Data security and privacy statement

Smart Digest for Jira
Last updated: 27 September 2026
Marketplace partner: Rstak (“we”, “us”)

This statement explains how the Smart Digest for Jira app (the “App”) accesses, stores, and protects data. It is the privacy policy and the security statement for the App. Rstak, not Atlassian, is responsible for the App’s processing of end-user data. Atlassian processes Jira Cloud data under its own agreements with the customer.

1. What the App is

The App is an Atlassian Forge app for Jira Cloud. It collects issue changes and sends them as an hourly or daily digest inside Jira, and optionally by email, Slack, or Microsoft Teams. Digests stay off until each user turns them on.

The App runs on Atlassian Forge. Rstak does not operate its own servers or database for the App. Stored data remains in the customer’s Atlassian Cloud site, in Forge Storage, in the region of that site.

2. Data we access

To build a digest, the App uses these Jira permissions:

A change that only edits the issue title is ignored. The App does not read issue descriptions or attachments in order to build the digest text.

3. Data we store

For a user who turns a digest on, the App may store:

We do not sell personal data. We do not use it for advertising.

4. Why we store it

We store this data only to build and deliver the digest the user configured. Where the GDPR applies, the bases are performance of the contract with the customer who installed the App, and the legitimate interest in delivering those notifications. A Slack or Teams message is sent only after the user provides a webhook address.

5. Who else receives data

Rstak does not transfer the stored Forge data to its own systems. There is no separate country where Rstak keeps a copy.

6. How long we keep it

7. Security

If we learn of a security incident that affects customer data, we will tell affected customers and Atlassian as required by law, and we will tell users what they should do. Contact us at the address on the support page.

8. Your choices

Each user can turn the digest off, or remove a Slack or Teams webhook, under the profile menu → Smart Digest. A site admin can uninstall the App. Where the GDPR applies, a person can ask for access or erasure through Atlassian account tools and through the support address.

9. Children

The App is for workplace use. It is not directed at children.

10. Changes

We will change the “Last updated” date when this statement changes. The current version is the page linked from the Marketplace listing.

11. Contact

Rstak — see the support page.