8. Security
The App uses only Atlassian-hosted compute and storage. It reads issues as the signed-in user, checks Jira permissions and the admin's undo rules before every undo, re-checks every issue before a bulk undo changes it, and changes workflows only after a Jira admin confirms and Jira's own validation passes. It keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.
9. Children
The App is a business tool and is not directed to children under 16.
10. Changes
We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.
11. Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company