Privacy Policy — Linkwright for Jira
Effective date: 30 September 2026
Saad Lagzouli, sole proprietor (entrepreneur individuel) trading as Linkwright (SIREN 130 855 364, France) (“we”) publishes Linkwright for Jira (the “App”), an Atlassian Forge app that shows GitHub activity — commits, branches, pull requests, reviews and deployments — on Jira issues.
1. Where the App runs and where data is stored
The App is built on Atlassian Forge. Its code runs on Atlassian’s infrastructure and all data it stores is kept in Forge storage (Forge SQL and Forge key-value storage) belonging to your Jira site, isolated from every other customer. We operate no server of our own and do not copy your data to any system we control.
2. Data the App processes
2.1 From GitHub, for repositories you attach to a Jira project
- repository names (
owner/name), which include the GitHub login of a personal account owner; - branch names, and the GitHub name of the user who pushed a new branch;
- commit identifiers, first line of commit messages, author names, dates, number of changed files;
- pull request numbers, titles, states, author logins, requested reviewer logins, comment counts;
- review states and reviewer logins;
- deployment identifiers, environment names, states and commit identifiers.
Only repositories that (a) the GitHub App has been granted access to by the GitHub account owner, (b) belong to a GitHub installation associated with your Jira site, and © are attached to a Jira project by a project administrator are read.
2.2 When a Jira administrator associates a GitHub installation
The administrator authorizes the App on GitHub once. Through that authorization the App reads the administrator’s GitHub user, the installations of the App they can access, and their role in the corresponding organizations, to verify they control the installation. The App stores the installation identifier, the account name and type, and the administrator’s GitHub login. The OAuth token is stored and refreshed by Atlassian Forge, not by our code. The App does not store Atlassian account identifiers.
2.3 Operational data
Synchronization state per repository (timestamps, error kinds), identifiers of the commits already sent to Jira’s Development panel (so none is sent twice), GitHub API quota counters, webhook delivery identifiers (kept 24 hours to discard duplicates), and a per-site webhook secret and GitHub installation token held in Forge encrypted storage.
3. How the data is used
Solely to provide the App’s features on your Jira site: linking GitHub activity to issues, displaying it in the App’s issue panel and in Jira’s native Development panel, and reporting how up to date it is. We do not sell data, use it for advertising, profile individuals, or train models on it. The App displays no advertising.
4. Where data is sent
- Your Jira site (Atlassian’s Jira APIs): the data in §2.1 is sent to Jira’s development and deployment information APIs so it appears in the native Development panel. It stays on your site.
- GitHub (
api.github.com): the App sends identifiers needed to read repositories, the GitHub App’s credentials, and, when it creates a repository webhook, your site’s webhook address and secret. No Jira data is sent to GitHub. - No other third party receives data.
5. Logs
Forge function logs, visible to us for support and debugging, contain repository names, issue keys, branch names, environment names, counters, identifiers and error messages. They do not contain commit messages, author names or emails, reviewer logins, tokens or secrets. Repository names can contain a personal GitHub login (see §2.1). Logs are retained according to Atlassian Forge’s log retention.
6. Retention and deletion
- Data stays in your site’s Forge storage while the App is installed.
- Detaching a repository from its last project deletes its webhook on GitHub and removes it from Jira’s Development panel.
- Uninstalling the App deletes the data the App sent to Jira’s Development panel (Jira behaviour) and the App’s Forge storage for your site, according to Atlassian Forge’s data deletion rules: Forge keeps that storage for 28 days after uninstallation (soft deletion, so that an accidental uninstall can be recovered on request within 21 days), then erases it. We keep no copy elsewhere.
- To request deletion earlier, contact saad@linkwright.io.
7. Security
Webhook deliveries are verified with an HMAC signature using a per-site secret and rejected otherwise; secrets are held in Forge encrypted storage; database queries are parameterized. Vulnerabilities are handled under the Atlassian Marketplace security bug fix policy.
8. Your rights
Where data protection law such as the GDPR applies, the customer operating the Jira site is the controller of the data processed by the App and we act as a processor. Individuals may exercise their rights through that customer or by contacting saad@linkwright.io.
9. Changes
We will update this policy when the App’s data processing changes and change the effective date above.
10. Contact
Saad Lagzouli, sole proprietor (entrepreneur individuel) trading as Linkwright (SIREN 130 855 364, France) — saad@linkwright.io