Privacy policy
Last updated 26 September 2026.
This policy covers the Pull Request Status Sync app for Jira Cloud ("the app"), built and supported by Michael Costa, trading as White Hat Harbor ("we"). The app runs entirely on Atlassian Forge, Atlassian's hosted app platform. We don't operate any servers of our own, and the app sends no data to us.
What the app processes
| Data | Source | Why | Stored? |
|---|---|---|---|
| Ticket keys, statuses and status history | Your Jira site | To decide whether a ticket is in review and when it entered review | Only the result of the most recent hourly run (ticket keys and the decision for each, up to 200) |
| Pull request titles, descriptions, branch names, states, author and reviewer usernames or account IDs, approval times and reviewed commits, and head commit dates | Bitbucket Cloud, GitHub and GitLab, via the credentials an admin provides | To count approvals | No. They're read on each check and not kept. |
| Webhook deliveries (host, event name, ticket keys, outcome) | Your code hosts, if you add webhooks | So admins can see deliveries arrive and what they did | The last 20 only, overwritten as new ones arrive. Delivery bodies aren't stored |
| Settings (workspace ID, repository names, project keys, status names, bot account IDs, and the Jira account ID of any "assign to" person; their name isn't stored, it's looked up when shown) | Your Jira admin | Configuration | Yes, in Forge storage |
| Bitbucket OAuth client ID and secret; GitHub and GitLab tokens | Your Jira admin | To call each host's API | Yes, each encrypted in Forge secret storage, never shown again, and sent only to its own host. A host's token is deleted when that host is disconnected. |
| Webhook secret (only if you use webhooks) | Generated by the app | To check that webhook deliveries really come from your code host | Yes, encrypted in Forge secret storage. Only Jira admins can view it, on the settings page; it's never sent anywhere. |
Where data goes
- Storage: Atlassian Forge storage, hosted by Atlassian and scoped to your installation.
- Outbound calls: only to
api.bitbucket.org,api.github.comandgitlab.com, as declared in the app's manifest, and only to the hosts you connect. - Writes to Jira: moving, reassigning and commenting on tickets, only in the projects an admin's rules cover.
- Logs: Forge keeps app logs that we, the developer, can read. Each hourly run logs the keys of promoted tickets, a count of held tickets, and any error messages, which can include ticket keys and repository names.
- No analytics, tracking, advertising or third-party services. We don't sell or share data.
Retention and deletion
Once a week the app reports the Jira account IDs in its settings to Atlassian's personal data reporting service. If Atlassian says an account was closed, its ID is removed, and any rule that assigned tickets to it keeps the current assignee instead. Settings, tokens and the webhook secret are kept until an admin changes them, disconnects a host (which deletes its token), or uninstalls the app. The last-run record is overwritten every hour. When the app is uninstalled, Atlassian deletes its Forge storage under the Forge platform's data retention rules. Forge logs expire under Atlassian's log retention.
Your rights
To ask about or delete data related to your site, open a request on the support page. We don't hold personal data outside Atlassian's platform, so most requests are handled by changing the settings or uninstalling the app.
Changes
We'll update this page and its date when the app's data handling changes.