Перевод для удобства. При расхождении действует английская версия.
Privacy Policy
In short: ArtUp Trace runs entirely on Atlassian's infrastructure. Its data is stored by Atlassian in your Jira site's data residency region, ArtUp Labs operates no servers that receive it, and the app sends nothing to third parties. ArtUp Export stores nothing at all: it converts Confluence pages in your browser and downloads the result to your computer. ArtUp Reports builds Excel, Word and PDF files from Jira issues in your browser; it stores only export templates, including the Atlassian account id of each template's author, and never stores issue content. ArtUp Query adds JQL functions to Jira: it reads work items, links, hierarchy, Sprint and status history and comment and attachment metadata as the app, and stores only ids, dates and metadata (including the Atlassian account ids of comment and attachment authors) — never issue text, comment bodies or attachment content. This website uses no cookies and no analytics.
1. Who we are
ArtUp Labs is the trade name of Artyom Karpets, an individual entrepreneur (sole proprietor) registered in the Republic of Kazakhstan ("ArtUp Labs", "we", "us").
- Registered address: 32 E. P. Slavsky Embankment, apt. 132, Ust-Kamenogorsk (Oskemen), 070004, East Kazakhstan Region, Republic of Kazakhstan
- IIN: 911223350864
- Email: [email protected]
2. Scope
This policy covers:
- ArtUp Trace for Jira Cloud (the "App"), an Atlassian Forge app for requirements traceability, distributed through the Atlassian Marketplace;
- ArtUp Export for Confluence Cloud ("ArtUp Export"), an Atlassian Forge app that exports Confluence pages to Markdown, distributed through the Atlassian Marketplace;
- ArtUp Reports for Jira Cloud ("ArtUp Reports"), an Atlassian Forge app that exports Jira issues to Excel, Word and PDF files, distributed through the Atlassian Marketplace. Where this policy says "the App", it applies to ArtUp Export and ArtUp Reports as well, except where sections 5, 6 and 7 say otherwise;
- ArtUp Query for Jira Cloud ("ArtUp Query"), an Atlassian Forge app that adds JQL functions to Jira (subtasks, links, sprint history, comments, attachments and field comparison), distributed through the Atlassian Marketplace. Where this policy says "the App", it applies to ArtUp Query as well, except where section 7 says otherwise; and
- the website at artuplabs.com (the "Website").
Your use of Jira Cloud and Confluence Cloud itself is governed by Atlassian's own privacy policy and terms. This policy does not cover Atlassian's processing.
3. Controller and processor roles
For data the App processes within your Jira or Confluence site, the customer (the organisation that installed the App) is the data controller, and ArtUp Labs acts as a processor on the customer's behalf. The App processes this data only to provide its features, on Atlassian's infrastructure.
For email correspondence you send us (for example, a support request), ArtUp Labs is the controller of that correspondence.
4. What data ArtUp Trace processes
4.1 Data the App reads from Jira
The App reads Jira data as the current user, so it can only see what that user is already permitted to see. It reads issues, issue links, statuses and basic user information needed to display them. The App never writes to Jira issues.
The App requests only these Atlassian scopes:
read:jira-work— read issues, issue links and project data;read:jira-user— read basic information about the current user, used for the per-action Jira permission check;storage:app— store the App's own data in Forge storage.
4.2 Data the App stores
The App stores the following in Forge SQL and Forge storage:
| Category | Contents |
|---|---|
| Project settings | Which issue types and link types count as requirements and verification. |
| Requirement records | Issue id, issue key, summary, status, and a fingerprint hash of the summary and description (used to detect changes). |
| Link records | Link type, the other issue's key and status, and the time the link was last confirmed. |
| Baselines | Frozen snapshots of the requirement and link records above. |
| Sync job metadata | Technical information about background synchronisation jobs (for example, progress and timing). |
The App does not store personal data: no names, email addresses or Atlassian account ids. It does not store passwords, access tokens or payment data. The full description text of issues is not stored; only a hash of it is.
4.3 CSV export
When a user exports to CSV, the file is generated and downloaded directly to that user's device. ArtUp Labs does not receive a copy.
4.4 Logs
The Atlassian Forge platform keeps logs of errors raised by the App. By design, the App does not log issue content; logs contain error messages only. ArtUp Labs can view these logs in the Atlassian developer console to diagnose problems.
5. What data ArtUp Export processes
5.1 Data the app reads from Confluence
ArtUp Export reads Confluence as the current user, through Atlassian's API in that user's browser, so it can only export what that user is already permitted to see. It reads the pages chosen for export (titles, content, versions, position in the page tree), their labels and attachments, and the display names of page authors and mentioned users. It never writes to Confluence.
ArtUp Export requests only these read-only Atlassian scopes:
read:page:confluence— read pages, their content and versions;read:space:confluence— find the space and its top-level pages;read:hierarchical-content:confluence— read the page tree in Confluence order;read:attachment:confluence— list and download page attachments;read:label:confluence— read page labels;read:confluence-user— read display names of page authors and mentioned users;search:confluence— find pages by title when you pick a page to export;storage:app— declared for future versions; the current version does not use it.
5.2 Where the processing happens
Conversion to Markdown and packing of the zip file happen in the user's browser. The resulting zip is downloaded directly to that user's device. Page content, attachments and user names are not sent to the app's backend, not sent to ArtUp Labs and not sent anywhere outside Atlassian and the user's browser. Author names are written only into the user's zip.
5.3 Data the app stores
None. ArtUp Export does not use Forge storage or any other storage: it keeps no settings, no page content, no export history and no personal data. The export-manifest.json file inside each zip (page ids, versions, file paths and options, no page content) exists only in the user's download; when the user drops it back in for an update export, it is read in the browser and not uploaded.
5.4 Backend and logs
ArtUp Export's only backend function reports whether the app's licence is active. It receives no page content, so Forge platform logs for ArtUp Export contain no Confluence content.
6. What data ArtUp Reports processes
6.1 Data the app reads from Jira
ArtUp Reports reads Jira as the current user, through Atlassian's API in that user's browser, so it can only export issues that user is already permitted to see. It reads the issues chosen for export (from a search, a saved filter, a board, a backlog, a sprint or a single issue) with the fields selected for the file — which can include descriptions, comments, work logs, issue links, sub-tasks and attachments or images — as well as saved filters, board configuration, the project list and the display names of users shown in the file. It never writes to Jira.
ArtUp Reports requests only these Atlassian scopes, none of which allows writing to Jira:
read:jira-work— read issues (search, fields, comments, work logs, links), saved filters, attachments and their thumbnails;read:jira-user— read display names of authors, assignees and template authors;read:board-scope:jira-software— read the issues of a board or backlog;read:sprint:jira-software— read the issues and details of a sprint;read:board-scope.admin:jira-software— read board configuration, to find the filter behind a board;read:project:jira— read the project list for project templates;storage:app— store export templates in Forge storage (section 6.3).
6.2 Where the processing happens
The Excel, Word or PDF file is built in the user's browser and downloaded directly to that user's device. Issue content, attachments and user names are not sent to the app's backend, not sent to ArtUp Labs and not sent anywhere outside Atlassian and the user's browser. The generated file exists only in the user's download.
6.3 Data the app stores
ArtUp Reports stores only export templates, in Forge storage:
| Category | Contents |
|---|---|
| Template settings | Template name, format (Excel or Word), scope (personal, project or site), the Excel column set and settings (such as layout, paper size and file-name pattern), the placeholders found in an uploaded Word template, file size, update time, and the Atlassian account id of the template's author. |
| Template index | The scope of each template id, used to find the template. |
| Word template files | The .docx file a user uploads as a template, stored in parts. |
The account id of a template's author is the only personal data ArtUp Reports stores. It is used to show who created a template and to check who may edit it; the author's display name is read from Jira when it is shown and is not stored. ArtUp Reports does not store issue fields, descriptions, comments, attachments, work logs, user names, email addresses, passwords, access tokens or payment data, and keeps no export history.
A Word template file contains whatever the user uploads; the app does not write Jira content into it. Please do not put confidential text in a template you share with a project or the whole site.
6.4 Backend and logs
ArtUp Reports' backend functions save, list and delete templates, check the current user's Jira permissions to decide who may manage a project or site template, and report whether the licence is active. They receive no issue content. If a backend function fails, the Forge platform log contains only the function name and the error message — no issue content, titles or user data. Errors in the browser stay in the user's browser.
7. What data ArtUp Query processes
7.1 Data the app reads from Jira
ArtUp Query answers JQL functions that Jira calls in a search. To do that it reads Jira as the app (not as a user): work items (key, project, type, status, dates, parent and epic), issue links, the hierarchy, the changelog entries for Sprint and status, and the metadata of comments and attachments — the author's account id, dates, the visibility type of a comment and the file extension of an attachment. It reads no comment text and no attachment content, and it never writes to Jira issues.
ArtUp Query requests these Atlassian scopes:
read:jira-work— read work items, links, the hierarchy, the changelog, comment and attachment metadata and run JQL searches;read:jira-userandread:user:jira— resolve the users and group members that conditions such asby,inRoleandinGroupmean;read:group:jiraandread:avatar:jira— read group membership (the avatar scope comes with the user and group reads; no avatars are stored);read:board-scope:jira-softwareandread:sprint:jira-software— read boards and sprints for the sprint functions;read:project:jira— read the project list for the settings page and to check project keys;read:app-data:jira— read the state of the app's JQL function precomputations;write:app-data:jira— write the app's JQL function precomputations only; it does not allow writing to work items;storage:app— the app's own Forge storage (section 7.3).
7.2 Where the processing happens
All processing happens in Atlassian's Forge runtime. The app has no external servers and makes no outbound network calls; nothing is sent to ArtUp Labs or to any third party. The settings and reference pages run in the user's browser and call only the app's backend and Jira.
7.3 Data the app stores
ArtUp Query stores the following in Forge SQL and Forge storage:
| Category | Contents |
|---|---|
| Work item index | Work item ids, project ids, the hierarchy and link edges between ids, status categories and dates. |
| Sprint history | Sprint ids, board ids, changelog entry ids, and the moves of a work item into and out of a sprint with their dates. |
| Comments and attachments | Comment and attachment ids, the Atlassian account id of the author, dates, the visibility type of a comment (comments with restricted visibility are ignored by every function), and the file extension of an attachment. |
| Results | Cached result ids of functions and the queue of pending updates. |
| Settings | The projects an administrator excluded and the state of the index. |
| Error log | The function name, the time and the error message. Never the function arguments, which contain the customer's JQL. |
The account ids of the authors of comments and attachments are the only personal data ArtUp Query stores. They are used to answer conditions such as by. Display names and email addresses are not stored. ArtUp Query does not store work item summaries, descriptions, comment bodies, attachment names or content, custom field values, passwords, access tokens or payment data.
Administrators can exclude projects from the index; the index rows of an excluded project are removed.
7.4 Backend, logs and retention
If a backend function fails, the app's error log and the Forge platform log contain only the function name, the time and the error message — no arguments, no work item content and no user data. The app deletes the index rows of a work item, comment or attachment when Jira reports that it was deleted, and removes an excluded project's rows. When the app is uninstalled, Atlassian deletes its Forge storage and SQL data according to Atlassian's data retention policy.
8. Why we process it
Data is processed only to provide the App's features: showing coverage of requirements, detecting suspect links, creating and comparing baselines, producing exports (including ArtUp Export's Markdown exports and ArtUp Reports' Excel, Word and PDF files), keeping ArtUp Reports' export templates, answering ArtUp Query's JQL functions, and diagnosing errors. We do not use App data for advertising, profiling, selling, or training machine-learning models.
Where the GDPR applies, the customer as controller determines the legal basis for processing its Jira data. Our processing of App data is on the customer's instructions, as expressed by installing and using the App. Our processing of support correspondence is based on our legitimate interest in answering your request.
9. Where the data is stored
ArtUp Trace is an Atlassian Forge app with the "Runs on Atlassian" designation. It has no external servers and makes no outbound network calls (no egress). All stored data remains in Forge SQL and Forge storage on Atlassian's infrastructure, in the customer's data residency region as handled by Atlassian. ArtUp Labs does not copy App data to its own systems.
ArtUp Export is also a Forge app with no external servers and no outbound network calls. It stores no data; Confluence content stays in the customer's Confluence site and, once exported, in the zip file on the user's device, under the customer's control.
ArtUp Reports is also a Forge app with no external servers and no outbound network calls. Its templates are stored in Forge storage on Atlassian's infrastructure, in the customer's data residency region as handled by Atlassian. Issue data stays in the customer's Jira site and, once exported, in the file on the user's device, under the customer's control. ArtUp Labs has no copy of either.
ArtUp Query is also a Forge app with no external servers and no outbound network calls. Its index and settings are stored in Forge SQL and Forge storage on Atlassian's infrastructure, in the customer's data residency region as handled by Atlassian. ArtUp Labs does not copy them to its own systems.
10. Retention and deletion
- App data is kept while the App is installed, so that coverage, confirmations and baselines remain available.
- Atlassian deletes app data stored in Forge after the app is uninstalled, according to Atlassian's data retention policy. See Atlassian's Forge storage documentation for reference.
- ArtUp Export keeps no data, so there is nothing to retain or delete after uninstalling it. Zip files users downloaded stay on their devices under the customer's control.
- ArtUp Reports keeps each template until a user with permission to manage it deletes it in the app; deleting a template removes its settings, its index entry and every part of its Word file. Atlassian deletes the app's Forge storage after the app is uninstalled, according to Atlassian's data retention policy. Files users downloaded stay on their devices under the customer's control.
- ArtUp Query keeps its index while the app is installed, so that its functions can answer. It deletes the rows of a deleted work item, comment or attachment and of a project an administrator excludes. Atlassian deletes the app's Forge storage and SQL data after the app is uninstalled, according to Atlassian's data retention policy.
- Forge platform logs are retained by Atlassian according to Atlassian's policies.
- Support emails are kept for as long as needed to handle the request and any follow-up, and deleted on request unless we must keep them by law. Support emails are deleted no later than 24 months after the last message in the conversation.
11. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Atlassian | Hosting and running the Apps (Forge), storage for ArtUp Trace (Forge SQL and Forge storage), ArtUp Reports templates (Forge storage) and the ArtUp Query index (Forge SQL and Forge storage), platform logs, Marketplace licensing and billing | Customer's data residency region as handled by Atlassian |
We use no other sub-processors for App data. We will update this list before adding one.
12. This website
The Website is a set of static pages. It sets no cookies and loads no advertising trackers. Pages are served through Cloudflare, which as our hosting and DNS provider may process technical request data (such as IP addresses) to deliver and protect the site. To count page views in aggregate, the Website uses Cloudflare Web Analytics (Cloudflare, Inc.): a script loaded from static.cloudflareinsights.com sends Cloudflare the page URL, the referrer, the browser, operating system and device type, and page load performance metrics; Cloudflare's report also shows the visitor's country. According to Cloudflare, the script uses no cookies or localStorage, the IP address is discarded at the nearest Cloudflare data center, and individual visitors are not tracked across websites. We see only aggregate statistics. See the Cloudflare Privacy Policy. The ArtUp AR XR section (artuplabs.com/ar-xr) has its own privacy policy.
13. When you email us
If you email [email protected] or [email protected], we receive your email address, name (if included) and whatever you choose to send, such as screenshots. Please do not send more Jira or Confluence content than needed. We use this only to answer you. Email is handled by our email provider, Zoho Mail (Zoho Corporation).
14. Payments
Purchases, licensing and payments are handled by Atlassian through the Atlassian Marketplace. ArtUp Labs does not receive or store payment card data. Atlassian may share with us licence and billing contact information for the purposes described in Atlassian's Marketplace terms.
15. Security
See our Security page for the App's architecture, access scopes, and how we handle vulnerabilities and incidents.
16. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to complain to a data protection authority.
- App data: because the customer is the controller, please direct requests to your organisation's Jira or Confluence administrator first. We will help the customer respond. Administrators can remove all App data by uninstalling the App.
- Correspondence with us: email [email protected]. We will respond within one month.
17. Children
The App and Website are business tools and are not directed at children.
18. Changes to this policy
We may update this policy, for example when the App gains new features or we add a sub-processor. We will change the "Last updated" date above and, for material changes, notify customers through the Marketplace listing or by email to the technical contact before the change takes effect.
19. Contact
ArtUp Labs (Artyom Karpets, individual entrepreneur), 32 E. P. Slavsky Embankment, apt. 132, Ust-Kamenogorsk (Oskemen), 070004, East Kazakhstan Region, Republic of Kazakhstan
Email: [email protected]