Lineset
Menu

Sumline privacy policy

Last updated 4 October 2026

Sumline (“the app”) is a Jira Cloud app built on Atlassian Forge and published by Sugar Systems, SIA (registration number 40203386400), Stirnu street 5-29, Riga, LV-1035, Latvia (“we”, “us”). This policy explains what the app does with data when a Jira site administrator installs it. What the Lineset websites and the app’s waitlist keep is in the Lineset privacy policy, which covers every app.

What the app does

Sumline reads issues in your Jira site and adds up their estimates and time fields across the issue hierarchy, then shows the result inside Jira. It reads on behalf of the person looking at the page, using their Jira permissions, so it never shows anyone an issue they could not open themselves.

Data the app processes

  • Issue data read from your Jira site: issue keys, summaries, issue types, status categories, parent links, story points, time-tracking values, sprint values, the values of any number fields your administrators chose to roll up, and the assignee's account id and display name. This data is processed to compute rollups. Display names are used only to label the assignee filter on the page being viewed and are never stored.
  • Your Atlassian account id, used only to keep each person's cached rollups separate from everyone else's and, if you dismiss the request for a review, to keep it dismissed for you.

The app processes no data from outside your Atlassian site.

Data the app stores

Everything the app stores lives in Forge Key-Value Storage, which is hosted by Atlassian inside the Atlassian cloud, in the data residency region of your site. The app stores four things:

  1. A rollup cache: the computed numbers for an issue, a space or a set of spaces, together with the issue keys, summaries and assignees' account ids needed to show them (never their names), keyed by the viewer's account id. Each entry is served for at most five minutes and deleted by Forge storage about 6 minutes after it is written.
  2. Site metadata: your site's list of fields (ids, names and types), its issue types, and the id, key, name and type (company- or team-managed) of the spaces the app has read, one entry each for the whole site, so the app does not ask Jira for them on every view. It names no person. Each entry is deleted by Forge storage about an hour after it is written.
  3. Settings chosen by your Jira administrators (which fields to roll up, including any number fields of your own, which hierarchy level makes a row, the done-only switch, whether the remaining estimate of done issues counts, the mixed-estimate rule).
  4. The review request: once the app is listed on the Atlassian Marketplace, it asks for a review in a small line that each person can dismiss. It stores the date the app was first opened on your site and, for each person who dismissed the line, their account id and the date, so the line stays dismissed.

The app stores no passwords, no API tokens and no data about people beyond what is listed above.

Where data goes

Nowhere. The app makes no network requests to any service outside Atlassian. It has no servers of its own, uses no analytics or tracking, and shares nothing with third parties. It is eligible for Atlassian's "Runs on Atlassian" program, which is Atlassian's designation for apps with no data egress.

Retention and deletion

  • Cache entries are served for at most five minutes after they are computed (less if an administrator changes the settings), and Forge storage deletes each one about 6 minutes after it is written. Forge removes expired entries in the background, so an entry can stay in storage for up to 48 hours after it expires; it is never served after five minutes.
  • Site metadata is deleted by Forge storage about an hour after it is written (again, at most 48 hours later).
  • Settings are kept until an administrator changes them.
  • The first-opened date and each dismissal of the review request are kept until the app is uninstalled.
  • All app storage is deleted by Atlassian when the app is uninstalled from your site.
  • We hold no copy of your data, so there is nothing for us to delete or return on request; your Atlassian administrators control it entirely.

Permissions the app asks for

  • read:jira-work — to read issues, their fields and the site's field definitions.
  • storage:app — to keep the cache, the site metadata, the settings and the review request's records in Forge storage.

Your rights and contact

The apps keep no copy of your Jira data outside your Atlassian site, so requests about it are handled by your Atlassian site administrators. For the waitlist, or questions about this policy, an app or the websites, contact our support site at https://sumline.atlassian.net/servicedesk/customer/portal/1 or by email at [email protected]. You can also complain to Latvia’s Data State Inspectorate (Datu valsts inspekcija).

Changes

We will update this page when an app’s data handling changes and note the date above. Material changes are also announced in that app’s Marketplace release notes.