Last updated: 2026-08-09
Jira Express (“the extension”) helps you browse Jira issues, leave comments, and log time from a Chrome side panel. This policy explains what data we process.
Who we are
Jira Express is operated by CDC Digital (“we”, “us”). CDC Digital is operated by Josef Dela Cuesta. Contact: cdcdigitallink@gmail.com .
What the extension stores on your device
Using Chrome storage, the extension may keep:
- An application session token (not your Atlassian password)
- Saved JQL views and display preferences
- Capacity / holiday / leave settings
- Unsent comment or worklog drafts
In-extension Google Analytics is disabled in v0.1.4, so the extension does not store an analytics client id or send usage events.
You can clear this by disconnecting in the extension and/or removing the extension.
What our servers store
When you connect, our backend (BFF) stores:
- Encrypted Atlassian access and refresh tokens
- Authorized Jira site metadata (cloud ID, name, URL)
- Hashed application session tokens
- Short-lived OAuth state and login-code hashes
We do not store your Atlassian password, and we do not keep a durable archive of Jira issue bodies, comments, or worklogs. Jira content is proxied to Atlassian to fulfill your request.
Third parties
- Atlassian / Jira Cloud — issue search, comments, and worklogs on your behalf after you consent
- Formspree — if you submit in-app feedback, your email and message are sent to Formspree for delivery to us
- Google Analytics — not active in v0.1.4. In-extension usage analytics is disabled in this build; no usage events are sent from the extension. Chrome Web Store listing views and installs may still appear in a separate Google Analytics property when we opt in via the Developer Dashboard.
- Ko-fi — if you open the tip panel, Ko-fi may process that interaction in its iframe
- Hosting / database / monitoring providers — operate the API infrastructure
Your choices
- Disconnect / logout in the extension deletes your connection and encrypted tokens from our servers (
DELETE /v1/session) - You can revoke access in your Atlassian account settings
- You can request help at cdcdigitallink@gmail.com
Security
Traffic uses HTTPS. Atlassian tokens are encrypted at rest on our servers. The extension does not embed Atlassian client secrets.
Changes
We may update this policy; the “Last updated” date will change. Continued use after changes means you accept the updated policy.