Skip to content

Privacy Policy

Last updated: April 4, 2026

This Privacy Policy explains how CommentLedger handles information for the CommentLedger Jira app.

What the app processes

When CommentLedger is installed in Jira, it processes and stores data needed to provide the comment audit log. That data can include:

  • Jira issue IDs and issue keys
  • Jira comment IDs
  • comment event types such as created, edited, and deleted
  • event and capture timestamps
  • readable text extracted from the comment body
  • comment visibility metadata
  • Jira account IDs, display names, and avatar URLs for users tied to captured events
  • installation and site identifiers needed to isolate tenant data
  • operational records used for reconciliation, retries, retention, and app setup

CommentLedger starts capturing data after installation. It does not recreate historical edits or deletions that were never observed by the app before installation.

Browser-side storage

The app stores two small UI preference flags in browser localStorage to remember whether certain sections of the operations page are expanded or collapsed. These preferences stay in your browser unless you clear them.

Where data is stored

CommentLedger stores customer audit data in Forge SQL on Atlassian-hosted infrastructure. The app uses one hosted database per installation.

CommentLedger does not persist customer audit data in a separate external database controlled by CommentLedger. Generated exports are created on demand and downloaded to the customer locally instead of being stored by the app as a second copy after generation.

Retention

By default, CommentLedger keeps audit history until a Jira administrator changes the app's retention policy. When an administrator sets a retention window, older audit events are trimmed according to that policy.

While the app remains installed, customer administrators are responsible for choosing retention settings that fit their legal and operational needs.

After uninstall, Forge-hosted storage follows Atlassian's hosted storage lifecycle and recovery rules rather than a separate CommentLedger retention workflow.

Security

CommentLedger is designed so that customer audit data stays within Atlassian-hosted Forge compute and storage for the app's primary data path. Access to audit history is limited by CommentLedger permissions together with the current user's Jira permissions.

Your choices

Customers can:

  • uninstall the app
  • change retention settings inside the app
  • control which Jira users have access through Jira and app permissions
  • request exports and manage those downloaded files locally

If you contact us and want us to delete information from a support conversation, ask through the support channel you used and we will review the request.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of this page and publish the revised version here.

Contact

For privacy or data-handling questions, use the support channel provided with your install, private sharing materials, or Marketplace listing.

Last updated: