Toine.com B.V.
Privacy policy for the apps
This policy is for the apps I publish on the Atlassian Marketplace for Jira Cloud and Confluence Cloud, through Toine.com B.V. Version 1, 21 September 2026.
The short version
The apps run on Atlassian Forge, inside your own Atlassian site. They read Jira data for the person using them, store a small amount of configuration and history in Atlassian app storage, and send nothing anywhere else. I don't receive or store any of your data. No external servers, no analytics, no cookies.
Who is responsible
The vendor of the apps is Toine.com B.V. in Utrecht, the Netherlands, Chamber of Commerce 87544903. That's my company. For the data the apps process inside your site, your organisation is the controller and Atlassian is the hosting provider under the Atlassian Cloud Terms of Service. Because the apps send no data out, Toine.com B.V. never acts as a processor of your content.
What the apps read
The apps ask for the read-only Jira scopes for work items and users. So they can read issues, fields, statuses, links, versions, and the display names and account IDs of Jira users. Only within the permissions of the person using the app. They can't create, change or delete anything in Jira.
What the apps store
The apps use Forge app storage, which Atlassian hosts on your site. What's in there: the release criteria and their thresholds (project defaults and personal preferences), the daily snapshots of the criteria status per release, and the decision log with each sign-off. That log holds the Atlassian account ID and display name of the person who signed, the date, the verdict and the note they wrote. That's the only personal data the apps keep.
Nothing is stored outside Atlassian. The apps don't call any server other than Atlassian's own APIs.
How long it's kept
The data stays on your site as long as the app is installed. When you uninstall the app, Atlassian removes its storage under the Forge storage lifecycle. Site administrators can reset the criteria to defaults from within the app whenever they want.
Who can see it
Only people with access to your Atlassian site, within their Jira permissions. I have no access to your site or to the app's storage on it. What Atlassian itself can access is covered by your agreement with Atlassian.
Security
The apps are Forge apps. They run in Atlassian's sandboxed runtime, use Atlassian's authentication and authorisation, and go through Atlassian's security review before they get listed. If you find a security issue, mail the support address below. Those get priority.
This website
toine.com is a static site on Vercel. It sets no cookies, has no analytics and loads nothing from third parties. Vercel keeps standard server logs (IP address, requested page, time) to run the service.
Your rights
Requests about personal data inside your Atlassian site go to your own site administrator. They can handle those directly in the app or in Jira. Questions about this policy can go to the address below.
Changes
If I change this policy, I publish the new version on this page with a new version number and date. Bigger changes I also mention in the app's release notes on the Marketplace.
Contact
Toine.com B.V., Utrecht, the Netherlands. Email contact@toine.com.