Product privacy
Automation Cost & Audit for Jira
This notice explains the data boundary of the TCYM Forge app that analyzes a Jira Automation export selected by the user.
Effective date: 2026-09-09
Short version: the selected Automation export is processed in the browser and is not uploaded to TCYM or a vendor-controlled external server. TCYM does not store the selected export.
1. Provider and scope
This notice is provided by TCYM, Japan, and supplements the TCYM Privacy Policy. If this notice differs from the common policy about this product's data handling, this product notice applies for this product.
Contact: support@tcym.jp.
2. Information processed by the app
The app processes the Jira Automation JSON export that the user deliberately selects through the product interface. Depending on the export, this may include rule names and identifiers, scope information, enabled or disabled state, triggers, conditions, actions, branches, loops, JQL or other configuration text, component values, email addresses, account identifiers, or other information embedded in an Automation configuration.
The app also processes planning inputs entered by the user, such as selected Atlassian product and plan, user counts, optional known monthly Automation steps, and an optional runs-per-rule assumption. These inputs are used only to calculate the planning view in the current browser session.
3. Where processing occurs
- JSON parsing, structural classification, findings, comparison, budget calculations, and report generation occur in the Forge Custom UI in the user's browser.
- The selected export and planning inputs are not sent to a TCYM server, external database, analytics provider, advertising service, or AI provider.
- The app requests no Jira API scopes and has no Jira write capability. It does not synchronize rules with the Automation Rule Management API.
- The Forge bridge is used for Forge app context and Marketplace licensing state needed to control access to the app.
4. Storage and retention
The selected export and planning inputs are kept only in the application's browser memory for the active page/session state. The app does not intentionally persist them in Forge Storage, localStorage, sessionStorage, IndexedDB, or a TCYM-controlled database.
CSV and HTML reports are generated locally only when the user chooses to download them. After download, the file is controlled by the user's browser, device, and organization, not by TCYM. Users are responsible for protecting and deleting downloaded reports according to their own policies.
5. External communication, analytics, and telemetry
The current app manifest has no Jira API scopes and no vendor remote configured for this v0.1 data path. The app does not use external analytics, behavioral telemetry, advertising trackers, or an external AI API for export analysis. Atlassian may still process ordinary Forge, installation, account, licensing, and platform information as part of operating Forge and Marketplace under Atlassian's own terms.
6. Support messages
If a user contacts TCYM support, the information the user voluntarily sends in that support message is handled under the TCYM Privacy Policy. Users should not send a raw Jira Automation export, credentials, secrets, or customer-confidential information unless it is necessary, authorized, and specifically requested through an appropriate support process.
7. Personal data and customer responsibility
The app is not designed to collect personal data from Jira automatically, but an Automation export can contain personal or confidential information if that information was placed in rule configuration. The app may therefore process such information locally in the browser even though TCYM does not receive or store it. Users must have authorization to export and analyze the selected configuration.
8. Changes and questions
TCYM may update this notice before or with a release that materially changes the product's data boundary. For privacy or security questions, contact support@tcym.jp.
日本語要約
利用者が選択したJira Automation export JSONは、Forge Custom UI上のブラウザ内で解析されます。TCYMの外部サーバー、外部DB、アクセス解析、広告、外部AI APIには送信されません。Jira API scopeやJiraへのwrite権限はなく、Forge Storage・localStorage・sessionStorage・IndexedDBへの永続保存も行いません。Budgetでは製品・プラン・ユーザー数、既知の月間Automation steps、任意のruns-per-rule仮定などをブラウザ内で処理します。CSV・HTMLレポートは利用者が操作した場合のみローカル生成されます。Automation設定内に個人情報や機密情報が含まれる場合、それらもブラウザ内で一時的に処理される可能性がありますが、TCYMは選択したexportを受領・保存しません。お問い合わせは support@tcym.jp までご連絡ください。