keelapps/Digest/Privacy policy
Privacy policy — Digest for Jira
The short version
Digest does not send your data anywhere. It runs entirely on Atlassian Forge, inside Atlassian's infrastructure. The app declares no external network permissions, which Atlassian enforces at the platform level. The optional Jira-notification channel is delivered by Jira's own notification service — there is no external email provider, no vendor server, no third party.
What the app stores
Everything is stored in Forge app storage (Atlassian-hosted KVS) inside your own Atlassian tenant region.
| Data | Examples | Why |
|---|---|---|
| Subscriptions | JQL, cadence, timezone, grouping, owner account id | to know what to roll up and when |
| Digest bodies | issue keys, truncated summaries, short change labels (“Status: To Do → In Progress”) | the content you asked for |
| Inbox | a ring buffer of your recent digests | so you can read them in-app |
| Site counters | number of subscriptions, deliveries, suppressed empty periods | the admin page shows counts only |
Digest bodies deliberately never contain issue descriptions, comment bodies, or ADF. Personal data is limited to Atlassian account ids (the subscription owner, and accounts that @mention them).
What is never stored
- Issue descriptions, comment bodies, or rich-text content
- Email addresses — unless you enable the optional Jira-notification channel, in which case delivery is handled entirely by Atlassian's infrastructure
- IP addresses, usage analytics, or behavioural tracking
Who can see it
Digests are generated with app permissions and re-filtered against the viewer's own permissions when they are opened. Anything the viewer cannot see is stripped and counted — the check fails closed. The admin page shows counters only: no queries, no names, no account ids, no issue data.
Retention and deletion
- The inbox is a ring buffer: older digests are replaced by newer ones.
- Deleting a subscription deletes its digests.
- Uninstalling the app removes all Forge storage.
Data residency
Whatever your Atlassian site's residency is. Digest adds no storage outside Forge and therefore introduces no additional residency considerations.
Sub-processors
None. Atlassian hosts everything; there is no other party involved.
Changes
Material changes to what is stored or where will be reflected here and in the Marketplace listing before they ship.
Contact
support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.