keelapps/Prefill/Privacy policy
Privacy policy — Prefill for Jira
The short version
Prefill for Jira (“Prefill”, “the app”) is published by Keelapps. Prefill does not send your data anywhere. It runs entirely on Atlassian Forge, inside Atlassian's infrastructure. The app declares no external network permissions, which Atlassian enforces at the platform level — it cannot make an outbound call even if it tried. There is no Keelapps server, no analytics service, no third party.
What the app stores
Everything below lives in Forge hosted storage, on your own Atlassian site.
- Request forms you create. A name and description, the target project and issue type, and the field configuration — which fields the form fills, which it asks about, and the values you set for them. The account id of whoever created and last changed the form.
- Use counters. How many times each form was opened and submitted, and when it was last used. These are approximate by design.
- Recent issues. For each form, the last 20 issue keys it produced, with the account id of the person who submitted and a timestamp. Issue content is not stored — the summaries and statuses shown next to those keys are read from Jira live, each time you look.
- Site settings, and the last observed licence state.
What the app does not store
Issue descriptions, comments, attachments, email addresses, and any Jira content beyond the issue keys described above. The only personal data the app stores is Atlassian account ids; display names are resolved from Jira when a page renders and are not persisted.
One thing that is up to you
The values you set on a form are stored as you type them. If you put personal data into a field's default or fixed value, that data is in Forge storage. The app cannot tell the difference between a routing label and a person's name.
How issues are created
Issues are created as the person submitting the form, using their own Atlassian credentials. Jira's own permissions decide whether the issue can be created, the reporter is the real submitter, and the issue appears in Jira's audit trail exactly as if it had been created through Jira's own interface. Prefill cannot create an issue on behalf of someone who could not have created it themselves.
Prefill is for people who already have a Jira seat. It does not provide anonymous or external submission, and it cannot: that would require an external server, and this app makes no external calls.
Who can see what
- The request form behind a link is visible only to signed-in Jira users who have permission to create issues in the target project.
- Values a form hides from submitters are applied on the server and are never sent to a submitter's browser.
- Site-wide lists of forms are visible only to Jira administrators.
Retention and deletion
Deleting a form removes its definition, its counters and its recent-issue list. Uninstalling the app removes everything the app has stored on your site, in accordance with Atlassian's Forge data lifecycle. Issues that were created through a form are ordinary Jira issues and are unaffected.
Sub-processors
None. Atlassian hosts everything; there is no other party involved, and Keelapps has no access path to your data. Forge storage is reachable only by the app itself, running inside Atlassian's infrastructure.
Because no data is transmitted outside Atlassian's infrastructure and the vendor neither accesses, stores nor transmits customer data, Keelapps is not a data processor for the purposes of this app. If your compliance team requires a Data Processing Addendum, Atlassian's standard addendum for the platform applies.
Data residency
Because everything is stored in Forge hosted storage, data residency follows your Atlassian site's data residency configuration automatically.
Changes
Material changes to what is stored or where will be reflected here and in the Marketplace listing before they ship. The effective date above moves with any change.
Contact
support@keelapps.atlassian.net — for questions about this policy, and for data access, correction or deletion requests.