Last updated: September 21, 2026 (the list of AI features)
This Privacy Policy describes how Project Commander ("we", "our", or "the App") collects, uses, and protects information when you use our Jira Cloud app.
Project Commander is a planning and analysis app for Jira Cloud, available both as a full-page app and a dashboard gadget. It provides capacity planning, delivery forecasting (including probabilistic / Monte Carlo simulation), sprint and scope management, a risk register and action tracking, portfolio and program rollups across multiple projects, saved plan baselines, and optional AI-powered insights. To provide this functionality, the App accesses the following Jira data:
Project Commander also stores content that you create or configure inside the App:
All data accessed by Project Commander is used solely to provide the App's functionality:
All App data is stored using Atlassian Forge's built-in storage, isolated to your Jira instance and scoped to your Atlassian account. No App content is held in browser local storage as a system of record.
App data persists until you uninstall the App or clear it through the App interface. Velocity history retains the last 10 completed sprints. Uninstalling the App removes all data stored in Forge storage, including App-managed content, configuration, snapshots, the AI API key, and the AI enrichment cache. The copy of issues kept in your browser is not in Forge storage; clearing your browser's site data removes it.
The web app is separate from the installed App and does not use Forge storage. Its demo mode does not collect, store, or transmit personal data: it runs on generated sample data in your browser and cannot connect to a Jira site. Its optional connect mode analyzes your own Jira through Atlassian's official sign-in (OAuth): you approve read-only access on Atlassian's consent screen for one chosen site, and the resulting access grant is held in your browser for the current tab session only, is sent with each request through our relay directly to your Jira, and is never stored or logged by us; you can revoke it at any time from your Atlassian account's Connected apps page. When you sign in to connect mode we record an irreversible connection code derived from your Atlassian account, together with sign-in dates, sign-in counts, and usage counts — never your name, email address, or site. The code cannot be turned back into your identity; we use it only to count distinct connections and, where necessary, to disable access that abuses the service. App content you create in connect mode (such as risks and settings) is held in your browser, and logging out deletes it. In connect mode the web app also keeps a copy of the issues it has read in your own browser, keyed to your Atlassian account, so repeat visits re-read only what changed; Log out, Refresh and Start over remove it, and a copy not used for 7 days is removed on the next visit. If you use the web app's optional AI features with your own provider key, your request and key are relayed to your chosen provider for that request only and are not stored by us.
Project Commander includes optional AI-powered features. They are off by default: none of them runs until you choose an AI provider and save your own API key in Settings → AI Features. The features that send data to your AI provider are:
These features send nothing to an AI provider: the Dashboard, the retrospective shown on a closed sprint, and the risk suggestions on the Risks tab, which are worked out by fixed rules from the project's own figures. Earlier versions had an AI box on the Dashboard and an AI button on the retrospective; both were removed on September 18, 2026.
When you trigger an AI feature, the App builds a project-context prompt and sends it to the AI provider you have configured. The prompt may include:
The prompt does not include full issue descriptions, attachments, issue comments, or your AI API key beyond the per-request header used to authenticate the call.
Some of the fields sent are free-text (notably sprint goals, time-off reasons, and the questions you type) and may contain PII or confidential information depending on what your team writes in them. If that's a concern, review the provider's data-use terms before enabling AI features, or leave them off.
You choose which provider to use by supplying your own API key in Settings. Project Commander does not supply API keys on your behalf and does not have access to your key beyond passing it per-request to the selected provider.
Why Atlassian shows all three. Atlassian names these same three addresses under data egress — on the screen Jira shows while the App is being installed, and in Atlassian Administration under Connected apps, on this App's Data management tab. That list is what the App is permitted to reach, declared up front, and Atlassian generates it from the App's own declaration — it is not a record of anything having been sent. The App reaches one of these addresses only when you have chosen that provider and saved your own API key, and only for the one request you triggered. With no key saved, none of the three is ever contacted.
Data sent to AI providers is subject to each provider's own privacy policy and terms. Project Commander does not log, store, or retain prompts or responses on its own servers. Responses are displayed in the App and discarded.
AI features can be disabled entirely by removing your API key from Settings. If no API key is configured, no data is ever sent to any AI provider.
Project Commander does not share, sell, or transfer your data to third parties, except as described in Section 4 (AI providers you explicitly configure).
We implement security measures to protect your information:
You have the following rights regarding your data:
Project Commander is distributed through the Atlassian Marketplace. Atlassian may collect information about your use of the Marketplace and Apps. Please refer to Atlassian's Privacy Policy for details.
Project Commander is a business productivity tool and is not intended for use by children under 16. We do not knowingly collect information from children.
We may update this Privacy Policy from time to time. We will notify users of significant changes through the Atlassian Marketplace listing or the App interface. Continued use of the App after changes constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: support@projectcommander.app