Project Commander
Features Issue Checker Coming soon FAQ Getting Started Docs Blog Support

Privacy Policy

Last updated: September 21, 2026 (the list of AI features)

This Privacy Policy describes how Project Commander ("we", "our", or "the App") collects, uses, and protects information when you use our Jira Cloud app.

1. Information We Access

Project Commander is a planning and analysis app for Jira Cloud, available both as a full-page app and a dashboard gadget. It provides capacity planning, delivery forecasting (including probabilistic / Monte Carlo simulation), sprint and scope management, a risk register and action tracking, portfolio and program rollups across multiple projects, saved plan baselines, and optional AI-powered insights. To provide this functionality, the App accesses the following Jira data:

Jira Project Data

  • Sprint information: Sprint names, dates, states, and goals
  • Issue data: Issue keys, summaries, story points, time estimates (original, remaining, and time spent), status, assignees, issue types, priority, due dates, start dates, resolution dates, epic links, and dependency links (blocks / blocked-by)
  • Board configuration: Board names and associated projects
  • User information: Display names of Jira users (primarily issue assignees) for workload tracking

Configuration and App-Managed Data

Project Commander also stores content that you create or configure inside the App:

  • Gadget and board settings (board selection, sprint capacity, display preferences)
  • Velocity tracking data from completed sprints
  • Sprint snapshots used for scope-creep detection
  • Team capacity configuration (per-member hours/week, utilization, time-off entries, holidays)
  • Risks (strategies, owners, mitigation actions, rationales) and action items (assignees, due dates, notes)
  • Retrospective notes and carry-over items
  • Governance policies, portfolio project lists, and alert dismissals
  • Saved plan baselines — named snapshots of scope, team capacity, delivery forecast, target date, and headline project stats, kept per project and per program
  • Per-user UI preferences and AI prompt-enrichment cache
  • Your AI provider API key, if you configure one

2. How We Use Information

All data accessed by Project Commander is used solely to provide the App's functionality:

  • Display sprint, issue, and team information in the App and dashboard gadget
  • Calculate capacity utilization, workload distribution, and feasibility scores
  • Track velocity metrics and scope changes from completed sprints
  • Surface risks, alerts, and dependency conflicts across sprints and projects
  • Roll up multiple projects into portfolio and program views
  • Run what-if scenarios, auto-leveling, critical-chain analysis, and probabilistic (Monte Carlo) forecasts
  • Save plan baselines and compare the current plan against them over time
  • Generate retrospectives and action items from closed sprints
  • Enable drag-and-drop issue management between sprints and inline editing of issue fields
  • Power optional AI features (see Section 4) when you provide an API key

3. Data Storage

All App data is stored using Atlassian Forge's built-in storage, isolated to your Jira instance and scoped to your Atlassian account. No App content is held in browser local storage as a system of record.

  • Jira Data: Project Commander reads your Jira data through Atlassian's secure APIs and never sends it to us or to any server of ours. To make repeat visits fast, the App keeps a copy of the issues it has read in your own browser, on your own device, keyed to your Atlassian account so nobody else using that browser sees it through the App; each visit then re-reads only what changed in Jira since the last read. Refresh, beside the project picker, and Start over remove that copy; a copy not used for 7 days is removed the next time the App opens; clearing your browser's site data removes it at any time.
  • Configuration and analytics: Gadget settings, team capacity configuration, velocity history, sprint snapshots (used for scope-creep detection), and per-user UI preferences are stored in Forge storage.
  • App-managed content: Risks (strategies, owners, mitigation actions, rationales), action items, retrospective notes and sprint carry-over items, governance policies, portfolio project lists, saved plan baselines, alert dismissals, and the AI prompt-enrichment cache are stored in Forge storage and follow your Atlassian account across devices.
  • AI API key: If you configure an AI provider key, it is stored using Forge's encrypted secret storage (separate from regular Forge storage) and only retrieved server-side at the moment an AI request is dispatched.

Data Retention

App data persists until you uninstall the App or clear it through the App interface. Velocity history retains the last 10 completed sprints. Uninstalling the App removes all data stored in Forge storage, including App-managed content, configuration, snapshots, the AI API key, and the AI enrichment cache. The copy of issues kept in your browser is not in Forge storage; clearing your browser's site data removes it.

The Web App at projectcommander.app/app

The web app is separate from the installed App and does not use Forge storage. Its demo mode does not collect, store, or transmit personal data: it runs on generated sample data in your browser and cannot connect to a Jira site. Its optional connect mode analyzes your own Jira through Atlassian's official sign-in (OAuth): you approve read-only access on Atlassian's consent screen for one chosen site, and the resulting access grant is held in your browser for the current tab session only, is sent with each request through our relay directly to your Jira, and is never stored or logged by us; you can revoke it at any time from your Atlassian account's Connected apps page. When you sign in to connect mode we record an irreversible connection code derived from your Atlassian account, together with sign-in dates, sign-in counts, and usage counts — never your name, email address, or site. The code cannot be turned back into your identity; we use it only to count distinct connections and, where necessary, to disable access that abuses the service. App content you create in connect mode (such as risks and settings) is held in your browser, and logging out deletes it. In connect mode the web app also keeps a copy of the issues it has read in your own browser, keyed to your Atlassian account, so repeat visits re-read only what changed; Log out, Refresh and Start over remove it, and a copy not used for 7 days is removed on the next visit. If you use the web app's optional AI features with your own provider key, your request and key are relayed to your chosen provider for that request only and are not stored by us.

4. AI Features and Third-Party Providers

Project Commander includes optional AI-powered features. They are off by default: none of them runs until you choose an AI provider and save your own API key in Settings → AI Features. The features that send data to your AI provider are:

  • What-If question box — on the What-If tab, in the Sprint and Project views. It turns a question in plain words ("what if we lose a developer for two weeks") into slider settings and an explanation.
  • AI Review — in an Auto-Level session on the Sprints tab. It reviews the rebalanced plan and names its main concerns.
  • Chain Analysis — in the Critical Chain section of the Projects tab. With a key saved, it asks your provider once, by itself, when you open that section.
  • Ask panel — in the app inside Jira. The AI works out what a question is asking when the plain words do not settle it, puts the figures the app has already worked out into a paragraph, and, when you press Write an update I can send on, writes a short update from those figures. Every figure comes from the app, never from the AI, and the panel answers without an AI at all.

These features send nothing to an AI provider: the Dashboard, the retrospective shown on a closed sprint, and the risk suggestions on the Risks tab, which are worked out by fixed rules from the project's own figures. Earlier versions had an AI box on the Dashboard and an AI button on the retrospective; both were removed on September 18, 2026.

What is sent

When you trigger an AI feature, the App builds a project-context prompt and sends it to the AI provider you have configured. The prompt may include:

  • Issue fields: keys, summaries, statuses, story points, time estimates, time spent, priority, issue types, assignee display names, due/start/resolution dates, dependency links (blocks / blocked-by), and epic links
  • Sprint fields: names, states, start/end dates, and sprint goals (free text)
  • Team and capacity context: member display names, hours per week, utilization, average velocity, time-off entries (member, dates, reason), and holiday entries
  • Velocity history and computed metrics for the project
  • For the What-If question box: the question you typed and the previous questions and answers in the same conversation, plus the project context above
  • For the Ask panel: the question you typed, the earlier questions and answers in the same sitting (until you press Clear), and the figures the app has already worked out to answer it

The prompt does not include full issue descriptions, attachments, issue comments, or your AI API key beyond the per-request header used to authenticate the call.

Some of the fields sent are free-text (notably sprint goals, time-off reasons, and the questions you type) and may contain PII or confidential information depending on what your team writes in them. If that's a concern, review the provider's data-use terms before enabling AI features, or leave them off.

Which providers

  • Anthropic (api.anthropic.com) — Claude AI models
  • OpenAI (api.openai.com) — GPT models
  • Google Gemini (generativelanguage.googleapis.com) — Gemini models

You choose which provider to use by supplying your own API key in Settings. Project Commander does not supply API keys on your behalf and does not have access to your key beyond passing it per-request to the selected provider.

Why Atlassian shows all three. Atlassian names these same three addresses under data egress — on the screen Jira shows while the App is being installed, and in Atlassian Administration under Connected apps, on this App's Data management tab. That list is what the App is permitted to reach, declared up front, and Atlassian generates it from the App's own declaration — it is not a record of anything having been sent. The App reaches one of these addresses only when you have chosen that provider and saved your own API key, and only for the one request you triggered. With no key saved, none of the three is ever contacted.

Data handling by providers

Data sent to AI providers is subject to each provider's own privacy policy and terms. Project Commander does not log, store, or retain prompts or responses on its own servers. Responses are displayed in the App and discarded.

Opting out

AI features can be disabled entirely by removing your API key from Settings. If no API key is configured, no data is ever sent to any AI provider.

5. Data Sharing

Project Commander does not share, sell, or transfer your data to third parties, except as described in Section 4 (AI providers you explicitly configure).

6. Data Security

We implement security measures to protect your information:

  • The Jira Cloud app runs entirely within Atlassian's secure Forge platform
  • All API communications use HTTPS encryption
  • API keys are stored using Forge's encrypted secret storage
  • No Jira data is transmitted to our servers
  • Access is controlled by your Jira permissions

7. Your Rights

You have the following rights regarding your data:

  • Access: View all configuration, velocity, and App-managed content (risks, action items, retros, etc.) through the App interface
  • Correction: Update your settings and App-managed content at any time through the App interface
  • Deletion: Clear velocity data and App-managed content through the App where applicable. Uninstalling the Forge app removes all App data stored in Forge storage — configuration, velocity, snapshots, team capacity, risks, action items, retros, governance, portfolio data, plan baselines, alert dismissals, AI enrichment cache, and the AI API key.
  • Portability: Your Jira data remains in Jira and is accessible through standard Jira exports. For App-managed content (risks, action items, retros), contact support@projectcommander.app if you need help exporting it.

8. Atlassian Marketplace

Project Commander is distributed through the Atlassian Marketplace. Atlassian may collect information about your use of the Marketplace and Apps. Please refer to Atlassian's Privacy Policy for details.

9. Children's Privacy

Project Commander is a business productivity tool and is not intended for use by children under 16. We do not knowingly collect information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of significant changes through the Atlassian Marketplace listing or the App interface. Continued use of the App after changes constitutes acceptance of the updated policy.

11. Contact Us

Questions or Concerns?

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: support@projectcommander.app

Project Commander
Privacy Policy Security Terms of Service Data Processing Agreement Support
Our apps Project Commander Issue Checker

© 2026 Project Commander. Operated by Donald Salz. Built for Jira Cloud.