Privacy Policy
1. Introduction
sielTrace ("we," "our," or "us") operates the sielTrace application for Atlassian Jira (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
By installing and using sielTrace, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
- Business Rules & Modules: Content you create in the sielTrace "business brain" (rules, modules, documentation)
- Support Tickets: Information you submit through our support system
- Repository Configuration: Repository URLs, provider types (GitHub, GitLab, Bitbucket, AWS CodeCommit), and connection settings
2.2 Information Automatically Collected
- Usage Data: Refinement runs, number of generated items, feature usage patterns
- Jira Issue Data: Issue summaries, descriptions, and keys you choose to refine
- Account Information: Atlassian account ID, display name, email (provided by Atlassian)
- Audit Logs: User actions, timestamps, IP addresses for security and compliance
2.3 Information from Third Parties
- Repository Metadata: Repository names, file structures, README content (we DO NOT store full file contents)
- Confluence Pages: Page titles and summaries when you choose to ingest documentation
- AI Provider Data: When using BYOK (Bring Your Own Key), data is sent directly to your chosen AI provider (OpenAI, Anthropic, etc.)
3. How We Use Your Information
We use collected information to:
- Provide and maintain the Service
- Refine user stories using your business rules and repository context
- Detect conflicts between requirements and existing code/business rules
- Generate acceptance criteria and technical context
- Track usage for billing and quota enforcement
- Improve the Service through anonymized analytics
- Provide customer support
- Send administrative communications (service updates, security alerts)
- Comply with legal obligations
4. Data Storage and Security
4.1 Where We Store Data
- Primary Storage: Atlassian Forge platform storage (encrypted at rest)
- Data Residency: Data is stored in Atlassian's data centers (US-EAST-1, EU-CENTRAL-1, AP-SOUTHEAST-2)
- No Third-Party Storage: We do NOT store your data in external databases or third-party services
4.2 Security Measures
- Encryption at Rest: All data encrypted using AES-256
- Encryption in Transit: TLS 1.3 for all data transmission
- Tenant Isolation: Complete logical separation between organizations (no cross-org data access)
- Access Controls: Role-based access control (admin-only for sensitive operations)
- Secret Management: Repository tokens and API keys stored encrypted, never logged
- Audit Logging: All sensitive operations logged for security review
4.3 Data Retention
- Active Accounts: Data retained while your subscription is active
- Deleted Accounts: Data deleted within 30 days of account deletion
- Audit Logs: Retained for 90 days for security purposes
- Backups: Retained for 30 days (encrypted, automatically deleted after retention period)
5. Data Sharing and Disclosure
5.1 We DO NOT Sell Your Data
We never sell, rent, or trade your personal information or business data.
5.2 Third-Party Services
We share data only with:
Atlassian: The Service runs on Atlassian Forge platform. Atlassian may access data per their Forge Security Policy.
AI Providers (only when processing refinements):
- Forge LLM (Atlassian): Issue summaries, business rules, repository metadata sent for AI processing
- BYOK Providers: If you configure your own API key (OpenAI, Anthropic), data is sent directly from your browser to that provider
Repository Providers (only when you connect a repo):
- GitHub, GitLab, Bitbucket, AWS CodeCommit: We fetch repository metadata using your provided token
5.3 Legal Requirements
We may disclose information if required by:
- Law enforcement or government agencies (with valid legal process)
- Court orders or subpoenas
- Protection of our rights, property, or safety
6. Your Rights (GDPR & CCPA Compliance)
6.1 Access & Portability
You can export your business brain (rules, modules) anytime via the "Export Brain" feature in the app.
6.2 Rectification
You can edit or update your business rules, modules, and settings directly in the app.
6.3 Deletion (Right to be Forgotten)
Contact us at sieltrace@gmail.com to request complete data deletion. We will delete all your data within 30 days.
6.4 Data Processing Objection
You can stop AI processing by:
- Pausing refinement operations
- Disconnecting repository integrations
- Uninstalling the app
6.5 Automated Decision-Making
Our AI generates suggestions (refined items, acceptance criteria), but YOU always approve what gets created in Jira. No automated decisions affect your account without human review.
7. International Data Transfers
If you are located outside the United States:
- Data may be transferred to and processed in the US or other Atlassian data centers
- We rely on Atlassian's Standard Contractual Clauses (SCCs) for GDPR compliance
- All transfers comply with applicable data protection laws
8. Children's Privacy
The Service is intended for business use. We do not knowingly collect information from individuals under 16 years of age.
9. Cookies and Tracking
We do NOT use cookies or third-party tracking.
The Service runs entirely within Atlassian Jira. Any cookies used are managed by Atlassian per their Privacy Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted with a new "Last Updated" date. Continued use after changes constitutes acceptance.
11. Contact Us
Data Controller: sielTrace
Email: sieltrace@gmail.com
For GDPR/CCPA requests or privacy concerns, contact us at the email above with subject line "Privacy Request".