Effective and last updated: July 21, 2026

Privacy Policy

This policy explains how Customer Portal Toolkit for JSM processes data in Jira Service Management Cloud and how Mederak Apps handles related support and website data.

1. Provider and scope

Customer Portal Toolkit for JSM (the “App”) is provided by Piotr Mederak, ul. Magnolii 1K/2, 05-500 Nowa Wola, Poland, trading as Mederak Apps (“Mederak Apps”, “we”, “us”). This policy covers the App, product support and the public product pages at mederak.app. It does not replace Atlassian's privacy notices for Jira Cloud, Jira Service Management, Atlassian Marketplace, Atlassian accounts or the Forge platform.

2. Privacy roles

The Atlassian customer controls its Jira/JSM content, users, permissions and App configuration. For customer data processed by the App to provide the service, the customer is normally the controller or business and Mederak Apps acts as its processor or service provider. Mederak Apps acts as an independent controller for business administration, support communications, security reports, legal compliance and consent-based public website analytics. The exact legal role may vary under applicable law and a separate written agreement.

3. Data processed by the App

The App processes only data needed by an enabled feature and permitted by the current actor, Jira/JSM permissions and App configuration. Depending on configuration and tenant capability, this may include:

4. Purposes and legal bases

The App processes data to render authorized portal content; validate, preview, save and publish configuration; calculate privacy-treated operational context; execute selected customer actions safely; prevent replay and abuse; run bounded background work; provide optional installation-local analytics and AI; and diagnose technical failures using redacted metadata. This processing is necessary to perform the customer agreement and follows the customer's instructions. Support, security and vendor-administration processing relies on contract performance, legal obligations and legitimate interests. Optional public website analytics relies on consent where required.

5. Data not collected or used

The App has no Forge Remote, external product backend/database, external fetch domain, advertising tracker or third-party app analytics. Mederak Apps does not sell customer or personal data, use App data for targeted advertising, collect Atlassian passwords or API tokens, or use customer data to build unrelated profiles. Logs are designed not to contain customer request content, comments, attachments, field values, credentials, tokens, private Jira errors or full AI prompts/completions.

6. Hosting, recipients and transfers

App processing uses Atlassian Jira Cloud and Forge services. Atlassian hosts the App's compute, storage, platform logs, async services and optional Forge LLM. Data residency and international transfer behavior therefore depends on the customer's Atlassian configuration and Atlassian's current services and contractual safeguards. See Data Residency and Subprocessors.

We may disclose data where required by law, to protect users or the service, or to professional advisers bound by confidentiality. We do not disclose customer data for independent marketing.

7. Retention

RecordRetention in the installed App
Drafts, published configuration, versions, settings, capability and migration metadata, participant-policy mappingsRetained while needed to provide the configured App and while the installation remains active; replaced or superseded through normal administration where supported.
Revision/publication claims1 hour.
Two-person approval records24 hours.
Action idempotency/results24 hours; short action rate claims last 90 seconds.
General widget cache and refresh leasesCache lasts three times the configured freshness period; leases last 30 seconds.
Historical metric snapshots96 hours for chart snapshots; 90 days for non-chart snapshots.
Optional product analytics90 days.
Content-free audit records180 days.
Optional AI result cache15 minutes.
Optional AI usage aggregates180 days; supporting leases/circuit state last up to 30 seconds/20 minutes.

When the App is uninstalled, Atlassian's current Forge documentation states that hosted storage is retained for 28 days. Reinstalling the App does not automatically restore data from the previous installation. Mederak Apps does not control Atlassian backup or physical-deletion schedules and does not promise immediate irrecoverability. See Uninstall and Data Deletion.

8. Security and access

Tenant, actor, project, request, module and license context comes from trusted Forge/Jira context. Sensitive reads, publications and actions are re-authorized in the backend. Current-request reads and customer mutations use the current user where supported; reviewed app-principal aggregates are project-bound and disclose only privacy-treated results. Configuration is schema-validated and does not permit arbitrary JavaScript, HTML, CSS, endpoints, payloads or unbounded expressions. See Security Practices.

9. Customer controls

Authorized administrators control configuration scope, published content, audiences, optional AI, optional installation-local analytics and two-person publication. Jira/JSM administrators control user access, permissions, fields, workflows and the installation itself. Anonymous output is limited to explicitly public, configuration-backed portal-header content and cannot access requests, aggregates, actions, personalization, preferences or AI.

10. Privacy requests

Depending on applicable law, individuals may have rights of access, correction, deletion, restriction, objection, portability or complaint. Submit requests through Mederak Apps Service Desk. Include the App name, Atlassian site hostname and enough information to verify the request, but do not send passwords, API tokens, confidential exports or unnecessary customer data.

Because the customer organization controls Jira content and the App installation, we may refer a request to or require confirmation from its authorized Jira administrator. We will respond without undue delay and within the period required by applicable law.

11. Public website and support data

The public mederak.app website is hosted by OVHcloud and may create ordinary infrastructure/security logs. With visitor consent where required, it may use Google Analytics and Google Ads measurement; Google Fonts may also receive technical request data when loaded. Website measurement is separate from the Forge App and cannot access customer Jira content. Support requests are processed in Atlassian Jira Service Management and retained as needed to provide support, maintain security records and meet legal obligations.

12. Children and sensitive data

The App is intended for organizational Jira Service Management use and is not directed to children. Customers are responsible for lawful request forms, notices, permissions and avoiding unnecessary special-category, regulated or high-risk data. The App should not be used as the sole basis for legal, employment, medical, financial, safety or similarly high-impact decisions.

13. Changes and contact

We may update this policy to reflect product, legal or platform changes. The effective date above identifies the current version. Material changes will be communicated through an appropriate product, Marketplace or support channel where required.

Privacy questions: Mederak Apps Service Desk. Provider: Piotr Mederak, ul. Magnolii 1K/2, 05-500 Nowa Wola, Poland.