Privacy policy
Draft: this policy is under review and may change before WhatShipped is listed on the Atlassian Marketplace.
Version 1.0, September 2026. https://whatshipped.co.uk/privacy
Provider: Andrew Blackshaw, trading as WhatShipped (sole trader), Flat 49 Hale Point, 45 Ilford Hill, Ilford IG1 2ZL, United Kingdom. Contact: hello@whatshipped.co.uk. We have checked with the ICO self-assessment and are exempt from the data protection fee.
1. What the app does
WhatShipped drafts release notes and digests from resolved Jira issues. Only when a user clicks Publish does it publish them to Confluence, update a changelog index page and, if enabled, link empty Jira version descriptions.
2. Where data lives
All app data is stored in Atlassian Forge hosted storage for your site. The app has no external services, remote backends, web triggers or outbound network egress. We cannot access your Jira or Confluence content or the app's stored data. We can see the app's Forge logs, which hold error types, ids and sizes, not issue text.
3. AI processing
Drafts are generated by the Atlassian Forge LLMs API (Claude models). Prompts and issue text are processed inside Atlassian's platform; we send nothing to any third party. We make no claim about model-side retention beyond Atlassian's statements for Forge LLMs. Before text reaches the model, the app removes assignee and reporter fields and redacts mentions, email addresses, phone numbers, credentials and known display names. Output is checked so no assignee or reporter name appears.
4. Data we collect, why, and how long
- Issue summaries, descriptions, comments, labels, resolution, fix version, sprint. Used to build the draft. Evidence quotes are kept so bullets can be traced. After 13 months (adjustable), unpublished notes are deleted and published notes keep only the published text.
- Assignee and reporter display names. Leak check only; never sent to the model. Temporary; deleted when the draft completes or fails.
- User count (
read:jira-user). Sizes the paid-tier budget. Only the number is kept; no user record, name or ID. - Voices, schedules, publish targets, edit-feedback pairs. Run the workflow and improve later drafts. Edit-feedback is capped at the newest 50 per project and voice.
- Cost ledger and error log. Budget cap and diagnostics. Ledger kept 13 months; error log 90 days.
We do not collect or store Atlassian account IDs, user names, email addresses, passwords or API tokens.
5. Disclosure and sub-processors
Data is disclosed to no one. The only sub-processor is Atlassian (Forge hosting, Forge LLMs, Marketplace billing). No marketing use, sale or sharing.
6. Your choices and rights
- Delete a note: removes the note and all its app data immediately.
- Uninstall: Atlassian deletes the app's Forge storage for your site.
- Published pages are your own content.
- Site users send access, correction and erasure requests to their site administrator. The app stores no personal identifiers, so Atlassian's personal data reporting API does not apply. Requests about our own records (licence and support contacts from Atlassian) go to hello@whatshipped.co.uk; we respond within one month. Complaints: Information Commissioner's Office, https://ico.org.uk.
7. Legal basis and role (UK GDPR / EU GDPR)
Your organisation is controller of its Jira content; we act as processor under the Marketplace Partner Agreement and this policy. We will sign a short Article 28 data processing addendum on request. Our own processing (licence and support records) rests on contract performance and legitimate interests.
8. International transfers
Data stays in Atlassian's infrastructure under your site's data residency settings. We transfer nothing ourselves.
9. Security and incidents
See Security and data handling. Incidents affecting customer data are reported to Atlassian, affected customers and regulators as the law requires, without undue delay.
10. Changes
Material changes are announced on the Marketplace listing.