This policy sets out how data is handled in the Atlassian Marketplace apps provided by Forgood (hereinafter "the Developer").
All of these apps run on Atlassian Forge. Both the code execution and the data storage stay entirely inside Atlassian's infrastructure, and no data is sent to any external server operated by the Developer.
The apps use only Atlassian's Forge Storage. The Developer cannot view the contents of that storage directly.
Permissions: read:page:confluence, read:space:confluence, read:attachment:confluence, storage:app
What it stores
What it does not store
Writes: "Writes nothing (read-only)."
Permissions: read:jira-work, write:jira-work, storage:app
What it stores
What it does not store
Writes: When you press Restore, it creates one new issue. It writes nothing else.
Retention: 90 days by default. You can change it to anywhere from 1 to 3650 days in settings. Records past the retention period are deleted daily, and are excluded on read as well. When the record limit (5,000 by default) is exceeded, the oldest records are deleted too.
Permissions: read:page:confluence, read:blogpost:confluence, read:space:confluence, read:content.metadata:confluence, read:comment:confluence, write:comment:confluence, read:user:confluence, search:confluence, read:content-details:confluence, storage:app
What it stores
What it does not store
Writes: When an approval is requested, when someone responds, and when an approved page is edited, it posts one comment on that page. It does not rewrite the page content (it does not request write:page:confluence, so it technically cannot).
Retention: Approval records are never deleted automatically. This app exists to keep them as an audit record, and a record that disappears at a deadline would defeat the point. Rounds are capped at 25 per page, and anything beyond that drops off oldest-first (storage is also capped at 60KB per page). Uninstalling the app deletes the Forge storage along with it (if you reinstall within Atlassian's retention period, the earlier records may still be there).
Permissions: read:jira-work, read:jira-user, storage:app
What it stores
What it does not store
Writes: Writes nothing. The app does not request write:jira-work, so it cannot change a single issue.
Retention: Settings are kept in Forge storage and are deleted when you uninstall the app. No issue content is stored at all — each export is assembled on the spot and handed straight back to your browser.
Some apps store your Atlassian account ID and display name. Where an app does, it is stated explicitly in the per-app list above. There is exactly one purpose: to keep a record of who did what — who changed a date, who deleted an issue, who gave an approval. They are used for nothing else.
Email addresses, IP addresses, browser information and behavioral logs are never stored at all. The account ID and the display name are both values that Atlassian already manages inside your own site.
If you want a particular record deleted, contact us through support. Some records can also be deleted directly from the app's own screens (records of deleted issues one at a time; change logs automatically, once the retention period has passed).
The data these apps handle is never disclosed or sold to third parties. No data is sent to analytics tools, to advertising, or to external AI services. The apps make no outbound network connections while running.
In normal operation, the Developer does not access your data. If access is required in order to investigate a fault, it is done only with your permission obtained in advance, and only to the extent necessary.
When you uninstall an app, the data that app stored in Forge Storage is deleted in accordance with Atlassian's specification. However, Atlassian keeps the data for a period after uninstallation, and if you reinstall the same app within that period the earlier data may still be present (the retention period is set by Atlassian, and we cannot change it). If you want data deleted immediately, contact us through support.
For Recover for Jira, individual records can be deleted from inside the app, and records are also deleted automatically according to the retention period setting.
These apps comply with Atlassian's partner terms and with the Forge security requirements. For how Atlassian itself handles data, please refer to Atlassian's privacy policy.
If this policy is changed, the last-updated date on this page will be revised. If a change is significant, we will also announce it in the Marketplace release notes.