1. Scope and provider
This notice applies to CloneGuard for Jira Cloud. CloneGuard is published under the 7thcode name. The applicable legal provider is the person identified in the Atlassian Marketplace listing and customer agreement. This notice supplements the general 7thcode Privacy Policy.
2. Information CloneGuard accesses
At a user’s request, CloneGuard accesses Jira work item fields, hierarchy relationships, comments, attachments, links, project metadata, create-screen metadata, users needed for field mapping, and Jira permission results. It uses this information to prepare a preflight plan and create only the approved destination work items.
3. Information CloneGuard stores
CloneGuard stores minimized operational records in installation-scoped Atlassian Forge storage: Atlassian account identifiers; source and destination Jira identifiers; mappings; plan fingerprints; approval decisions and receipts; job, node, and artifact status; timestamps; safe error codes; returned target attachment identifiers; templates; and source-to-target results.
CloneGuard does not store Jira description bodies, comment bodies, attachment bytes, passwords, API tokens, or secrets in job history or application logs. Source content is fetched from Jira only when preflight, execution, or verification requires it.
4. Purpose and permissions
Information is processed only to build and approve the requested clone contract, create approved Jira targets, prevent duplicate or unsafe writes, verify the result, provide an Evidence Package, investigate errors, protect the service, and meet legal obligations. Jira content operations run as the user who initiated the job. CloneGuard checks permissions during preflight and execution, and Jira enforces current permissions on each write.
5. Hosting, transfers, and sharing
CloneGuard runs on Atlassian Forge and declares no remote backend or external network egress. It does not sell End-User Data, use it for targeted advertising, embed a third-party analytics SDK, or share it with a 7thcode-operated sub-processor. Forge-hosted information follows Atlassian’s platform security, processing-location, and data-residency controls. Atlassian separately processes information under its own agreements and privacy terms.
6. Retention and deletion
Installed job, event, index, and template records expire after 365 days unless overwritten or erased earlier. Forge privacy events are used to erase records associated with a closed Atlassian account. After uninstall, Atlassian may retain soft-deleted Forge hosted-storage data for up to 28 days. A customer-consented recovery request must be made through Atlassian within 21 days of uninstall, as described in Atlassian’s hosted-storage lifecycle.
Evidence Package JSON is downloaded to the user’s browser. The customer controls that copy and should apply its own access and retention policy.
7. Individual rights and requests
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal information. Your Jira organization or site administrator may control profile and content information in Jira. For a CloneGuard privacy request, identify the app and affected Jira site without including credentials or confidential content in the first message.
Send a private CloneGuard privacy request ↗8. Security and changes
See the 7thcode Security Policy for private vulnerability reporting. Material changes to this notice will be published at this URL with an updated effective date. A change that introduces external processing, telemetry, a new data category, or a new sub-processor will be reviewed before release and communicated where required.