WhatShippedSupport

Privacy policy

Draft: this policy is under review and may change before WhatShipped is listed on the Atlassian Marketplace.

Version 1.0, September 2026. https://whatshipped.co.uk/privacy

Provider: Andrew Blackshaw, trading as WhatShipped (sole trader), Flat 49 Hale Point, 45 Ilford Hill, Ilford IG1 2ZL, United Kingdom. Contact: hello@whatshipped.co.uk. We have checked with the ICO self-assessment and are exempt from the data protection fee.

1. What the app does

WhatShipped drafts release notes and digests from resolved Jira issues. Only when a user clicks Publish does it publish them to Confluence, update a changelog index page and, if enabled, link empty Jira version descriptions.

2. Where data lives

All app data is stored in Atlassian Forge hosted storage for your site. The app has no external services, remote backends, web triggers or outbound network egress. We cannot access your Jira or Confluence content or the app's stored data. We can see the app's Forge logs, which hold error types, ids and sizes, not issue text.

3. AI processing

Drafts are generated by the Atlassian Forge LLMs API (Claude models). Prompts and issue text are processed inside Atlassian's platform; we send nothing to any third party. We make no claim about model-side retention beyond Atlassian's statements for Forge LLMs. Before text reaches the model, the app removes assignee and reporter fields and redacts mentions, email addresses, phone numbers, credentials and known display names. Output is checked so no assignee or reporter name appears.

4. Data we collect, why, and how long

We do not collect or store Atlassian account IDs, user names, email addresses, passwords or API tokens.

5. Disclosure and sub-processors

Data is disclosed to no one. The only sub-processor is Atlassian (Forge hosting, Forge LLMs, Marketplace billing). No marketing use, sale or sharing.

6. Your choices and rights

7. Legal basis and role (UK GDPR / EU GDPR)

Your organisation is controller of its Jira content; we act as processor under the Marketplace Partner Agreement and this policy. We will sign a short Article 28 data processing addendum on request. Our own processing (licence and support records) rests on contract performance and legitimate interests.

8. International transfers

Data stays in Atlassian's infrastructure under your site's data residency settings. We transfer nothing ourselves.

9. Security and incidents

See Security and data handling. Incidents affecting customer data are reported to Atlassian, affected customers and regulators as the law requires, without undue delay.

10. Changes

Material changes are announced on the Marketplace listing.