← WIPGate

WIPGate for Jira: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the WIPGate app for Jira Cloud (the "App") processes, where it is kept, and your rights. It covers only the App, not Atlassian's products, which are governed by Atlassian's own privacy policy.

1. Summary

  • The App runs entirely on Atlassian's Forge platform ("Runs on Atlassian"). It has no servers of its own and sends no data to Great Work or to any third party.
  • WIP limit rules, settings and a capped activity log (the latest 400 events) are stored in your site's Forge storage (key-value store), hosted by Atlassian.
  • Counts of work in progress are read from Jira search when they are needed and are not stored.
  • Great Work LLC cannot see your rules, your work or the log.

2. What the App processes

DataWhyWhere it lives
Rules: name, scope JQL, exemption JQL, status ids, field id and name, limits, individual limits (keyed by Atlassian account id or by field value), mode, override group ids and names, who last changed the rule (account id) and whenTo check limitsForge storage, until the rule is deleted or uninstall
Settings: what to do when a limit cannot be checked, an extra line for block messagesTo run the AppForge storage
Activity log: time, rule, work item key, the person's display name or field value the limit applied to, count, limit, outcome (blocked, warned, override, reassigned over limit, not checked), the account id of the person who moved the work when Jira provides it, an error noteSo admins can see blocks and overridesForge storage, the latest 400 events, until overwritten or uninstall
The work item being moved: key, status, work type, assignee (account id), and the one field a rule counts perTo decide whether the move fitsIn memory during the check
Counts and, for the overview, work item keys plus the assignee or the counted fieldTo show counts against limitsIn the browser and in memory during the request
Your account id, Jira admin permission, and (for overrides) the groups of the person moving workTo decide what you may change and who may go over a limitIn memory only
Display names of people with individual limits or on the overviewTo show namesIn the browser; display names in the activity log as above
A license-state record (active or not, and when it was seen)So the validator knows whether the subscription is activeForge storage

The App does not read work item summaries, descriptions, comments or attachments, and does not collect IP addresses, passwords, API tokens, payment card details or analytics. It sets no cookies and loads no third-party scripts or fonts.

3. Where data is stored

All App data is stored by Atlassian in Forge storage for your site. Atlassian is the hosting provider and acts as a subprocessor under Atlassian's terms. Great Work LLC uses no other subprocessors. Data residency follows what Atlassian offers for Forge storage (UNVERIFIED at time of writing: confirm Forge key-value storage residency coverage on Atlassian's current Forge data residency page before stating it in the listing).

4. Who can see what

  • Only Jira admins can create, change or delete rules and settings, and only they see the activity log.
  • Anyone with access to the App sees the WIP overview. Counts are computed as that person, so work they cannot browse in Jira is not counted for them and is never listed.
  • The person moving a work item sees a block message naming the rule, the person or value, the count and the limit.
  • Great Work LLC: no access. If you open a support request, we see only what you send us.
  • Atlassian: as the platform operator, under Atlassian's privacy policy.

5. Retention and deletion

Rules stay until an admin deletes them. The activity log keeps the latest 400 events; older ones are overwritten. Uninstalling the App removes its Forge storage according to Atlassian's Forge data deletion process.

6. Support requests

If you contact support through our help desk or by email, we process what you send (name, email, message, attachments) only to answer you, keep it up to 24 months, and delete it sooner on request.

7. Your rights

Depending on where you live (for example EU/UK GDPR or US state privacy laws), you may have the right to access, correct, delete or port personal data and to object to processing. For data in your Jira site, your organization (the Atlassian customer) is the controller and Atlassian processes it on your behalf. For support data, Great Work LLC is the controller: email hello@greatwork.company. We respond within 30 days.

8. Security

The App uses only Atlassian-hosted compute and storage, reads Jira as the signed-in person in its pages, re-checks admin permission on the server for every change, validates every JQL query with Jira's strict parser before saving it, and keeps no secrets of its own. Report vulnerabilities to hello@greatwork.company.

9. Children

The App is a business tool and is not directed to children under 16.

10. Changes

We will post changes here and update the effective date. Material changes will also be announced in the App's Marketplace release notes.

11. Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company