Privacy Policy
Effective date: 13 September 2026
This policy describes what IssueRescue for Jira ("IssueRescue", "the app", "we", "us") collects, stores, and does with data when installed on a Jira Cloud site, and what your rights are with respect to that data. IssueRescue is developed and provided by Stephen Hutchins.
What data IssueRescue collects and stores
IssueRescue is a Forge app that keeps a snapshot of a Jira issue's data so that, if the issue is later deleted, an administrator can restore it. To do this, the app collects and stores:
- Issue fields: summary, description, issue type, project, priority, labels, components, due date, and custom field values.
- Atlassian account references for the issue's assignee and reporter (account ID and, where available, display name).
- Comments and worklogs, including their text content and the account reference and timestamp of whoever originally wrote them.
- Who deleted the issue and when (account reference and timestamp), if that information was available from Jira at the time of deletion.
- The outcome of a restore: the new issue's ID/key and the time it was created.
Where any of the above is a comment, worklog description, issue description, or custom field that supports rich text, that content can include an @mention of another Atlassian user — IssueRescue treats an accountId embedded that way the same as any other stored account reference (see "Your rights," below).
What IssueRescue does not collect
- Attachment file contents. (Attachment metadata support is defined in the app's data model but is not an active feature in the current version.)
- The full Jira change history/audit log for an issue.
- Any Atlassian API token, password, or credential — IssueRescue authenticates to Jira using Forge's own managed app identity, which the app's own code never sees or stores.
Where data is stored
All data IssueRescue stores lives exclusively in Forge's own hosted Key-Value Store, scoped to your Jira site's installation of the app. IssueRescue does not operate its own servers, databases, or hosting infrastructure of any kind — everything runs on Atlassian's Forge platform, which encrypts hosted data at rest.
Who can access it, and where it goes
Only a Jira site administrator can open IssueRescue's admin page, and every action it offers (viewing deleted issues or restore history, restoring an issue, or permanently deleting a stored snapshot) independently checks, on the server side, that the person invoking it currently holds Jira's global "Administer Jira" permission.
IssueRescue does not send issue, comment, worklog, or account data to any service outside Atlassian/Forge infrastructure. Every network call the app makes is a call to Jira's own REST API, made through Forge's own proxied client. IssueRescue has no third-party runtime dependencies, does not use analytics, advertising, or tracking of any kind, does not sell or share data with any third party, and does not use artificial intelligence or machine learning on your data. IssueRescue does not make any automated decision that has a legal or similarly significant effect on a person.
How long data is kept
There are two, separate retention periods that apply, at different layers:
IssueRescue's own retention (while the app is installed)
- A snapshot of a deleted issue is kept for up to 30 days from the date it was deleted. After that, IssueRescue automatically and permanently deletes it — enforced both by a scheduled daily cleanup and opportunistically whenever the app is used, so this holds even on a Jira site that goes unused for a while.
- An administrator can permanently delete a specific deleted-issue snapshot immediately, at any time, instead of waiting for the 30 days.
- Once an issue has been successfully restored, the record of that restore (for the History view) is kept indefinitely, so administrators retain an audit trail of what was recovered and when. An administrator does not currently have an in-app way to delete an individual history record, or to erase all IssueRescue data in bulk on demand.
Atlassian's platform-level retention (after IssueRescue is uninstalled)
This part is Atlassian's own policy for Forge-hosted app data generally — it is not something IssueRescue configures, controls, or can shorten. Per Atlassian's current developer documentation: when a Forge app is uninstalled, its hosted storage is retained by Atlassian's platform for 28 days, and a request to recover/relink that data to a reinstalled app must be submitted to Atlassian within 21 days of uninstallation. Do not rely on this page for the current figures — check Atlassian's own documentation, since platform policies can change independently of this app.
Your rights: access, correction, and erasure
IssueRescue stores Atlassian account references (account IDs and, where available, display names) as described above. Because of this, the app participates in Atlassian Forge's Personal Data Reporting program:
- IssueRescue periodically reports the Atlassian account IDs it currently stores to Atlassian, so Atlassian can tell the app when one of those accounts is closed or its profile data has changed.
- If Atlassian reports that an account has closed, IssueRescue automatically erases that account's identity information (the account ID, cached display name, and any @mention of that account inside stored issue/comment/worklog content) from every record it holds — while preserving the surrounding issue/comment/worklog content itself where that's possible without the erased identity.
- If Atlassian reports that an account's data was updated, IssueRescue clears its own cached copy of that account's display name (keeping the account ID, which remains needed for a future restore) rather than continuing to show a name that may now be stale.
This automatic process is currently triggered only by Atlassian's own weekly report — it is not yet a self-service, on-demand control inside the app. If you are a data subject and want to make an access or erasure request some other way (for example, before an account is formally closed with Atlassian), or if you're an administrator who wants to make such a request on someone's behalf, email privacy@issuerescue.co.uk. We may ask for information reasonably necessary to verify the request and identify the relevant Jira site or Atlassian account. We will handle verified requests without undue delay and within any period required by applicable law.
Uninstalling the app
Uninstalling IssueRescue from your Jira site stops it from capturing new snapshots or running any further processing. What happens to the data already stored is governed by Atlassian's own platform-level retention policy described above, not by IssueRescue.
Changes to this policy
When this Privacy Policy changes, we will update the effective date shown on this page. Where a change is material, we may also provide additional notice through this website, the Atlassian Marketplace listing, or another appropriate channel.
Contact
Questions about this policy, or a data access/erasure request: privacy@issuerescue.co.uk