Privacy Policy — Access Review for Jira

Last updated: 14 June 2026

Access Review for Jira ("the App") is a Forge app that runs entirely on Atlassian's infrastructure. It helps Jira administrators see who can access which projects and why, detect access risks, and produce access-review evidence. This policy explains what data the App processes and how.

Data the App accesses

To build the access picture, the App reads the following configuration and identity metadata from your Jira site, using read-only Atlassian APIs:

The App requests read-only permission scopes only. It never modifies your Jira configuration or data.

Where data is processed

All processing happens inside Atlassian's Forge platform. Your data never leaves Atlassian's infrastructure. The App makes no calls to any external service and transmits no data to the vendor or any third party. The App qualifies for Atlassian's "Runs on Atlassian" program.

Data the App stores

Using Forge's hosted storage (which resides within Atlassian), the App stores only:

Exports (CSV / PDF) are generated in your browser on demand and are not stored by the App.

Access control

The App is available only to users with the Administer Jira permission, and it surfaces only data those administrators are already entitled to see.

Data retention & deletion

Stored review rounds and cache remain in your site's Forge storage until you remove them or uninstall the App. Uninstalling the App removes its stored data per Atlassian's Forge data-lifecycle handling.

Contact

Questions about this policy: contact@flowtimeapps.com. See also the support page.