Privacy Policy
1. Introduction
This Privacy Policy describes how ScriptFabric ("we", "our", or "us") collects, uses, and protects information when you use the ScriptFabric application ("the App") available on the Atlassian Marketplace. By installing or using the App, you agree to the practices described in this Privacy Policy.
2. About the App
ScriptFabric is a Forge-based application built on Atlassian's Forge platform. It provides features such as custom scripting, workflow automation, scheduled jobs, event-driven listeners, script console execution, and related capabilities within your Jira environment.
3. Data Accessed by the App
To provide its features, the App accesses the following data within your Atlassian Jira environment:
| Data Type | Purpose |
|---|---|
| Jira issue fields and metadata | Enable scripts to read and modify issue data |
| Jira workflow configurations | Support workflow-based automation and post-functions |
| Jira user display names and account IDs | Attribute script executions and enforce permissions |
| Jira project keys and project names | Scope script execution and automation to projects |
| Jira custom fields and field configurations | Allow scripts to interact with custom field data |
| Jira group and role membership | Enforce group-based and role-based permissions |
The App does not access:
- Passwords or authentication credentials
- Billing or payment information
- Data from other Atlassian products (unless explicitly stated)
- Any data outside the Atlassian environment
4. How Data Is Stored
The App is built on Atlassian Forge and uses Atlassian Forge Key-Value Storage (KVS) as its only data store.
This means:
- All data is stored exclusively within Atlassian's infrastructure
- No data is transmitted to, stored on, or processed by external servers operated by us
- Data is protected by Atlassian's security, redundancy, and compliance controls
- We do not have direct access to your data; it resides within your Atlassian tenant
For more information, refer to Atlassian's Trust Center.
5. Data Stored by the App
The App stores the following data in Forge KVS, scoped to your Atlassian site:
| Stored Item | Purpose | Retention |
|---|---|---|
| Script definitions and configurations | Persist user-created scripts and automation rules | Until manually deleted or app uninstalled |
| Scheduled job configurations | Maintain scheduled script execution settings | Until deleted by admin or app uninstalled |
| Script execution logs | Provide audit trail and debugging information | Until deleted by admin or app uninstalled |
| Saved script templates | Enable reuse of common script patterns | Until deleted by user |
| App permission settings | Manage group-based and role-based access | Until modified by admin |
6. Data Sharing
We do not:
- Sell your data to any third party
- Share your data with advertisers
- Transfer your data to external systems
- Use your data beyond providing App functionality
Data may only be accessed by:
- Atlassian (as the infrastructure provider)
- Your Atlassian administrators (via standard admin controls)
7. Data Retention
- Data is retained as long as the App remains installed
- When the App is uninstalled, all associated data is automatically deleted by Atlassian
- Project administrators can manually delete stored data at any time
8. Security
The App relies on Atlassian Forge's built-in security, including:
- Encryption in transit and at rest (TLS)
- Scoped API permissions (least-privilege access)
- No external credential storage
- Authentication handled by Atlassian
- Script execution sandboxed within the Forge runtime
All permissions are declared in the manifest.yml and limited to what is necessary.
9. Your Rights (GDPR & Privacy Laws)
If you are in the EEA, UK, or another region with data protection laws, you have the right to:
- Access — View your data within the App
- Deletion — Request deletion or uninstall the App
- Portability — Export data (CSV/Excel)
- Objection — Contact us for concerns
For Atlassian-managed data, please contact Atlassian directly.
10. Children's Privacy
This App is intended for professional use in business environments and is not designed for individuals under 16. We do not knowingly collect data from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- The "Last Updated" date will be revised
- Updates will be communicated via the Marketplace or release notes
- Continued use of the App indicates acceptance of the updated policy