Privacy Policy
Priority Scoring for Jira · Last updated: October 5, 2026
1. Introduction
This Privacy Policy explains how Priority Scoring — RICE, WSJF, ICE & Rovo AI for Jira ("the App"), developed by Janek Behrens ("we", "us", "our"), handles data when installed on your Atlassian Jira Cloud instance. We are committed to protecting your privacy and being transparent about our data practices.
2. Data We Access
The App accesses the following Jira data solely to provide its functionality:
- Issue data: Issue keys, summaries, descriptions, issue types, priorities, statuses, labels, and story points — used to calculate backlog health, display scoring fields, and (for the Rovo AI feature) suggest scoring dimension values.
- Assignee display names: User display names associated with issues — shown in the ranking (to filter by assignee) and when the Rovo AI agent lists sprint issues. They are never stored by the App.
- Project data: Project keys and names — used to scope health calculations, the dashboard, and the gadget.
- Custom field values: RICE, WSJF, and ICE score fields created by the App — used to display and update priority scores on issues.
- Score fields of other apps: only when a user runs the score import, the values of another app's RICE, WSJF or ICE fields in the chosen project — copied into the App's own score fields.
- Sprint data: Sprint name and open-sprint membership — used by the Rovo AI agent when analysing issues in a sprint.
3. Data We Store
The App stores the following data using Atlassian Forge Storage (KVS), which is hosted and managed by Atlassian within your cloud instance:
- Score dimensions per issue: The numeric input values for each scoring framework (e.g. RICE: Reach, Impact, Confidence, Effort) associated with an issue key.
- Computed scores: The resulting priority score per issue and framework is not kept in Forge Storage; it is written to the corresponding custom field, which Jira stores.
- Framework configuration: Custom dimension weights (×1–×5 per dimension per framework) and score thresholds set in the admin dashboard.
- Rovo AI settings: The configured apply mode (suggest / confirm / auto), bulk limit, and whether AI comment writing is enabled.
- Board Health settings: The stale threshold and the Health Criteria chosen per project key.
- Backlog health cache: Aggregated, anonymised backlog metrics per project (counts of stale issues, missing fields, unscored issues). This cache does not contain personal data. It expires after one hour.
- Project list cache: IDs, keys and names of the Jira projects, for the project pickers. It expires after 15 minutes.
- Score history (Score Audit Trail): Recorded only while a Jira administrator has turned it on in the settings; it is off by default and can be turned off again at any time. At most one entry per issue, framework and day (a later change on the same day replaces that day's entry), with the date and time, the score value, and the source (manual or Rovo AI). The last 30 entries per issue and framework are kept.
- Rovo AI activity log: A capped log (last 50 entries) of score-apply events triggered by the Rovo AI agent, containing issue keys, scores, frameworks, modes and timestamps. No personal data is stored in this log.
- Per-user settings: The project a user selected last (project key and name), whether the user turned on the score import, and the state of the review prompt. They are stored per user, keyed by the user's Atlassian account ID, so team members do not overwrite each other's choices. The App also stores the date it was installed.
- Anonymous daily usage counters: Per day, how often features were used (for example "a score was saved"). No IDs, names or content.
We do not store issue descriptions, issue titles, comments, user emails, or any other free-text content entered by your team; the only names the App keeps are project names (project list and last selected project).
4. Rovo AI Feature and Issue Content
The App includes a Rovo AI agent ("Priority Scoring") that can analyse Jira issues and suggest or apply RICE, WSJF, or ICE scores. When this feature is used:
- The App reads the summary and description (up to 600 characters) of the requested issue and passes this data to the Rovo agent for analysis.
- This processing occurs within Atlassian's Rovo platform and is subject to Atlassian's Privacy Policy and Atlassian's page on AI trust and data handling.
- The App itself does not send issue content to any external AI service or third-party server outside the Atlassian platform.
- AI-suggested scores are advisory outputs. The App stores only the numeric dimension values and computed score — not the raw issue content or AI reasoning text — unless comment writing is explicitly enabled by the administrator (see below).
5. Optional: Rovo AI Comment Writing
If an administrator enables the "Write AI reasoning as comment" option in the dashboard settings, the Rovo AI agent may post a comment on a Jira issue containing the computed score and the AI's reasoning text. This is opt-in and disabled by default. These comments are stored as standard Jira issue comments, governed by Atlassian's data handling practices.
6. Data We Do NOT Collect
- We do not collect, transmit, or store any data on our own servers. There are no servers operated by us.
- We do not store email addresses, avatars or other profile data. Atlassian account IDs are used only as keys for the per-user settings in section 3; assignee display names are shown live and never stored.
- We do not use cookies, tracking pixels, analytics platforms, or advertising networks.
- We do not store issue descriptions, comments, or any free-text content entered by users.
Technical logs and usage counts: Like most Forge apps, the App writes technical log lines (for example "a score was saved" or "Jira did not answer") and, once a day, the anonymous usage counters and the subscription state to Atlassian's app logging, which Atlassian makes available to us as the app vendor. Log lines may contain project keys from your site (an issue key is reduced to its project, the issue number is never logged), as well as frameworks, modes, counts, scores, HTTP statuses and error codes, but never issue numbers, titles, descriptions, names, email addresses, account IDs or JQL. We use them only to find errors and to see which features are used.
7. Data Processing Location and Data Residency
All data processing occurs within the Atlassian Forge runtime environment. The App runs on Atlassian's infrastructure as part of the Runs on Atlassian program. No data is transmitted to servers operated by us or any third party outside the Atlassian platform.
Everything the App stores in Forge Storage (section 3) is held in Forge hosted storage, which supports Atlassian's data residency: it is kept in the same location as your Jira site and moves with it when an admin moves the site's data to another location. Not in scope: Jira data the App reads without storing it, the scores in the App's custom fields and the optional Rovo comments (both stored by Jira under Jira's own data residency), Rovo chat content (processed by Atlassian Rovo), and the technical logs in section 6, which are handled by Atlassian's app logging.
8. Data Retention
- Score data, configuration and per-user settings (score dimensions, weights, thresholds, settings) are retained in Forge Storage as long as the App is installed.
- Custom field values (RICE, WSJF, ICE scores on issues) are stored by Jira as standard custom field data. Removing the custom fields from Jira's field configuration will remove these values.
- Health cache expires automatically after one hour and is refreshed on demand; the project list cache after 15 minutes. An expired entry is deleted when it is next read.
- Score history keeps the last 30 entries per issue and framework; the history of an issue and framework is deleted automatically 90 days after its last change. Turning the audit trail off stops new entries; existing entries expire on the same schedule.
- Rovo AI activity log is capped at 50 entries and older entries are overwritten automatically.
- Anonymous daily usage counters are deleted automatically after 8 days; counters written by app versions before 6.36 (October 2026) are kept while the App is installed.
- After you uninstall the App, Atlassian keeps the App's storage for 28 days and then deletes it (Forge documentation: data recovery for apps with hosted storage). During that time the App cannot read it. Within 21 days of the uninstall, you can ask us to have Atlassian restore it to a new installation of the App.
9. Personal Data and GDPR
The App stores Atlassian account IDs only as keys for the per-user settings in section 3 (last selected project, import switch, review prompt), so team members do not overwrite each other's choices. It stores no email addresses, avatars or other profile data. Assignee display names are read from Jira when the ranking or the Rovo AI agent lists issues, used only for that display, and never stored or transmitted externally by the App. The per-user settings stay in Forge Storage on Atlassian's platform (section 7).
For all other stored data, the App retains numeric values (scores, dimensions, weights, thresholds), issue and project keys, and project names. GDPR data subject requests (access, rectification, erasure, portability) relating to personal data held by Jira itself should be directed to Atlassian. For any App-specific data concerns, contact us at the address below.
After you uninstall the App, Atlassian deletes all App-related data from Forge Storage after 28 days (section 8).
10. Security
The App follows Atlassian Forge security best practices:
- Runs in a sandboxed Forge environment with no egress to external networks outside the Atlassian platform.
- Uses scoped Jira API permissions: it reads issue, project, label and user data (display names) and the Rovo chat it is called in, and writes only scores and, if enabled, Rovo comments.
- Does not store credentials, tokens, or secrets.
- Rovo AI write actions (apply score, bulk apply) are protected by a configurable apply-mode setting (suggest / confirm / auto) that administrators can restrict.
See our Security Policy for full details.
11. Children's Privacy
The App is a business productivity tool and is not directed at children under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the updated policy.
13. Contact
For questions or concerns about this Privacy Policy, contact us at:
Email: support@janekbehrens.de