Privacy: browser data and organization storage
Jira exports are parsed and analyzed in your browser. When you sign in, select an organization project and have import permission, new imports are also saved to the organization database for its members.
How your Jira export is processed
Signed-out imports remain in browser storage. Organization imports can contain issue keys, summaries, descriptions, assignees, sprint names, history, original CSV row values and calculated findings. Account authentication stores your email and identity. Public educational pages and the sample project do not expose customer Jira data.
See the storage, retention and deletion details and organization access controls. The service operator has administrative database access. We do not claim a compliance certification or independent security audit.
What is stored in your browser
| What | Where | Why |
|---|---|---|
| The normalized dataset you imported | IndexedDB | So your analysis survives a page reload |
| Field mappings, status mappings, sprint dates | localStorage | So your next import needs fewer clicks |
| Thresholds, theme, analytics opt-out | localStorage | Preferences |
The local copy stays until you clear it — below, in the app’s settings, or by clearing site data in your browser.
Google Analytics
We use Google Analytics 4 (G-HED8TN1QG4) to understand which features are used. Product events exclude Jira contents:
- Jira data is not sent to Google Analytics. Events describe product usage only — for example “CSV imported” with a size bucket such as “100–499 issues”, or “report exported as CSV”.
- Event parameters are restricted by code to a fixed list of product values, booleans and small numbers. Anything else — an issue key, summary, name, project or sprint name — is rejected before sending.
- Page URLs are sent without query strings, and URLs in the app never contain sprint names (sprints are referenced by position).
- Google signals and ad personalization are disabled for analytics. Analytics is not loaded if your browser sends Global Privacy Control or Do Not Track.
Google AdSense
- Jira data is not sent to AdSense. Ads appear only on the landing page and educational guides — never in the analysis workspace.
- The ad script is loaded only when an ad placement is shown. If it was loaded earlier in the same tab, opening the workspace triggers a full page reload so that no ad script is present while your data is on screen.
- Google may use cookies to serve ads on content pages. See Google’s policy on how it uses information from sites that use its services.
Organization deletion and retention
Owners and admins can delete imports and projects in Data & imports. Only owners can delete the whole organization. Clearing this browser does not delete server records. Live database rows are removed by these deletion actions; backup retention is controlled by the service operator and provider. There is no scheduled expiration implemented for organization imports.
Conversion analytics
We measure the path from public content to signup, organization creation, CSV import and the first usable analysis. Sample exploration is not activation. Only allowlisted landing-page and source categories are attached; account IDs, email, raw referrer URLs and Jira fields are excluded from event parameters. Google Analytics can still use browser identifiers and receive network information. This is not a claim of anonymity.
Limits of this promise
Browser extensions you install can read any page, including this one; that is outside our control. If you are working with highly sensitive data, use a browser profile without extensions, or remove sensitive columns (such as Description) before importing — the analysis only requires issue keys, statuses and sprints.