Privacy Policy: Sprint Scope Search for Jira
Effective 2026-10-07. Updated 2026-10-07: added Support requests; the support form is now our only contact route and has a self-hosted anti-spam check.
This policy covers the Atlassian Marketplace app Sprint Scope Search for Jira ("the app") and the WorkAlong support portal at /support (see Support requests). The app is provided by WorkAlong ("WorkAlong", "we"). Contact: the support form.
Summary
- The app runs entirely on Atlassian's Forge platform ("Runs on Atlassian").
- The app uses no servers of ours and sends no data outside Atlassian.
- The app stores no issue content and no personal data.
- We, WorkAlong, can't see your Jira data.
- If you contact support, we keep what you send us, as described in Support requests.
What the app processes, and where
| Data | Where it's kept | Why |
|---|---|---|
| Sprint-field change history of your issues (which sprint, when, by whom) | Read from Jira when needed. Not stored. | To work out when issues entered or left sprints |
A wlSprintScope issue property per issue that has been in a sprint, containing sprint ids only |
Your Jira site, as a Jira issue property | So that the JQL functions can search sprint history |
| A catalog of sprints and boards: ids, names, states, dates, project keys, and the time each sprint was started | Atlassian-hosted Forge storage for your installation | To resolve sprint names and know sprint start/end times |
| Sync progress (counters, the id of the last issue processed) | Atlassian-hosted Forge storage | To resume the first sync |
| Report data: issue keys, summaries, statuses, story points, and who changed sprint scope | Not stored. Computed on request, as the viewing user, and shown only to that user | The Sprint scope page and CSV export |
| Operational logs: function names, timings, numeric issue/sprint ids, error codes | Atlassian's Forge logging | Reliability and support. No issue content, sprint names or user names are logged. |
What we don't do
- The app sends no data out of Atlassian: no external servers, no analytics, no third-party services. (The support portal below is separate from the app and only gets what you type into it.)
- No selling, sharing or advertising use of any data.
- No access to your data by WorkAlong staff, apart from operational logs.
- Atlassian provides those logs to app developers.
- They contain only the items listed above.
Support requests
This section covers the support form at /support and our email replies, for all WorkAlong apps (including Catalog Undo). It's separate from the app: the app itself never sends us data.
| What we collect | Why |
|---|---|
| Your name, email address, the app, the site URL (optional), the category and your message | To answer you and fix the problem |
| The time you sent it | To track our response time |
| Your IP address | Only to limit abuse (rate limiting). It's held in the portal server's memory for up to 24 hours and is not stored in the ticket or in logs. |
- Where it's stored: each request becomes a ticket in a private Jira project on our own Atlassian site (workalong-team.atlassian.net), hosted by Atlassian. Only WorkAlong can see it. It isn't visible to other customers or to apps installed on that site.
- How it gets there: the form is served by our web server on Fly.io (US), which passes your request to Atlassian over HTTPS and doesn't keep a copy. Its logs contain only the ticket number, app and category.
- Who handles it: WorkAlong. We may use AI tools to help triage and draft replies; a person checks replies before they're sent. We don't sell, share or use support data for advertising, and we don't add you to any mailing list.
- Email: we reply to the email address you give us, from our own support mailbox. If you reply to us, your reply is kept in that mailbox. The form doesn't email you. When a ticket is created, our server sends one internal alert to our own support mailbox through our email provider, Resend. That alert holds only the ticket number, app, category and a link to the ticket: none of your name, email address, site URL or message.
- Anti-spam check: the form uses a self-hosted proof-of-work check (the open-source ALTCHA widget, served from workalong.app). Your browser solves a small puzzle from our server and sends the answer with the form. It involves no third-party service, sets no cookies, doesn't track or fingerprint you, and collects no personal data. Our server only checks the answer and remembers it until it expires (at most about an hour) so it can't be reused.
- No cookies or trackers: the support page sets no cookies and loads nothing from third parties: no third-party scripts, captcha, fonts or analytics.
- Retention: we keep a ticket for 24 months after it's resolved, then delete it. Ask us to delete your ticket sooner and we will, unless we must keep it by law (for example, billing records).
- Your rights: send a request through the support form (category Question) to see, correct or delete your support data. We answer within one business day.
- Please don't send passwords, API tokens, payment card numbers or your customers' personal data.
Data residency
Forge storage and Jira issue properties are hosted by Atlassian. They follow your Jira site's data residency settings.
Retention and deletion
- While installed: the data above is kept and updated.
- App storage after uninstall: Atlassian deletes it within about 30 days.
- Issue properties after uninstall: the
wlSprintScopeproperties stay on your issues. They hold only sprint ids and are no longer searchable. On request, we'll provide a script your admin can run to remove them.
Your rights and roles
- GDPR / CCPA roles: for the app data described above, Atlassian hosts and processes it on its platform for you. WorkAlong doesn't receive or store personal data from the app, so we don't act as a controller or processor of your Jira content. For support requests you send us, WorkAlong is the controller.
- Questions or data requests: use the support form (category Question). We answer within one business day.
Security
- Contact: report security issues through the support form with category Security.
- Minimum access: the app requests only the permissions it needs. Its only write access is the
wlSprintScopeissue property. - Pages run as you: the Sprint scope page reads Jira as the viewing user, so it shows only issues and sprints that user can already see.
- Security policy: see Security.
Changes
We'll post changes on this page with a new effective date. Material changes will also be noted in the app's Marketplace release notes.