Privacy Policy
Last updated September 28, 2026
The short version: ForgeHook does not collect, store, or transmit any customer data, webhook payloads, or Jira issue details to Crewlabs or any third party. Everything runs on Atlassian's own infrastructure, inside your Atlassian Cloud instance.
Data collection and transmission
ForgeHook does not collect, store, or transmit any customer data, webhook payloads, or Jira issue details to Crewlabs or any third-party servers. The app contains zero third-party tracking scripts, telemetry, or external analytics SDKs.
Data storage and encryption
All app configuration settings (destination project key, default issue type, summary prefix) and deduplication keys are stored strictly inside your own Atlassian Cloud Key-Value Store (KVS) — tenant-isolated to your instance.
Shared secret tokens are stored securely in Atlassian's encrypted storage and are never returned in plain text or rendered over network APIs after saving.
Subprocessors
ForgeHook runs entirely on Atlassian Forge infrastructure (*.atlassian-dev.net and *.atlassian.net). Crewlabs engages no additional cloud hosting providers or data subprocessors for ForgeHook.
Data retention and deletion
Uninstalling ForgeHook from your Jira Cloud instance automatically deletes all app configurations, stored secrets, and deduplication keys from Atlassian's Key-Value Store.
Accounts and sign-in
ForgeHook has no accounts or sign-in of its own — it operates entirely within your existing Jira Cloud site's authentication and permissions.
Changes to this policy
If this policy ever changes, the updated version will be posted at this same URL with a new "last updated" date.
Contact
Questions about this policy can be sent to support@crewlabs.io.