Privacy Policy
Read-only Gantt for Jira is a viewer. It reads issues from your Jira site to draw a Gantt chart and does nothing else with them. It cannot change your data, it does not store it, and none of it leaves Atlassian.
Who we are
The app is published by Goor Software. For anything in this policy, write to support@goor.email.
Your organisation controls the data in your Jira site. We process it only on your behalf, only inside your Jira, and only to draw the chart you asked for.
What the app reads
To draw a chart, the app reads these fields from the issues in the project you are viewing:
- summary, issue type, status, parent
- issue links, used to draw dependency arrows
- due date and the start-date field configured for your site
- assignee, so a bar can show who a task belongs to
The assignee field contains personal data — a person’s name and avatar as they appear in Jira. It is read and shown on screen. It is never stored by the app and never sent anywhere.
Every request is made as the signed-in user. The app cannot show anyone an issue they could not already open in Jira themselves. It does not widen access, and it does not act with elevated permissions.
What the app stores
The app stores technical configuration only — never your content. Nothing anyone typed into Jira is written to the app’s storage: no summaries, descriptions, comments, attachments, statuses, dates, names or avatars. Not a single issue, in whole or in part, is copied out of your Jira site.
What is stored is the handful of identifiers the app needs to know how your site is configured. Two small records, in Atlassian Forge storage:
- Settings — which fields to treat as start and end dates, and which issue link types count as dependencies. These are field identifiers and link type names, written only by a site administrator on the app’s settings page.
- A detection cache — for each project key, the date fields the app detected, with a timestamp. It expires after 30 days and is then detected again. This exists to avoid re-running a costly query on every load.
That is the complete list: field identifiers such as
duedate or customfield_10015, project keys,
link type names such as Blocks, and a timestamp. Settings
a site administrator chose, in other words — not a record of your work.
The chart itself is assembled in your browser from data fetched live each time you open it, and it is gone when you close the tab.
What the app does not do
- It cannot write to Jira. The app holds two
permissions,
read:jira-workandstorage:app. There is no write permission of any kind, so it cannot create, edit, move or delete an issue, and it cannot alter timestamps. You can see this list on the Marketplace listing before installing. - It sends no data to Goor Software or to any third party. The app makes no network requests outside Atlassian.
- It contains no analytics, tracking, advertising or profiling code, and sets no cookies of its own.
- It writes no application logs containing your data.
Where processing happens
The app runs entirely on Atlassian infrastructure using Atlassian Forge, under Atlassian’s Runs on Atlassian model. Your data stays within the Atlassian cloud environment that already hosts your Jira site. We operate no servers of our own and hold no copy of your data.
Sub-processors
Atlassian is the only processor involved. Because the app neither transmits nor stores data outside Atlassian, we engage no sub-processors of our own.
Retention and deletion
The settings record and the detection cache are tied to the app’s installation on your site. Uninstalling the app ends its access to your Jira immediately. The stored records are then held by Atlassian for 28 days and deleted after that — this is the retention period Forge hosted storage applies to every app, and we cannot shorten it. Reinstalling the app does not bring the previous records back; it starts from defaults.
Independently of that, the detection cache expires 30 days after it is written and is then re-detected.
There is nothing else to delete: no copy of your issues exists outside your Jira site.
Security
The app inherits the security controls of the Atlassian Forge platform, including its authentication, tenant isolation and encryption of stored data. Because the app has no write access, no external network access and no server of its own, the ways it could expose data are limited by design rather than by policy.
Your rights
Requests to access, correct or delete personal data held in your Jira site should go to your own organisation, which controls that data. We hold no separate copy to act on. If you need confirmation of what the app stores, or help with a request, write to support@goor.email and we will respond within two business days.
Changes to this policy
If the app’s data handling changes — for example if it ever requests an additional permission — this page will be updated and the date at the top changed before the new version is released. Material changes will also be noted in the app’s Marketplace listing.
Contact
Goor Software · support@goor.email
Organisations needing a processor agreement can use our Data Processing Agreement.