Effective August 19, 2026

Privacy Policy

Notification Hygiene for Jira is designed to minimize retained data and keep app processing within Atlassian Forge.

Provider and scope

Notification Hygiene for Jira is offered under the Korinvale Software brand by Alan Shen operating individually as a sole proprietor (“Provider”). This policy describes how the app processes data to provide its documented functionality.

Data processed during an audit

The app reads notification-scheme configuration and project-to-scheme mappings available through Jira APIs. Transiently processed data may include scheme identifiers and names, events, assignments, recipient types and identifiers, group names, project roles, user status, custom-field references, and direct-email recipients.

These details are used to calculate findings and are not sent to an external service.

Data retained

Only compact drift data is stored in Atlassian Forge KVS:

  • Capture timestamps.
  • Notification-scheme identifiers and names.
  • Deterministic configuration fingerprints.
  • Added, removed, or changed scheme identifiers and names for at most 20 change records.
  • The latest scheduled-scan time, scheme count, change flag, or safe error category.

The app does not retain recipient details, account IDs, group names, project roles, email addresses, raw Jira responses, credentials, or event-level configuration.

Hosting and sharing

  • UI, compute, and persistent app storage are provided by Atlassian Forge.
  • The app declares no remote backend or external egress.
  • The app uses no external database, advertising, analytics, or AI service.
  • Korinvale Software does not sell end-user data.
  • Atlassian processes Forge-hosted data under its applicable platform terms and controls.

Our role and data-processing terms

For customer-directed processing covered by the GDPR, Korinvale Software acts as a processor or subprocessor and not as the customer's controller. For customer-directed processing covered by the CCPA, Korinvale Software acts as a service provider or contractor and not as a business for that Customer Personal Information.

The product-specific Data Processing Addendum describes the processing instructions, safeguards, subprocessing, assistance, deletion, and CCPA restrictions that apply.

Authorization

Interactive Jira reads run as the signed-in user and remain subject to that user’s permissions. The daily scheduled trigger reads notification schemes as the installed app under the required Jira configuration scope. The admin page is limited to users with Jira’s global administrator permission.

Running an interactive audit and daily scheduled monitoring require an active paid or evaluation license. Reset drift history remains available without an active license so former customers and customers whose evaluation has ended can delete retained app data.

Retention and deletion

  • Drift history is bounded to 20 change records.
  • A Jira administrator can use Reset drift history to delete the baseline and retained change history even without an active license.
  • Forge-hosted storage may be retained by Atlassian for up to 28 days after uninstallation under the current Forge storage lifecycle.
  • The app does not offer a custom customer-selected retention period.

Your requests

Send privacy or data-deletion questions to support@korinvale.com. We will respond based on the data processed by the app and the controls available through Atlassian Forge.

Changes

Material changes will be published on this page with an updated effective date.