Privacy Policy
Last updated: September 26, 2026
The app
This Privacy Policy explains what data is collected by Lefryx Checklists for Jira (Templates, Automation & DoD) ("the app"), provided by Lefryx ("we", "us") as a Marketplace Partner on the Atlassian Marketplace, how that data is used, who it is disclosed to, and what choices you have.
The app is built on Atlassian Forge and runs on Atlassian-hosted compute and storage. It makes no outbound network calls to services outside Atlassian's infrastructure, and it stores no end-user data outside Atlassian products.
Our role
For data held in your Atlassian instance — checklists, templates, and the account identifiers recorded in the activity history — you are the data controller under the GDPR and we act as a data processor, processing that data only to provide the app's functionality.
For the licensing contact details Atlassian supplies to us, and for correspondence you send to our support address, we act as the data controller.
Data the app collects
The app collects only what it needs to work:
| Data | How it is used |
|---|---|
| Checklist and template content you create, including rich text, links, and @mentions | Stored and displayed as your checklists and templates. |
| Atlassian account IDs of people who create or modify a checklist item, or who are @mentioned in one | Used to record who changed what in the activity history, and to render @mentions with the correct display name. |
| Creation and modification timestamps | Used to order and display the activity history. |
| Issue, project, and issue type identifiers | Used to attach each checklist to the correct issue and to offer the right templates per project. |
| Issue details read from Jira, such as key, project, assignee, and reporter | Used to create sub-tasks in the right project, to add the key of an issue created from an item to that item's text, and to suggest people for @mentions. |
| Project list, read from Jira | Used to let you choose a project when configuring an automation rule. |
| Issues and subtasks created from checklist items | When you convert an item into an issue, Jira's own create dialog opens with the item's text as the summary and its details, or a link back to the issue, as the description. When you convert items into subtasks, the app creates them directly with the same content. The app writes to Jira only in response to these actions. |
The app collects no usage analytics or behavioural tracking data and sets no cookies. Anything kept in your browser's local storage, such as the emoji skin tone you pick, is used only for the app's interface.
Permissions the app requests
| Scope | Why it is needed |
|---|---|
storage:app | To store checklists and templates in Atlassian Forge storage for your Atlassian cloud site. |
read:jira-user | To resolve the display name of a user shown in the activity history or in an @mention. |
read:jira-work | To read the issue, project, and issue type a checklist belongs to. |
write:jira-work | To create an issue or subtask when you convert a checklist item into one. |
Where data is stored
All data the app stores is held in Atlassian Forge storage for your Atlassian cloud site, encrypted at rest and in transit by Atlassian. Data residency for this storage is provided by Atlassian as described in its documentation for Forge apps. We operate no database or infrastructure of our own. The app writes technical error logs, such as issue IDs and error messages, to Atlassian's Forge logging service; these logs contain no checklist content.
Licensing data
We act as a Marketplace Partner under the Atlassian Marketplace Partner Agreement. When you start an evaluation or buy a licence, Atlassian may provide us with the licensee's details, such as the organisation name and the name and email address of the billing and technical contacts. We access this through the Atlassian Marketplace partner interface and use it only for licensing, invoicing, tax compliance, and related communication about the app.
Support requests
If you contact us for support, we process what you choose to send us: typically your email address and any description, screenshots, or logs you attach. We use it only to investigate and resolve your request.
Who we share data with
We do not sell personal data and do not share it with third parties for advertising. The service providers involved in processing are:
| Party | Domain | Where data is stored | Purpose |
|---|---|---|---|
| Atlassian | atlassian.com | Atlassian's cloud infrastructure | Hosts the app and all data it stores; handles Marketplace licensing and billing. |
| Porkbun | porkbun.com | United States | Provides the lefryx.com domain and forwards mail sent to [email protected]. |
| Cloudflare | cloudflare.com | Cloudflare's global network | Hosts the lefryx.com website. |
| google.com | Google's global infrastructure | Hosts the mailbox that receives forwarded support mail and any email correspondence with us, and serves the web fonts used on lefryx.com. |
We may also disclose data where required by law.
Checklist data held in your Atlassian site is not transferred to any party other than Atlassian, which hosts it.
Security
Because the app runs on Atlassian Forge, it inherits the platform's security model: data is encrypted in transit and at rest by Atlassian, the app can reach only Atlassian APIs, and every request is limited to the permissions listed above.
To report a security issue, write to [email protected]. If we become aware of a personal data breach affecting you, we will notify you without undue delay.
Retention and deletion
Checklist and template data is retained for as long as the app is installed. Deleting a checklist, an item, or a template removes it from the app; an issue's activity history keeps a record of each checklist change, including the text of deleted items, and holds the latest 1,000 entries for each issue. When the app is uninstalled, the data it stored in your instance is deleted by Atlassian in line with the Forge data retention policy. We keep no copy of it at any point.
If a Jira issue is deleted, the checklist data attached to it stays in app storage until the app is uninstalled.
Licensing records are retained for as long as required for accounting and tax purposes. You can request deletion of data we hold about you by writing to the address below, and we will respond within 30 days.
Your choices and rights
You may access, correct, export, or delete personal data relating to you, and object to or restrict certain processing. For data held inside your Atlassian instance, contact your Jira administrator, who controls that data; checklists, items, and templates can also be edited or deleted directly in the app at any time. For licensing or support data, contact us at the address below. You also have the right to lodge a complaint with your local data protection authority.
Changes
We may update this Privacy Policy from time to time. The date at the top of this page shows when it was last changed, and material changes will be published here before they take effect.
Contact
Lefryx
51 Zavodska Street, Zolotonoskyi district, Chornobai, Cherkaska oblast 19901, Ukraine
[email protected]