Data security and privacy statement
Smart Digest for Jira
Last updated: 27 September 2026
Marketplace partner: Rstak (“we”, “us”)
This statement explains how the Smart Digest for Jira app (the “App”) accesses, stores, and protects data. It is the privacy policy and the security statement for the App. Rstak, not Atlassian, is responsible for the App’s processing of end-user data. Atlassian processes Jira Cloud data under its own agreements with the customer.
1. What the App is
The App is an Atlassian Forge app for Jira Cloud. It collects issue changes and sends them as an hourly or daily digest inside Jira, and optionally by email, Slack, or Microsoft Teams. Digests stay off until each user turns them on.
The App runs on Atlassian Forge. Rstak does not operate its own servers or database for the App. Stored data remains in the customer’s Atlassian Cloud site, in Forge Storage, in the region of that site.
2. Data we access
To build a digest, the App uses these Jira permissions:
- Read Jira work. Issues, changelog, watchers, and due dates, so the digest can describe status, comment, assignee, priority, and due-date changes, and due-today or overdue reminders.
- Read Jira users. Account id and time zone, so the digest goes to the right person at the hour they chose.
- Send Jira notifications. Email is sent through Jira’s own notification feature. The App does not read or store the user’s email address or password.
- App storage. The preferences, events, and history described below.
- Report personal data. A weekly report to Atlassian of account ids the App has stored, and erasure when Atlassian marks an account closed.
A change that only edits the issue title is ignored. The App does not read issue descriptions or attachments in order to build the digest text.
3. Data we store
For a user who turns a digest on, the App may store:
- Atlassian account id
- digest frequency, daily hour, and time zone taken from the Jira profile
- filters, such as “don’t notify me about my own changes” and due-date reminders
- whether email, Slack, or Teams is turned on
- a Slack or Microsoft Teams webhook address, only if that user pastes one; it is stored as a Forge secret
- pending events: issue key, project key, event type, time, a short summary line, and the actor’s account id and display name
- a recent history of sent digests
- a marker that a due-date reminder was already sent, kept for 3 days
We do not sell personal data. We do not use it for advertising.
4. Why we store it
We store this data only to build and deliver the digest the user configured. Where the GDPR applies, the bases are performance of the contract with the customer who installed the App, and the legitimate interest in delivering those notifications. A Slack or Teams message is sent only after the user provides a webhook address.
5. Who else receives data
- Atlassian. The App reads issues and sends notification email through Atlassian APIs. Storage is Forge Storage on the customer’s site.
- Slack or Microsoft, only if the user saves a webhook. The payload is the digest text and issue keys, sent only to that address. We do not operate Slack or Teams. Those providers process the payload in their own regions.
Rstak does not transfer the stored Forge data to its own systems. There is no separate country where Rstak keeps a copy.
6. How long we keep it
- Pending events older than 7 days are discarded.
- Due-date reminder markers expire after 3 days.
- Digest history is a recent list used to show past digests in the App. It is removed when the user’s data is erased or the App is uninstalled.
- On uninstall, the App attempts to delete stored preferences, events, history, and webhook secrets. Atlassian also applies Forge retention rules after uninstall.
7. Security
- The App runs only as a Forge app. There is no vendor-hosted database to breach.
- Access is limited to the permissions listed above.
- Webhook addresses are stored as Forge secrets, not in the page the user sees.
- Traffic uses the HTTPS connections provided by Atlassian, and by Slack or Microsoft when a webhook is used.
- The App is not “Runs on Atlassian”, because a user can choose to send a digest to Slack or Teams.
If we learn of a security incident that affects customer data, we will tell affected customers and Atlassian as required by law, and we will tell users what they should do. Contact us at the address on the support page.
8. Your choices
Each user can turn the digest off, or remove a Slack or Teams webhook, under the profile menu → Smart Digest. A site admin can uninstall the App. Where the GDPR applies, a person can ask for access or erasure through Atlassian account tools and through the support address.
9. Children
The App is for workplace use. It is not directed at children.
10. Changes
We will change the “Last updated” date when this statement changes. The current version is the page linked from the Marketplace listing.
11. Contact
Rstak — see the support page.