User Access Review for Jira — Privacy Policy

Last updated: 14 August 2026. Applies to the User Access Review for Jira Cloud app.

The short version

User Access Review runs entirely on Atlassian's Forge platform. It has no external server and no egress permission in its manifest, so your data never leaves Atlassian's infrastructure. The app is read-only and stores nothing: every table is rebuilt from Jira each time you open the page.

What data the app accesses

Within your Jira Cloud site only, and only for the project whose page you are viewing:

The data touched is therefore: project role names and the users and groups that hold access to a project (Atlassian account IDs, display names, group names), together with how that access is granted — through a role, a group or a direct grant.

Requests to Jira are made as the app rather than as the viewer, so the page can show the complete role and audit picture instead of a partial one. Precisely because of that, the app checks your own permissions before it makes those requests: the permissions table requires the Administer Projects permission on the project you are viewing, and the audit report requires the site-wide Administer Jira permission. That check is made against Jira with your own credentials, and it fails closed — if it cannot be completed, access is refused rather than granted.

Where data is stored and processed

What the app does not do

Data retention and deletion

Access snapshots are retained for 400 days, and older ones are removed automatically whenever a new snapshot is written. That window is deliberately just over a year: the audit periods this app is built for (ISO 27001, SOC 2) run twelve months, while Jira's own audit log stops at 180 days. Uninstalling the app immediately ends its access to your Jira site, and its Forge storage is discarded with the installation; reinstalling starts a fresh history rather than restoring the old one. Nothing is written into Jira itself, so uninstalling leaves no residue there.

Contact

Questions about this policy: info@kyc-checks.nl.