Privacy Policy

Priority Scoring for Jira · Last updated: October 5, 2026

1. Introduction

This Privacy Policy explains how Priority Scoring — RICE, WSJF, ICE & Rovo AI for Jira ("the App"), developed by Janek Behrens ("we", "us", "our"), handles data when installed on your Atlassian Jira Cloud instance. We are committed to protecting your privacy and being transparent about our data practices.

2. Data We Access

The App accesses the following Jira data solely to provide its functionality:

3. Data We Store

The App stores the following data using Atlassian Forge Storage (KVS), which is hosted and managed by Atlassian within your cloud instance:

We do not store issue descriptions, issue titles, comments, user emails, or any other free-text content entered by your team; the only names the App keeps are project names (project list and last selected project).

4. Rovo AI Feature and Issue Content

The App includes a Rovo AI agent ("Priority Scoring") that can analyse Jira issues and suggest or apply RICE, WSJF, or ICE scores. When this feature is used:

5. Optional: Rovo AI Comment Writing

If an administrator enables the "Write AI reasoning as comment" option in the dashboard settings, the Rovo AI agent may post a comment on a Jira issue containing the computed score and the AI's reasoning text. This is opt-in and disabled by default. These comments are stored as standard Jira issue comments, governed by Atlassian's data handling practices.

6. Data We Do NOT Collect

Technical logs and usage counts: Like most Forge apps, the App writes technical log lines (for example "a score was saved" or "Jira did not answer") and, once a day, the anonymous usage counters and the subscription state to Atlassian's app logging, which Atlassian makes available to us as the app vendor. Log lines may contain project keys from your site (an issue key is reduced to its project, the issue number is never logged), as well as frameworks, modes, counts, scores, HTTP statuses and error codes, but never issue numbers, titles, descriptions, names, email addresses, account IDs or JQL. We use them only to find errors and to see which features are used.

7. Data Processing Location and Data Residency

All data processing occurs within the Atlassian Forge runtime environment. The App runs on Atlassian's infrastructure as part of the Runs on Atlassian program. No data is transmitted to servers operated by us or any third party outside the Atlassian platform.

Everything the App stores in Forge Storage (section 3) is held in Forge hosted storage, which supports Atlassian's data residency: it is kept in the same location as your Jira site and moves with it when an admin moves the site's data to another location. Not in scope: Jira data the App reads without storing it, the scores in the App's custom fields and the optional Rovo comments (both stored by Jira under Jira's own data residency), Rovo chat content (processed by Atlassian Rovo), and the technical logs in section 6, which are handled by Atlassian's app logging.

8. Data Retention

9. Personal Data and GDPR

The App stores Atlassian account IDs only as keys for the per-user settings in section 3 (last selected project, import switch, review prompt), so team members do not overwrite each other's choices. It stores no email addresses, avatars or other profile data. Assignee display names are read from Jira when the ranking or the Rovo AI agent lists issues, used only for that display, and never stored or transmitted externally by the App. The per-user settings stay in Forge Storage on Atlassian's platform (section 7).

For all other stored data, the App retains numeric values (scores, dimensions, weights, thresholds), issue and project keys, and project names. GDPR data subject requests (access, rectification, erasure, portability) relating to personal data held by Jira itself should be directed to Atlassian. For any App-specific data concerns, contact us at the address below.

After you uninstall the App, Atlassian deletes all App-related data from Forge Storage after 28 days (section 8).

10. Security

The App follows Atlassian Forge security best practices:

See our Security Policy for full details.

11. Children's Privacy

The App is a business productivity tool and is not directed at children under 16. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the updated policy.

13. Contact

For questions or concerns about this Privacy Policy, contact us at:
Email: support@janekbehrens.de