Worklog Ledger for Jira

Worklog Ledger privacy statement

Updated October 5, 2026. Provider: Alexander Landaverde. This statement describes the Worklog Ledger Jira Cloud application.

Data processed

The app reads currently authorized Jira worklogs: source and issue IDs, worklog IDs, author Atlassian account IDs, timestamps and integer seconds. It stores billing configurations, owner and tenant identifiers, captures, source coverage and reconciliation metadata in Atlassian Forge hosted storage. It does not intentionally store worklog comments, names or email addresses in ledger captures.

Purpose and retention

Stored data supports billing-period review, repeat comparisons and export. Captures expire after 180 days, report previews after 15 minutes, and aggregate action events and administrator-notice acknowledgements after 90 days. Saved configurations persist until deleted. Application checks enforce expiry while Forge physical deletion may occur later. Platform backups and logs follow Atlassian retention.

Usage observations

Successful report, capture, comparison and export-generation events record an action name, license category, UTC day, hashed billing period and completeness indicator under an owner/tenant storage namespace. Events exclude worklog content, hours, JQL, author IDs and comments. These observations are pseudonymous, not claimed to be anonymous. The app does not send them to an external advertising or analytics service.

Personal-data lifecycle

The app reports stored account identifiers and their oldest retrieval dates to Atlassian’s personal-data reporting API. When Atlassian requests erasure or invalidates an account’s stored data, affected captures are removed as whole records, together with related owner configurations, action records and Tempo secrets. Operators can create fresh captures after an update is processed. Minimal hashed closed-account markers are retained to prevent reintroducing erased data.

Native Jira release

Tempo connections and outbound Tempo requests are disabled for launch. Native Jira reporting requires no Atlassian PAT, password or third-party token. Any secret retained from pre-release testing can be removed through the existing disconnect operation.

Administrator notices

Customer-specific notices are restricted to the affected site and current Jira administrators. Acknowledgements record a notice identifier and time under the authenticated administrator’s storage namespace, expire after 90 days and participate in personal-data erasure. Notice configuration must not contain raw worklog content or credentials.

Data processing terms

See the data processing information for the customer DPA process, Forge suppliers and the approved supplier-notice term.

Access, disclosure and deletion

Captures are private to their creator and checked against current Jira permissions before stored rows are displayed or exported. Atlassian processes data to operate Forge and Jira. Authorized operator downloads leave the application and should be handled under your organization’s policies. We do not sell application data or use it for advertising. Delete your own configurations and captures in the app, and disconnect Tempo to remove its token. For access, correction or erasure requests concerning data stored by another operator, contact support@alexanderlandaverde.com. Please provide the product name and account/site identifiers needed to locate the records, without credentials or sensitive worklog content.