⚡ Project Commander
Features User Manual Privacy Terms

Privacy Policy

Last updated: March 20, 2026

This Privacy Policy describes how Project Commander ("we", "our", or "the App") collects, uses, and protects information when you use our Jira Cloud app or standalone web application.

1. Information We Access

Project Commander is a Jira dashboard gadget that helps teams manage sprint capacity. To provide this functionality, the App accesses the following Jira data:

Jira Project Data

  • Sprint information: Sprint names, dates, states, and goals
  • Issue data: Issue keys, summaries, story points, time estimates, status, assignees, and issue types
  • Board configuration: Board names and associated projects
  • User information: Display names of issue assignees for workload tracking

Configuration Data

  • Your gadget settings (board selection, capacity limits, display preferences)
  • Velocity tracking data from completed sprints

2. How We Use Information

All data accessed by Project Commander is used solely to provide the App's functionality:

  • Display sprint and issue information in the dashboard gadget
  • Calculate capacity utilization and workload distribution
  • Track velocity metrics from completed sprints
  • Enable drag-and-drop issue management between sprints

3. Data Storage

Jira Cloud App (Forge)

  • Jira Data: Project Commander does not copy or store your Jira data outside of Atlassian's infrastructure. All Jira data is accessed in real-time through Atlassian's secure APIs.
  • Configuration: Your gadget settings are stored securely using Atlassian Forge's built-in storage, which is isolated to your Jira instance.
  • Velocity Data: Historical velocity metrics are stored in Forge storage within your Atlassian environment.

Standalone Web App (Beta)

  • Credentials: Your Jira email and API token are stored only in your browser's session storage. They are cleared automatically when you close the browser tab. They are never transmitted to or stored on our servers.
  • Proxy Function: Credentials are passed per-request through a secure Netlify function that forwards API calls to your Jira instance and immediately discards them. No credentials or Jira data are logged or retained.
  • Configuration: App settings and beta session data (your name, email, and beta code) are stored in your browser's local storage.
  • Jira Data: All Jira data is fetched in real-time from your instance and displayed in the browser. No Jira data is sent to or stored on our servers.

Data Retention

  • Jira Cloud app: Configuration data persists until you uninstall the App or manually clear it. Velocity data retains the last 10 completed sprints. No data is retained after App uninstallation.
  • Standalone app: Credentials are cleared when you close the browser tab. Configuration is stored in your browser only. Nothing is retained on our servers.

4. Data Sharing

Project Commander does not share, sell, or transfer your data to third parties.

5. Data Security

We implement security measures to protect your information:

  • The Jira Cloud app runs entirely within Atlassian's secure Forge platform
  • All API communications use HTTPS encryption
  • API keys are stored using Forge's encrypted secret storage
  • No Jira data is transmitted to our servers
  • Access is controlled by your Jira permissions
  • The standalone app's API proxy restricts requests to *.atlassian.net domains and approved Jira REST API endpoints only
  • The standalone app operates in read-only mode by default and does not modify your Jira data
  • API tokens are masked during input (password field) and stored only in browser session storage

6. Your Rights

You have the following rights regarding your data:

  • Access: View all configuration and velocity data through the App interface
  • Correction: Update your settings at any time through the gadget configuration
  • Deletion: Clear velocity data through the App, or uninstall to remove all App data
  • Portability: Your Jira data remains in Jira and is accessible through standard Jira exports

7. Atlassian Marketplace

Project Commander is distributed through the Atlassian Marketplace. Atlassian may collect information about your use of the Marketplace and Apps. Please refer to Atlassian's Privacy Policy for details.

8. Children's Privacy

Project Commander is a business productivity tool and is not intended for use by children under 16. We do not knowingly collect information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes through the Atlassian Marketplace listing or the App interface. Continued use of the App after changes constitutes acceptance of the updated policy.

10. Contact Us

Questions or Concerns?

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: support@projectcommander.app

⚡ Project Commander
Privacy Policy Terms of Service Support

© 2026 Project Commander. Built for Jira Cloud.