LEGAL

Privacy Policy

What data Automation Doctor accesses, stores, and processes when installed on a Jira Cloud site.

1. Who we are

Automation Doctor for Jira is developed and maintained by AppRL. Contact: support@app-rl.com.

2. What the app does, in short

The app analyzes Jira Automation rules installed on the customer's site, estimates Automation Steps consumption, compares it against a monthly allowance configured by the administrator, and presents a review-priority panel. It is read-only: it never modifies, creates, pauses, or executes any automation.

3. Data the app accesses

3.1 Jira data

  • Automation rule definitions (name, state, triggers, conditions, actions, branches/loops), with sensitive fields redacted where the API offers that option.
  • Automation Steps consumption metrics per rule, when available.
  • Issue metadata strictly necessary to estimate a rule's trigger volume (e.g. approximate count of issues matching a JQL, field/status change history), without storing issue content.
  • List of Jira fields (names and IDs), used only to resolve which field a rule watches.

The app does not read issue comments, attachments, descriptions, or service management portal customer data beyond what is strictly necessary for the calculations above.

3.2 Administrator configuration

  • An email and API token of an administrator account, provided by the customer's administrator, used exclusively to authenticate calls to the Atlassian Automation API on behalf of the site.
  • The monthly Automation Steps allowance, entered manually by the administrator.
  • Interface language preference, per user account ID.

3.3 What the app does not collect

  • No payment card data (handled by Atlassian or the payment processor directly).
  • No third-party tracking cookies or pixels.
  • Data is never sold, rented, or shared with third parties for advertising.
  • Customer data is never used to train AI models.

4. Where data is stored

All storage uses Atlassian's own Forge Key-Value Store, within the data residency already configured for the customer's site. This includes the connection credential (stored as a secret, never exposed back to the frontend), the configured allowance, a short-lived cache of the current month's usage, and the language preference. No customer data is sent to any server operated by the developer outside Atlassian's Forge infrastructure.

5. Third-party sharing

The app only communicates with Atlassian's own domains: api.atlassian.com and the installed site's own *.atlassian.net domain. No data is sent to any third-party analytics provider or subprocessor.

6. Retention and deletion

  • The usage cache is automatically replaced every few minutes and is not kept as permanent history.
  • Disconnecting the app immediately deletes the stored credential.
  • Uninstalling the app removes all associated Forge storage, per the standard Forge platform policy.

7. Contact

Questions about this policy: support@app-rl.com.