Privacy Policy
PII Shield · Effective Date: September 6, 2026 · Developer: Appcento (David Day)
Overview
PII Shield ("the App") is an Atlassian Forge app that helps Jira Cloud administrators detect, redact, and manage PII (Personally Identifiable Information) in issues and comments, producing audit-ready evidence artifacts for compliance with GDPR, HIPAA, and PCI-DSS regulations.
This Privacy Policy describes how the App handles data when installed on your Atlassian Jira Cloud site.
Data Collection and Storage
The App does not collect, store, or transmit any personal data outside of your Atlassian Jira Cloud site.
The App runs entirely on the Atlassian Forge platform ("Runs on Atlassian"). All processing occurs within Atlassian's infrastructure. The App does not have any external servers, databases, or third-party service integrations.
What the App accesses
- Issue content: Issue descriptions, comments, and custom fields to detect PII patterns (emails, phone numbers, SSNs, credit cards, etc.).
- Issue metadata: Issue keys and project information for evidence record creation and audit trail logging.
- User information: Admin user information for unmask actions and audit trail logging (admin-only operations).
What the App does NOT access
- User personal information beyond standard Jira user references and admin audit logging
- Attachments or binary files (MVP focuses on text-based PII detection)
- Project settings or configurations beyond app-specific admin settings
- Any data outside the scope of issue content and metadata
Data Processing
All data processing happens within the Atlassian Forge runtime:
- Detection: The App scans issue content using regex-based pattern matching to identify PII. No data leaves Atlassian's infrastructure.
- Redaction: When PII is detected, the App redacts the content by replacing sensitive values with [REDACTED] placeholders using Jira's REST API.
- Evidence Storage: Evidence records (timestamps, hashes, patterns, regulations) are stored in Atlassian Forge Custom Entity Store within your Jira Cloud instance.
- Encrypted Vault: Original PII values are encrypted (AES-256-GCM) and stored in Atlassian Forge Secure Storage for admin verification purposes only.
- No external calls: The App makes no HTTP requests to external services. There is no egress from Atlassian's infrastructure.
Data Retention
Evidence records and audit logs are retained indefinitely within your Jira Cloud instance for compliance purposes. Original PII values stored in the encrypted vault are automatically deleted after 30 days if not reviewed by an administrator. Admins can manually purge vault entries through the admin dashboard.
Third-Party Services
The App does not use any third-party services, analytics tools, or tracking mechanisms. The App does not send data to any external servers.
Atlassian Forge Platform
The App is built on and hosted by the Atlassian Forge platform. By using the App, your data is subject to Atlassian's own data handling practices as described in:
Permissions (Scopes)
| Scope | Purpose |
|---|---|
read:jira-work |
Read issue content and metadata for PII detection and evidence record creation |
write:jira-work |
Redact PII in issues and comments by updating content with [REDACTED] placeholders |
These are the minimum scopes required for the App to function.
Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Effective Date" at the top of this document. Continued use of the App after changes constitutes acceptance of the updated policy.
Contact
If you have questions about this Privacy Policy or the App's data practices, contact us at:
Email: [email protected]
Website: https://appcento.com
PII Shield · Privacy Policy · Terms of Service · EULA · Security · Contact