Privacy policy
Successor is an Atlassian Forge app that runs entirely on Atlassian infrastructure. It makes no network calls outside Atlassian - there is no server of ours for your data to travel to.
What we store
All of it in Atlassian Forge storage, inside your own Atlassian instance's trust boundary:
- Atlassian account IDs and display names of the people involved in a run - the person leaving, the person taking over, and the administrator who ran it.
- Per-artifact results for each run, including the error messages Jira returned on any write that did not land.
- Completion attestations for manual steps: who ticked an item and when, including previous attestations on items that were later un-ticked.
- Which checks could not be completed during a scan, and why.
- The app's own settings.
This is the audit evidence the app exists to produce.
What we never store or access
- Credentials, API tokens or passwords.
- Email addresses.
- Issue content, comments or attachments.
There is no analytics, no tracking, no telemetry, and no third-party service of any kind.
Retention
Run history is capped at the 200 most recent records; older records are deleted automatically as new ones are made. Uninstalling the app deletes all of its storage - this is enforced by the Forge platform, not by us. One platform detail: Atlassian keeps the storage of an uninstalled app recoverable for 28 days, so that a reinstall can be re-linked to its history if you ask Atlassian for it; after 28 days it is gone. The app itself holds nothing once it is uninstalled.
Closed Atlassian accounts
Once a week the app reports the account IDs it holds to Atlassian's personal data reporting service, as Atlassian requires of every app that stores personal data. When Atlassian answers that an account has been closed, the app erases that person's account ID and display name from every stored run; the run itself remains, showing "Deleted Atlassian account" in their place. When Atlassian answers that a profile changed, the stored display name is refreshed. Deactivating or suspending a user in your site is not an account closure and changes nothing here.
Access
Only Jira administrators of your site can open the app or read anything it has stored. Every backend call independently re-verifies the caller's administrator permission rather than trusting that the request came from the app's own page.
Data processors
Atlassian, via the Forge platform, is the only processor. Data never leaves Atlassian's infrastructure, so there is no sub-processor list to publish.
Data residency
Everything the app stores lives in Atlassian Forge hosted storage. Atlassian keeps that storage in the same location as your Jira instance and moves it when you move Jira, so the app appears as pinned in Atlassian Administration once your Jira data is pinned.
In scope for data residency, meaning stored in your chosen location:
- Atlassian account IDs.
- User display names.
- Run records: Jira artifact names, ids, outcomes and error messages.
- Checklist attestations: the administrator's name and the timestamp.
Out of scope: nothing. The app stores no other End-User Data, and none of it is held anywhere else.
Changes to this policy
If this policy changes, the effective date above changes with it. Material changes will be noted in the app's release notes on the Atlassian Marketplace.
Contact
Questions about this policy, or about data held by the app: support@rigelapps.dev.