Privacy Policy
The app reads the work items you ask for and builds a spreadsheet from them in your browser. It stores nothing on our side, sends nothing to us or to anyone else, and changes nothing in your Jira. The file it produces is downloaded straight to your computer.
Who we are
The app is published by Goor Software. For anything in this policy, write to support@goor.email.
Your organisation controls the data in your Jira site. We process it only on your behalf, only inside your Jira, and only to build the file you asked for.
What the app reads
The app reads the work items matched by the source you choose — a space, a saved filter, or a JQL query — and, from each of them, only the fields you selected as columns.
That selection is yours, so the categories of data are too. They may include free-text fields such as summary, description and comments, and fields naming people such as assignee and reporter. Free-text fields in Jira can contain anything your organisation put there, including personal data.
Every request is made as the signed-in user. The app cannot return a work item that person could not already open in Jira themselves. It does not widen access and never acts with elevated permissions.
What the app stores
Nothing, on our side or in Atlassian storage. The app
holds one permission, read:jira-work, and no storage
permission at all. There is no database, no cache and no copy of your
work items anywhere.
Each export is assembled in your browser, page by page, and the data is gone from memory when you close the tab.
One thing is remembered, and it is on your own device: the list
of columns you last chose, kept in your browser’s local storage
so you do not have to pick them again next week. It is a list of field
identifiers such as summary or
customfield_10015 — no work item content, no names. It
never leaves your browser, and clearing your browser data or pressing
Reset to default in the app removes it.
Where the exported file goes
This is the part worth stating plainly, because it is the point of the app: the file is downloaded to the computer of the person who exported it. From that moment it is an ordinary file outside Jira, and Jira’s permissions no longer apply to it. It can be copied, forwarded and opened by anyone who gets it.
The app does not send that file anywhere. It is built in the browser and saved locally; it does not pass through us, and there is no cloud copy, no email delivery and no third-party service involved.
Because a file is not bound by Jira permissions, the app treats exporting as a right of its own: it declares a Jira global permission, Export work items, granted by an administrator in Jira settings → System → Global permissions and held by administrators only until they decide otherwise. Being able to read work items on screen does not, by itself, allow taking them out.
What the app does not do
- It cannot write to Jira. The app holds a single
permission,
read:jira-work. There is no write permission of any kind, so it cannot create, edit, move or delete a work item, and it cannot alter timestamps. You can see this on the Marketplace listing before installing. - It sends no data to Goor Software or to any third party. The app makes no network requests outside Atlassian.
- It contains no analytics, tracking, advertising or profiling code, and sets no cookies of its own.
- It writes no application logs containing your data.
Where processing happens
The app runs entirely on Atlassian infrastructure using Atlassian Forge, under Atlassian’s Runs on Atlassian model. Reading and assembling happen inside the Atlassian cloud environment that already hosts your Jira site and inside your own browser. We operate no servers and hold no copy of your data.
Sub-processors
Atlassian is the only processor involved. Because the app neither transmits nor stores data outside Atlassian, we engage no sub-processors of our own.
Retention and deletion
There is nothing on our side to retain or delete: the app stores no data. Uninstalling it ends its access to your Jira immediately.
The column list kept in your browser is removed by clearing your browser’s site data, or by pressing Reset to default in the app.
Files that were already exported are ordinary files on the computers they were saved to, and only your organisation can manage them.
Security
The app inherits the security controls of the Atlassian Forge platform, including its authentication, tenant isolation and encryption. Because it has no write access, no external network access, no storage and no server of its own, the ways it could expose data are limited by design rather than by policy. Who may export is enforced on the server side, on every request, not only in the interface.
Your rights
Requests to access, correct or delete personal data held in your Jira site should go to your own organisation, which controls that data. We hold no separate copy to act on. If you need confirmation of what the app does, write to support@goor.email and we will answer in writing.
Changes to this policy
If the app’s handling of data changes, this page is updated and the date at the top changes with it. Material changes are noted in the app’s release notes on the Marketplace.