Privacy Policy
Effective Date: January 2025
Last Updated: January 2025
Overview
Jirvana ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how our AI Sprint Assistant app collects, uses, and protects information when you use our service through the Atlassian Marketplace.
Information We Process
Data We Access
Jirvana accesses the following Jira data to provide AI analysis:
- Sprint Information: Active sprint details, start/end dates
- Issue Metadata: Ticket keys, summaries, statuses, assignees
- Project Data: Project keys and basic project information
- Workflow Data: Issue transitions and status changes
- Relationship Data: Issue links and dependencies
Data We Do NOT Collect
- Personal Information: Names, email addresses, phone numbers
- Sensitive Content: Issue descriptions, comments, attachments
- User Activity: Browsing history, click tracking, usage patterns
- Authentication Data: Passwords, API tokens, or credentials
How We Use Information
AI Analysis
- Pattern Recognition: Identify blockers and dependencies
- Workload Analysis: Assess team capacity and balance
- Performance Insights: Detect velocity risks and optimization opportunities
- Recommendation Generation: Create actionable sprint improvements
Service Provision
- Real-time Processing: Analyze current sprint data when you access the app
- Insight Generation: Provide 5 actionable recommendations per analysis
- Status Updates: Display current ticket statuses and assignee information
Data Storage and Retention
No Persistent Storage
- Real-time Processing: All analysis happens in real-time
- No Data Caching: We do not store or cache your Jira data
- Session-based: Data is processed only during your active session
- Immediate Disposal: All processed data is discarded after analysis
Atlassian Infrastructure
- Secure Environment: All processing occurs within Atlassian's secure Forge platform
- No External Storage: Data never leaves Atlassian's infrastructure
- Compliance: Inherits Atlassian's SOC 2, ISO 27001, and other certifications
Data Sharing and Disclosure
We Do Not Share Data
- No Third Parties: Your data is never shared with external parties
- No Aggregation: We do not aggregate or combine data across organizations
- No Analytics: We do not use your data for analytics or machine learning training
- No Marketing: Your data is never used for marketing or advertising
Legal Compliance
We may disclose information only if required by law, such as:
- Valid legal process or court order
- Protection of our legal rights
- Prevention of fraud or security threats
AI Processing and External Services
OpenRouter AI
Jirvana uses OpenRouter for AI analysis with the following protections:
- Data Collection Denied: Explicit "data_collection: deny" setting
- No Training Data: Your data is never used to train AI models
- Anonymous Processing: No identifying information sent to AI services
- Temporary Processing: Data is processed and immediately discarded
Privacy-First AI
- Pattern Analysis Only: AI processes patterns, not sensitive content
- No Personal Data: Only ticket metadata and relationships analyzed
- Secure Transmission: All API calls use encrypted connections
- Immediate Deletion: AI providers do not retain processed data
Your Rights and Controls
Data Access
- Transparency: All processed data comes from your existing Jira instance
- Visibility: You can see exactly what data is being analyzed
- Control: Standard Jira permissions control data access
Data Control
- Jira Permissions: Your existing Jira permissions control app access
- Opt-out: Uninstall the app to stop all data processing
- No Account Creation: No separate account or profile created
Regional Compliance
- GDPR: Compliant with European data protection regulations
- CCPA: Meets California privacy requirements
- SOC 2: Operates within Atlassian's certified environment
Contact Information
Privacy Questions
For questions about this Privacy Policy or our privacy practices:
- Email: privacy@jirvana.dev
- GitHub: Privacy Issues
- Response Time: We respond to privacy inquiries within 72 hours
Data Protection Officer
For GDPR-related inquiries:
- Email: dpo@jirvana.dev
- Subject Line: "Jirvana Privacy Inquiry"