Version Select Privacy Policy
Effective date: September 3, 2026
Last updated: September 11, 2026
This Privacy Policy explains how VersionSelect (the App), a Jira Cloud app, processes information when it is installed and used. The App developer is identified as the app owner on the VersionSelect installation page and can be contacted using the customer-support contact displayed there.
1. Scope
This policy applies only to VersionSelect. The App developer is responsible for the App's data processing practices described here. Hosting the App on Forge does not replace this policy with Atlassian's privacy policy. Atlassian, the Jira site administrator, and the operator of any configured external service catalog have their own privacy practices and policies.
2. Information processed by the App
VersionSelect processes information needed to manage service and version choices in Jira, using either an administrator-configured external API or a manually maintained catalog:
- App configuration: the selected catalog mode, field selection limit, debug-mode preference, and, in API mode, the catalog API base URL and bearer token entered by a Jira administrator. The configured API origin is also submitted to Forge to obtain installation-specific outbound access permission.
- Manual catalog: service and version identifiers, names, optional service groups, and ordering entered or imported by an administrator, together with catalog revisions and temporary save-session data. JSON imports are read in the browser; applying an import updates the draft, and saving sends the catalog records to Forge storage. JSON exports are downloaded through the administrator's browser.
- Connection information: the outcome and timestamp of the most recent connection test.
- Catalog data: service and version identifiers, display names, optional service groups and version creation timestamps, search text, pagination and sorting values used to retrieve API results.
- Jira custom-field data: the selected service IDs, names and optional groups, version IDs and names, formatted display values, and a source identifier that labels the App's data source rather than a person. These values are stored as part of the Jira issue by Atlassian.
- Technical processing data: request context and operational information necessarily processed by Atlassian Forge to execute the App. Essential resolver errors are logged using predefined error codes. Administrators can enable detailed backend diagnostics, disabled by default, which record timestamps, operation names, random invocation correlation IDs, timings, counts, and HTTP status codes in Forge application logs. App diagnostic logs omit bearer tokens, URLs, search text, service/version names, request/response bodies, exception messages and stacks, Jira issue content, and user profile data. These logs are not additionally stored in App KVS storage.
VersionSelect currently declares the read:jira-work scope. The App does not subscribe to Jira issue events, backfill existing work items, or copy issue IDs, issue keys, issue bodies, comments, attachments, or user identity into App storage. It does not intentionally collect personal names, email addresses, Atlassian account IDs, advertising identifiers, payment information, or sensitive personal information.
Administrators should not enter or import personal or sensitive information in service names, groups, versions, or other catalog fields. Users should avoid including such information in search text. If it is supplied, it may be processed and retained in the same way as other catalog or search data described here.
3. How information is used
The information above is used only to:
- authenticate requests to the configured catalog;
- create, edit, import, export, and save a manual catalog and field settings;
- display searchable service and version choices in Jira;
- save and render the selected Jira custom-field value;
- test catalog connectivity; and
- improve reliability through short-lived response caching, error handling, and troubleshooting.
The App does not use information for advertising, behavioral profiling, marketing, or sale. It does not use third-party analytics or tracking technologies.
4. Storage and security
App configuration, manual catalogs and revisions, and API response caches are stored in Atlassian Forge hosted storage, isolated by installation. The bearer token is stored with Forge secret storage and is never returned to the browser after it is saved. Catalog requests are made by the Forge backend over HTTPS. The App does not preconfigure a catalog host; a Jira administrator authorizes the configured API origin through Forge customer-managed egress controls when saving API settings.
Selected custom-field values remain in Jira and are governed by the Jira customer's configuration, access controls, and retention policies. The App does not copy committed Jira field values into Forge hosted storage for a saved-history directory.
No method of storage or transmission is completely secure. VersionSelect uses reasonable technical measures appropriate to the limited data it processes, but absolute security cannot be guaranteed.
5. External catalog and service providers
In API mode, opening or searching service and version lists may send requests to the catalog API chosen by the Jira administrator. Requests include the configured bearer token and applicable search text and pagination values. Version-list requests also include the selected service name, its group, and sorting parameters; they do not send the App-generated service ID. Testing connectivity sends an authenticated health-check request. The App does not add Jira user identity, issue bodies, comments, or attachments to these requests. Selected service names and groups may also be present in Jira field values, and are sent as catalog lookup parameters.
Manual mode reads catalog choices from Forge storage and does not make requests to the external catalog API. API mode may reuse cached results without making a new external request. The external catalog operator may retain requests or access logs under its own policies.
Atlassian provides the Forge compute and hosted-storage infrastructure used by the App. Atlassian processes information under its own terms, privacy policy, and applicable Forge data-processing terms. The external catalog operator processes catalog requests under the terms selected by the Jira customer. VersionSelect does not sell personal information and does not disclose it to data brokers or advertisers.
Application logs
The Publisher does not view customer logs online or download customer logs. Customers download logs for their own troubleshooting and manage those copies themselves. Forge still records application diagnostics and may record platform errors and technical metadata. This practice does not mean logging is disabled or that Atlassian cannot provide developer log-access capabilities. A future change to Publisher access will require review and updated disclosure.
6. Retention and deletion
Customer administrators can create, view, edit, delete and reorder services and versions on the manual data-source configuration page, or maintain the active API catalog in their own backend service. Removing an active catalog entry does not rewrite old manual-catalog revisions or Jira field values. Those records follow their separate retention and deletion processes.
- Service-list cache entries expire after approximately five minutes.
- Version-list cache entries expire after approximately two minutes.
- Saved manual catalogs, revisions, and replaced records have no automatic expiration. Removing an option from the active catalog does not erase its previous stored records. Uncommitted temporary save-session records are assigned a 24-hour expiry; records promoted during saving become persistent. Expiry is subject to Forge's storage lifecycle and is not a guarantee of immediate physical erasure.
- App configuration and the last connection-test result persist until updated or removed under the applicable Forge data lifecycle. Switching between API and manual modes does not delete the saved API URL, bearer token, or manual catalog. Changing an API URL does not create or retain a saved-selection history partition.
- Uninstalling the App does not imply immediate erasure of hosted data. Retention and removal after uninstall follow Atlassian's Forge hosted-storage lifecycle.
- Selected field values remain in Jira until an authorized Jira user edits or deletes the issue or field data, subject to the customer's Jira retention rules.
A Jira administrator can delete the stored bearer token from the VersionSelect settings page in API mode. This does not delete other settings, caches, or catalogs. For deletion of Jira issue data, users should contact their Jira site administrator. For other privacy or App-data deletion requests, use the support contact displayed on the App's installation page to discuss the applicable process and scope. Deletion of data held by an external catalog provider must be addressed with that provider. Administrators control retention of JSON files they export or otherwise download.
7. International processing
App data in persistent Forge hosted storage follows the applicable data residency settings of the customer's Jira installation. When Jira is pinned to a supported location, Forge manages placement and migration of that installation's persistent hosted data to the chosen location. For installations without a pinned location, Atlassian determines and may change the hosting location. The supported locations and their associated countries or regions are listed in Atlassian's Forge data residency documentation. Organization administrators can inspect their site's settings in Atlassian Administration. Jira field values follow Jira's applicable data residency arrangements.
Data residency of persistent storage is distinct from processing location. Forge may execute functions outside the Jira installation's location; this policy does not promise that all execution, logs, or data in transit remain in the selected storage region. The configured external catalog's processing and storage locations are determined by its operator and should be confirmed by the Jira administrator. Atlassian and that operator may process information outside the user's country under the applicable agreements and data-transfer arrangements.
8. Children's privacy
VersionSelect is a business productivity tool and is not directed to children. The App does not knowingly collect personal information from children.
9. Privacy rights
Depending on location, individuals may have rights to access, correct, delete, restrict, or object to processing of personal information. Because VersionSelect does not intentionally store user-identifying personal information, requests concerning Jira account or issue data should normally be directed to the relevant Jira site administrator. Other requests may be sent through the support contact on the installation page.
10. Changes to this policy
This policy may be updated to reflect changes to the App, legal requirements, or service providers. The date at the top identifies the latest version. Material changes will be reflected in the published policy before or when the relevant App change is made available.
11. Contact
For privacy or support questions, contact support@fogsea.top. The Publisher handles support correspondence from mainland China. This support-mail path is separate from catalog requests, which run from Forge to the customer-configured API and do not pass through the Publisher’s computer or mailbox.