Privacy policy

Your reminder records are stored on Atlassian Forge

This policy describes what HandoffPing stores, how Jira receives a reminder, and how reporting, retention, account closure, and uninstall cleanup work.

Who operates the app

HandoffPing is an independent Jira app operated by InGarden. Questions about this policy or a data request can be sent to mike@zhavzharov.space.

Data the app stores

Reminder records are stored in Atlassian Forge hosted storage for the Jira site installation. A record can include:

  • the Jira issue key associated with the reminder;
  • the creator's Atlassian account ID;
  • the Atlassian account IDs of specifically selected Jira people;
  • the resolved recipients' Atlassian account IDs once delivery begins;
  • the reminder message entered by the user;
  • recipient mode, delay, scheduled time, and delivery timestamps;
  • reminder state, revision, request identifier, and Jira HTTP result metadata.

The current interface offers Me, Current assignee, and Specific people. At the scheduled time, the app stores the resolved recipients' Atlassian account IDs before asking Jira to send the notification. This keeps the reminder visible to people who received it and follows assignee handoffs.

Keep reminder text minimal. It is user-provided content and may become personal or confidential if you enter such information. Do not put passwords, secrets, health data, or other sensitive personal data in a reminder.

Data the app does not copy

HandoffPing does not copy Jira issue summaries, descriptions, comments, attachments, user email addresses, display names, or group membership into its reminder records.

How a notification is processed

At the scheduled time, Forge reads the issue summary, status, and current assignee from Jira. If Jira reports that the issue is completed, the app skips delivery. Otherwise, Jira receives the issue key, reminder message, issue summary and status, resolved recipient account ID, and a Browse permission restriction. The issue summary and status are used for the notification but are not copied into the stored reminder record.

The app has no non-Atlassian backend, external database, advertising, third-party email provider, or external tracking. There is no third-party analytics on this Trust Center or in the current app build.

Operational logs

Operational logs are designed to contain a pseudonymous reminder ID, state, elapsed time, and Jira HTTP status. They are designed not to contain reminder text, Jira issue keys, or Atlassian account IDs.

Personal-data reporting and closed accounts

HandoffPing periodically sends the Atlassian account IDs represented in its Forge storage to Atlassian's personal-data reporting API. That platform request contains account IDs and retrieval dates, not reminder messages. Atlassian can identify an account as updated or closed.

An updated-account result refreshes only the reporting record; the app does not fetch or store profile fields. For a closed account, the app first blocks future writes and delivery. It then deletes creator-owned reminder messages and linked records, or removes the account from recipient data on reminders created by someone else.

Before that erasure begins, the app creates a per-installation pseudonymous suppression marker from a one-way keyed digest. The marker does not contain the raw Atlassian account ID and prevents later jobs or retries from reintroducing the closed account. The app's best-effort pre-uninstall cleanup attempts to remove this marker; if cleanup is incomplete, Atlassian's hosted-storage retention lifecycle applies.

Forge queries and cleanup jobs are bounded and retry-safe, so a closed-account cleanup may require multiple background runs. Delivery is blocked first while the remaining records are drained.

Retention and deletion

Cancelled reminder records are automatically eligible for deletion after 30 days. Completed reminder records and terminal or orphaned delivery-attempt records are eligible after 90 days. Scheduled, active, and paused reminders are not deleted merely because of age.

When an administrator uninstalls the app, a pre-uninstall job runs best-effort cleanup of Forge storage, prioritizing records that can contain personal data. The lifecycle window is bounded, so the app does not promise that every cleanup operation will finish before the uninstall completes.

After uninstall, Atlassian soft-deletes Forge-hosted storage and currently retains it for 28 days after uninstall. See Atlassian's Forge storage reference for the current platform retention and recovery details.

To ask about access, correction, or deletion, email mike@zhavzharov.space. We will identify the affected installation with its site administrator and handle the request using the capabilities available for that installation.

Atlassian platform processing

Atlassian provides the Forge compute and storage platform and processes hosted data under its own platform terms and controls. For platform-level information, review Atlassian's Forge privacy and security FAQ and privacy policy.

Changes to this policy

This page will be updated when implemented data handling or the app's availability changes. The effective date will be revised when a material update is published.