Privacy policy
Last updated: October 7, 2026
Applies to Triage for Jira (Sentry Integration), distributed on the Atlassian Marketplace.
Who we are
Voussoir Software 349 Elkins Road, #94 Elkins, NH 03233
Under UK and EU GDPR, you are the data controller and we act as a data processor for the data described here.
The short version
The app takes error data that Sentry sends it, stores a reduced version of that data inside your own Atlassian site, and creates Jira work items from it.
Nothing leaves Atlassian. The app makes no outbound network calls at all: not to us, not back to Sentry, not to anyone else. It carries Atlassian's Runs on Atlassian badge, which certifies that.
We can't see your data. It's held in your site's own Forge storage. We have no console, no export and no way to reach it.
There's no analytics, telemetry or tracking of any kind, and no third-party script, font, stylesheet or endpoint anywhere in the interface. An automated test checks this on every build.
What the app receives
Only what Sentry sends to the webhook URL you configure, which is Sentry's standard payload for issue and alert events. It can include the error title, culprit, level, platform, release and environment; the Sentry issue id, project id and slug, and the link back to Sentry; the name of the alert that fired; a stack trace; tags; the URL and method of the request that failed; and, on issue webhooks, who resolved or reopened the issue.
What the app throws away
The payload is stripped down before anything is stored or written to Jira. These are removed wherever they appear, however deeply nested, and are never written anywhere:
| Removed | Why |
|---|---|
vars, the local variables on stack frames |
Routinely hold API keys, tokens and credentials |
cookies |
Session tokens and identifiers |
headers |
Authorization headers, cookies, API keys |
extra, arbitrary developer context |
Unbounded, and often personal data |
| Query strings on request URLs | Frequently carry tokens |
Stack frames aren't filtered, they're rebuilt from a list of fields that are safe to keep: filename, function, line number and source line. Anything Sentry adds to frames in future is therefore dropped rather than passed through, which is the safer way round.
What's left is then scanned for credential-shaped text and redacted: credentials inside URLs, bearer and basic authentication, JSON web tokens, AWS access key ids, GitHub, Slack and OpenAI token prefixes, key=value secrets, PEM private key blocks and long runs of hex.
This reduces the risk rather than removing it. If your error titles or messages contain personal data, that data will end up in the Jira work items the app creates, because what goes into a Sentry error message is decided by your own application.
What the app stores, and where
All of it sits in Forge storage inside your own Atlassian site. None of it is on our systems, because we don't run any.
| What | Contents | Kept until |
|---|---|---|
| Connections | Name, optional base URL, Sentry installation id, delivery counts, timestamps | You remove the connection, or uninstall |
| Sentry Client Secrets | Held in Forge's encrypted store. Never shown back, never logged | You replace them, remove the connection, or uninstall |
| Rules | Your mapping configuration | You delete the rule, or uninstall |
| Links | Sentry issue id paired with Jira work item id | You unlink, or uninstall |
| Counters and snapshots | Event count, first and last seen, and the reduced event for display | You unlink, or uninstall |
| Delivery log | The 50 most recent deliveries: time, outcome, reason, error title, Sentry issue id, work item key | Rolls off after 50 entries |
| Daily statistics | Counts only, no event content | Uninstall |
The app also writes into Jira itself: work item summaries, descriptions, comments, two custom fields and an indexed issue property. That's ordinary Jira data, covered by your own Jira instance and your own retention policy, and it stays after the app is uninstalled.
What we never receive
We have no servers in this system. The app runs entirely on Atlassian's Forge platform inside your site. We receive no error data, no usage data, no telemetry and no personal data, and we can't read your delivery log, your rules or your Client Secrets.
Sub-processors
None, apart from Atlassian, which hosts the app as part of your Atlassian subscription.
The app uses no analytics provider, error tracker, CDN, font host, session recorder or advertising network.
Deleting data
Uninstalling the app deletes everything it stored: connections, encrypted Client Secrets, rules, links, counters, the delivery log and the statistics. Atlassian does this as part of uninstallation.
Without uninstalling, you can remove a connection to delete its stored secret and stop accepting its deliveries, unlink a work item in the Sentry error panel to delete its link and counter, or clear the delivery log from the Dashboard.
Jira work items the app created aren't deleted, because they belong to you. Delete them as you would any other work item.
Requests from data subjects
The data lives in your Atlassian site and we can't reach it, so these are served from your side. Search Jira for the work items concerned, and clear the delivery log, which is the only place the app keeps error titles outside Jira itself. We'll help with any request, but we can't carry one out for you, because we have no access to your data.
International transfers
We don't make any. Data stays in whichever Atlassian region hosts your site.
Security
Webhook signatures are verified with HMAC-SHA256 over the exact bytes received, before the payload is parsed. Unsigned requests and wrongly signed ones are rejected.
Client Secrets live in Forge's encrypted store. They're never returned to the browser and never written to logs.
A connection attaches to the first Sentry organisation that posts to it and refuses every other one, so two organisations can't read each other's data through a shared URL.
The app declares no external network permissions and can't acquire any without a new version, a manifest change visible on the Marketplace, and Atlassian's review.
If you find a vulnerability, please email support@voussoirsoftware.com rather than opening a public issue, and put "security" in the subject so it is not treated as a setup question.
Changes to this policy
Anything material will show up here with a new date, and in the app's Marketplace release notes.
Contact
Voussoir Software 349 Elkins Road, #94 Elkins, NH 03233