Privacy policy
Last updated: 21 August 2026 · Applies to all Nirama Solutions apps for Atlassian products, including FastPoll — Polls, Votes & Surveys for Jira, FastPoker for Jira, FastGantt — Gantt Charts & Timelines for Jira, FastRisk — Risk Matrix & RAID Log for Jira and FastAudit — Custom Field Scanner for Jira, and to this website.
The short version
Our apps run entirely on Atlassian's Forge platform inside your own Atlassian tenant. We operate no servers, and app data is never sent outside Atlassian's infrastructure ("no egress"). We cannot read your polls, estimates, issues, or configuration. The only data we receive is diagnostic logging through Atlassian's developer tools — never your content.
Data the apps store
Our apps store the following in Atlassian Forge storage, which lives in your Atlassian tenant and is hosted by Atlassian:
FastPoll
- Poll definitions — the question, options, settings (poll type, visibility rules, closing time), and the Atlassian account ID of the creator.
- Votes — the voter's Atlassian account ID, their choices (selected options, point allocations, or ranking), a timestamp, and — for non-anonymous polls only — the voter's display name, captured at the moment of voting so it can be shown next to results.
For anonymous polls, no display name is stored, and the account ID is kept solely to enforce one vote per person. It is never returned to any viewer, and vote timestamps and ordering are withheld from results so individual ballots cannot be inferred.
FastPoker
- Sessions — the project the session belongs to, its settings (deck, round timer, auto-reveal), the issue currently being estimated, and the Atlassian account ID of the facilitator.
- Participants — for each person in a session, their Atlassian account ID and a timestamp. No display name or other profile field is stored: the participant list is rendered by looking those account IDs up in Jira at the time of viewing.
- Votes — the voter's Atlassian account ID, the card they chose and a timestamp, per issue. Votes are withheld from every participant, including the facilitator, until the round is revealed.
- Accepted estimates — the issue key, the agreed value, and the round's statistics (number of voters, spread, duration).
- Project configuration — the Jira field estimates are written to, the deck, and the backlog query, if set.
A session expires automatically after 8 hours of inactivity, or when the facilitator closes it. Closing deletes the votes and the participant list — everything keyed by an account ID — leaving only the accepted estimates and their round statistics, which contain no account IDs. Uninstalling the app purges everything, including those results and the project settings.
FastGantt
- A cached projection of your Jira issues — for each issue in a project where FastGantt is used: the issue key and the fields mapped for the timeline (summary, status, dates, estimates, issue links, issue type, and the assignee's Atlassian account ID). The account ID is the only thing stored about a person — no display name, no email address, no avatar URL and no time zone. The names and faces you see on the timeline are read live from Jira each time you open the plan, with your own permissions. Everything in this cache derives from data already in your Jira; it exists so large timelines load quickly, and it is refreshed from Jira automatically.
- Project configuration — the field mapping, scheduling settings, and (if configured) the JQL query that scopes the timeline.
- Dependency scheduling metadata — the scheduling type and lag for linked issue pairs. No personal data.
- Your own view preferences — the columns and chart options you have chosen for a project, stored against your Atlassian account ID so your view follows you between machines. The record holds your settings and nothing about you.
Because FastGantt stores Atlassian account IDs, it implements Atlassian's User Privacy APIs: it reports the accounts it holds on Atlassian's reporting cycle, and erases an account's data when Atlassian reports that account closed. Uninstalling FastGantt purges its cache, settings and view preferences, and Atlassian additionally removes app storage in line with the Forge data lifecycle.
FastRisk
FastRisk stores no personal data whatsoever — no names, no email addresses, and not even an Atlassian account ID. It is the only app of ours that can say that, and it follows from the design rather than from a policy: the app keeps no record of who did anything.
What it stores in Forge storage is only:
- Per-project matrix configuration — the matrix size (3×3, 4×4 or 5×5), the wording of the likelihood and impact scale labels, and the band thresholds. Display settings; no personal data.
- Review-reminder markers — for each issue FastRisk has commented on, the issue's id and the review date it already mentioned, so the same lapse is not raised twice. An id and a date; no personal data. These are deleted automatically after 120 days.
The risk assessments themselves are not app data — they are Jira data. Likelihood, impact, score, RAID type, mitigation note and review date are stored in custom fields on your own Jira issues, and the app reads them back out of Jira on every request rather than keeping a copy. They are therefore covered by your agreement with Atlassian: Jira's retention, Jira's export, Jira's residency, Jira's issue history. The app also writes a comment mentioning the assignee when a review date lapses, and that comment is an ordinary Jira comment from then on.
Because nothing personal is held, there is nothing for FastRisk to report or erase through the Forge Privacy API. Risk owners shown in the register, and mentioned in a reminder, are read from Jira at the moment the page or comment is rendered.
Uninstalling FastRisk deletes every configuration record and reminder marker it holds. It does not delete your assessments: those are values in your own Jira fields, which Jira retains for 30 days after an app is removed so that reinstalling restores them. Erasing a customer's risk register on uninstall would be destroying their records rather than removing ours.
FastAudit
- A custom field inventory — for each custom field in the site: its id, name, description and type, how many screens, contexts and projects reference it, the date Jira last recorded it as used, the names and ids of saved filters that mention it, and the verdict the app reached with the evidence behind it. This is configuration metadata. The app records how many issues hold a value in a field, never the values themselves, and it never reads issue content.
- Snapshots and settings — a weekly count of fields, limit headroom and verdict mix for the trend chart, plus the administrator-tunable thresholds. Aggregate numbers only, no personal data.
- A cleanup journal — for each cleanup action: what was done, to which field, the verdict at the time, the result, a timestamp, and the Atlassian account ID of the administrator who performed it. This account ID is the only personal data FastAudit stores. No display name is stored — the names shown in the audit trail are looked up in Jira at the time of viewing.
Journal entries are deleted automatically 90 days after they are created. Because an Atlassian account ID is personal data, FastAudit also reports the accounts its journal holds to Atlassian each week through the Forge Privacy API, and erases an administrator's account ID from the journal as soon as Atlassian reports that the account has been closed — the record of what changed remains, without the identifier.
FastAudit only ever moves a custom field to Jira's own field trash, from where it can be restored until the deletion date Jira sets. It never deletes a field permanently, and it never changes the data held in a field.
Data we (the vendor) can access
- Your content: none. Polls, votes, estimates, issues and user data stay in your tenant. We have no API or backdoor to read them.
- Diagnostic logs. Atlassian shares app error logs with us through the Forge developer console (site admins can disable this under Atlassian Administration → Connected apps → Logs access). Our logs are deliberately sparse and never include poll questions, options, ballots, estimates, names, or account IDs.
- Aggregate metrics. Atlassian provides us anonymous operational metrics (invocation counts, error rates, latency).
Where data lives and how long
All app data is stored by Atlassian in Forge hosted storage, subject to Atlassian's own hosting, residency, and security practices. Deleting a poll permanently deletes it and its votes; closing or expiring a FastPoker session deletes its votes and participants; FastRisk's review-reminder markers are deleted 120 days after they are created; FastAudit's cleanup journal entries are deleted 90 days after they are created. Uninstalling an app ends all access to its data, and Atlassian removes app storage in line with the Forge data lifecycle.
Billing
Purchases are handled entirely by Atlassian Marketplace. We never receive payment details. Atlassian provides us standard licensing information (site, tier, license state) to operate the subscription.
This website
This website is static. It sets no cookies and runs no analytics or trackers. If you email us, we keep the correspondence for as long as needed to handle your request.
Our role under GDPR and CCPA
For the data the apps handle — account IDs, votes, polls, estimates and configuration audit records — we act as a data processor: it is processed for your purposes, on your instructions, and it stays in your own Atlassian tenant, with Atlassian as the sub-processor that hosts it. For the little personal data we hold in our own right — support and security correspondence, and the licensing and contact records Atlassian passes to us — we are the data controller, and our sub-processor for it is Microsoft, which hosts our email. Nirama Solutions AB is established in Sweden, so the GDPR applies to us in full. We are not subject to the CCPA — we meet none of its thresholds — and we never sell or share personal information.
Your rights
Because app data lives in your organisation's Atlassian tenant, requests to access, correct, or erase personal data held by an app are typically fulfilled by your own Jira administrators (for example, by deleting a poll or ending a session). For anything relating to data we hold — support correspondence or diagnostic logs — contact us and we will resolve it promptly. EU/EEA users may also have rights under the GDPR, which we honour.
Changes and contact
If this policy changes materially, we will update this page and its date. Questions: support@niramasolutions.com · Nirama Solutions AB, Sweden.