Data Controller: Aheadnode. Contact: privacy@aheadnode.com.
1.Scope
This policy covers Smart Runbooks for Jira, an Atlassian Forge app installed by a customer's Atlassian site administrator. The app runs inside Atlassian's Forge platform. When you install and run it, the Atlassian customer is the data controller for the Jira and Confluence content processed, and Aheadnode acts as a data processor / sub-processor provider.
2.What the app processes
When a Jira issue is resolved (or on demand), the app reads the issue and creates a Confluence document. To do that it processes:
| Data | Purpose | Leaves Atlassian? |
|---|---|---|
| Issue summary, description, comments | Drafting the document | Yes — sent to Google Gemini |
| Up to 3 image attachments (images only) | Multimodal context | Yes — sent to Google Gemini |
| Linked-issue / Epic-child summaries (capped) | Extra context | Yes — sent to Google Gemini |
| Comment author display names | Attribution in the draft | Yes (as part of the prompt) |
| Account IDs (assignee / reporter) | Page contributors / review sub-task | No (used only in Atlassian APIs) |
Input sent to the AI is bounded (roughly the most-recent 25 comments and a description capped at ~8,000 characters). The app does not process payment data, and uses no analytics, advertising, or tracking technologies.
3.Sub-processor and international transfer
The only third party the app shares data with is Google (Gemini API, generativelanguage.googleapis.com), used to draft documents. Issue content is sent to Google at the moment of generation. Under Google's API terms, this content is not used to train Google's models. On the default shared key, calls are billed to Aheadnode; a customer may instead configure their own Google Gemini API key, in which case that processing is governed by the customer's own agreement with Google. Data may be processed in Google's data centers outside your region.
4.Where data is stored
All app logic runs on Atlassian Forge. The app's only datastore is Forge KVS (encrypted at rest, inside Atlassian). We store: admin settings, a per-user panel preference (keyed by Atlassian account ID), workspace-shared templates (with the author's account ID), quota counters, and the URL of each generated Confluence page. We do not store generated page bodies — those live in the customer's own Confluence. An optional customer-supplied Gemini API key is stored encrypted and never displayed.
5.Retention
Settings, preferences, templates, and page-URL checkpoints persist until the app is uninstalled or the related Jira / Confluence item is deleted (the app removes its checkpoints on issue, project, and page deletion). Generated Confluence pages are customer-owned content, governed by the customer's Confluence retention.
6.Your rights
The app supports the Atlassian Personal Data Reporting / Erasure lifecycle (declared scope report:personal-data): stored account IDs are reportable, and on an Atlassian erasure event the app removes the user's preferences and strips author IDs from templates. To exercise access, correction, deletion, or portability rights under the GDPR, CCPA, or similar laws, contact privacy@aheadnode.com or your Atlassian site administrator. Content inside generated Confluence pages is managed by the customer in Confluence.
7.Security
Least-privilege Atlassian scopes; secrets (any bring-your-own key) are stored in encrypted Forge KVS and never sent to the browser; publishing to a caller-selected space is gated by that caller's own Confluence access; Jira Service Management (customer) tickets are routed to the configured customer-KB space so customer content isn't placed in an unintended space.
8.Changes and contact
We may update this policy; material changes will be reflected here with a new effective date. Questions or requests: privacy@aheadnode.com.