ChangeGuard for Jira Privacy Policy
Last updated: 2026-08-05
ChangeGuard for Jira is a Flowdence app for testing and governing Jira Software work-type and workflow changes.
Data processed
Section titled “Data processed”ChangeGuard may process Jira site, project, issue, work type, status, workflow, label, Fix Version, and app-module context; customer-authored policy, waiver, reason, and JQL text; policy history, simulation results, findings, compliance and Audit evidence; and support information customers choose to provide.
ChangeGuard does not request Atlassian passwords, personal access tokens, or customer API credentials. Operational Forge logs are designed to contain event names, bounded codes, counts, timings, and app-owned identifiers rather than customer-authored content or Jira issue/project identifiers.
Account privacy
Section titled “Account privacy”Raw Atlassian account IDs are kept only in a dedicated Forge-hosted privacy registry. Immutable policy, governance, simulation, and Audit records use random actor references. ChangeGuard reports the account registry to Atlassian’s Personal Data Reporting API weekly and removes the direct identifier mapping when Atlassian reports an account closed or updated.
Purposes and roles
Section titled “Purposes and roles”Flowdence processes customer Jira data to provide, secure, support, and improve the app and meet legal or Marketplace duties. Customers control their Jira site, configuration, policies, and content. Flowdence acts as processor/service provider for customer End-User Data and may act as controller for limited billing, support, security, and abuse-prevention records.
Storage, retention, and transfers
Section titled “Storage, retention, and transfers”App data is stored in Atlassian Forge hosted storage or Jira app properties. ChangeGuard has no Flowdence remote backend or external data egress. Audit events use a 30-day retention window and async simulation jobs use a 7-day TTL. Other records remain according to product lifecycle and customer/legal requirements. Atlassian controls Forge hosting regions and transfer safeguards under its terms.
Requests and contact
Section titled “Requests and contact”Customers can request access, correction, deletion, or support at https://flowdence.io/support. Privacy contact: privacy [at] flowdence.io.