What TrueGuard for Jira stores, where it stays, and what you can ask us to do.
TrueGuard for Jira is an Atlassian Forge app that keeps dated records of who holds project roles in your Jira Cloud site and what changed, and lets you export them. This page covers what it stores, where, and how requests about that data are handled.
Last updated 11 October 2026
Who we are
TrueSignal Holdings Pvt Ltd operates TrueGuard for Jira. We operate from India. Contact: apps@truesignal.company, the contact form, or by post at Flat# 501, Om Sairam Nilayam, New Nallakunta, Hyderabad, Telangana 500044, India. This is also the contact point for any data-protection question; we have not appointed a data protection officer, and do not believe the law requires one for our scale of processing.
Our role
The records TrueGuard keeps are about the people in your Jira site, and you decide to install the app and what to do with them. For those records you are the controller and the app processes them for you. We are the controller only for what reaches us directly: support emails and contact-form messages, the installation and licensing details Atlassian shares with app vendors, and the app's operational logs.
If you need a data processing agreement for the app, email apps@truesignal.company.
Where the data lives
TrueGuard stores its data in Forge SQL, the hosted storage Atlassian provides to Forge apps, on your site's installation. The app makes no calls to any server outside Atlassian's platform, so TrueSignal does not receive a copy of these records. Atlassian hosts them under its own terms. As the developer, we can see the app's operational logs through Atlassian's developer tools (see What we store). Apart from the operational logs described below, data leaves the platform only when an administrator copies an evidence export out of the app.
Atlassian's own documentation says Forge SQL follows your site's data-residency pinning. We rely on that documentation and do not control it; check Atlassian's current page if residency matters to you.
What we store
- People and groups — Atlassian account ID or group ID, display name, whether it is a user, group or permission scheme, and whether the account is active.
- Access records — who holds which role in which project, or which permission scheme a project uses, with the time it was captured. Group members are not listed individually.
- Change events — role, permission-scheme, workflow and group-membership changes taken from Jira's audit log: what changed, who made the change, the before and after values, and the time. A before or after value can contain the account ID of a user added to or removed from a group. Group changes are site-wide, not per project.
- Review decisions — the reviewer's account ID, the member reviewed, the decision (confirm, revoke or needs follow-up), the time, and an optional free-text comment. The comment is whatever the reviewer types, so avoid putting anything in it you would not want kept.
- Review cycles and export log — who opened a cycle and its period, and for each evidence export who requested it, the period, a SHA-256 hash and a record count.
TrueGuard does not read or store issue content, issue comments, attachments or passwords. Operational logs hold counts, timings, project keys, dates, job and review-cycle IDs, and error messages. An error message can include an Atlassian account ID, a URL containing your site address, a value sent to the app that it rejected, or the first 300 characters of an error response from Jira. We can read these logs through Atlassian's developer tools unless an administrator has turned off log access for the app in Atlassian Administration; if access is later turned back on, Atlassian shares up to the previous 60 days of logs again.
An evidence export contains full Atlassian account IDs and reviewers' comments. Treat an export as personal data when you store or share it.
Why it is processed
The app processes this data to provide what you installed it for: dated records of access and changes, review cycles, and evidence exports. Whether your organisation has a lawful basis to keep access records about its staff and contractors, and to tell them, is for you as controller to decide. Where we are the controller of a support message you send us, we use it to answer you, on the basis of our legitimate interest in doing so.
We do not sell this data, use it for marketing, or use it to train models. TrueGuard for Jira does not use AI and makes no decision about any person. Recording a decision in the app does not change anyone's access in Jira; people at your organisation act on it in Jira.
Retention, deletion and erasure requests
Access records, change events and review decisions are append-only by design. That is what makes them usable as evidence, and it means the app has no way to edit or delete an individual record. A changed decision is added as a new entry.
The app keeps the records described under What we store for as long as it is installed on your site. It has no automatic expiry and no function to delete them, because a record deleted early would no longer be evidence.
This matters if you or a person named in your records asks for erasure. The app cannot remove one person's records. The only way to remove the app's stored data is to uninstall the app, and that removes all of it for your site, not just one person's. Atlassian's documentation says that when a Forge app is uninstalled, the data it stored in Atlassian's hosted storage is first soft-deleted and then retained for the rest of the retention period outlined in Atlassian's SOC 2 report; a separate Atlassian page states that Forge hosted storage retains data for 28 days after uninstallation. We do not control that period, and the data is not removed the moment you uninstall. Atlassian also says that if the app is reinstalled and a request is made within 21 days of uninstallation, the new installation can be relinked to the old data. Atlassian asks the app developer to make that request with the customer's consent; we would make it only if you asked us to.
Evidence exports that an administrator has copied out of the app are not affected by uninstalling and are yours to manage. The operational logs described above are ours: they are held in Atlassian's developer tools, not in the app's storage, and Atlassian's documentation on uninstalling does not say what happens to them. If you need records or logs erased or restricted earlier or in part, email apps@truesignal.company with your site address. We will answer within one month and tell you plainly what can be done and what cannot, rather than promise a deletion we cannot show.
Support emails are kept only as long as needed to answer them.
International transfers
We operate from India. Because the app's data stays on Atlassian's platform and we receive no copy, the app does not itself send your records to us. Atlassian's own terms govern where and how it hosts the data. If you email us, your message is processed in India. Messages sent through the contact form pass through Cloudflare, which hosts our website, and Resend, which delivers them to our inbox, before reaching us in India. The operational logs we read through Atlassian's developer tools are viewed from India.
EU and UK representative
We have not appointed a representative in the EU or the UK under Article 27 of the GDPR and UK GDPR. Our own assessment is that Article 27 does not apply to us: the app is offered in English to organisations that run Jira, not to individuals, and we do not monitor the behaviour of people in the EU or UK. That is our judgement and has not been independently confirmed. We will revisit it, and appoint a representative if needed, if our service starts targeting individuals in those regions or the law or regulators' guidance changes.
Security and breaches
Only an administrator of your Jira site, or an administrator of the project concerned, can open the app's screens or read its records; the app checks the signed-in user's own Jira permission on each request. The app requests only read access to your Jira data. Its permissions are listed in the app's manifest and shown on Atlassian's consent screen when you install it. If we become aware of a personal data breach affecting data the app processes for you, we will tell you without undue delay so you can meet your own notification duties.
Not a certification
TrueGuard produces dated records you can offer as access-review evidence. It is not a certification, and it does not on its own satisfy any SOC 2 or ISO 27001 control. Your auditor decides whether the records are sufficient.
Children
The app is for organisations and is not directed at children. We do not knowingly process children's data.
Your rights
Depending on where you are, you can ask for access to data held about you, to correct it, to delete it, to restrict or object to its use, and to receive it in a portable format. If you are a person named in an organisation's TrueGuard records, that organisation is the controller; email apps@truesignal.company and we will help them respond or pass your request to them. We acknowledge within 5 working days and respond in full within one month. You can also complain to your local data protection authority, for example your national supervisory authority in the EU, the Information Commissioner's Office in the UK, or the Data Protection Board of India for processing in India.
Changes to this policy
We will update this page when what we store, who processes it or where it goes changes, and change the date at the top. For material changes we will also email the contact Atlassian gives us for your installation, where it gives us one.