Permissions and data
Sumline only reads your Jira issues and adds up their numbers. It cannot edit an issue or change a field, it has no servers of its own, and nothing it reads or stores leaves your Atlassian site. The privacy policy is the formal version of this page.
The two permissions
read:jira-work: to read issues, their fields and the site’s field definitions.storage:app: to keep the app’s own settings and rollup cache in Forge storage.
Those are the only two. Sumline asks for no write access, calls no service outside Atlassian and declares no outside hosts.
Whose permissions it uses
Sumline reads Jira as the person viewing, never as the app. Jira applies that person’s own permissions, so nobody is shown an issue they could not open themselves, and a total only adds up the issues that person can see. The cache is kept per person, so one person’s totals are never shown to another.
What it reads
To compute a rollup, Sumline reads these fields of the issues in view: key, summary, issue type, status category, parent, story points, the time tracking values (original estimate, time spent, remaining estimate), sprint, and the assignee’s display name and account id. It also reads the viewer’s Atlassian account id, only to keep each person’s cache apart.
What it stores
Everything Sumline stores is in Forge Key-Value Storage, hosted by Atlassian in your site’s data residency region. It stores two things:
- A rollup cache. The computed numbers for an issue, a space or a set of spaces, with the issue keys and summaries needed to show them, kept per person. An entry is ignored five minutes after it was computed, or as soon as an admin changes the settings, and overwritten by the next rollup; storage has no expiry of its own. A very large result is not cached at all and is recomputed on every open.
- The settings a Jira admin chose. See Settings.
The spaces chosen for a dashboard gadget are saved by Jira as that gadget’s configuration, like any other gadget’s, not by Sumline.
It stores no passwords, no API tokens and nothing about people beyond the account ids above.
Where data goes
Nowhere. Sumline is built on Atlassian Forge and makes no network request to any service outside Atlassian. It uses no analytics or tracking and shares nothing with third parties. It is eligible for Atlassian’s “Runs on Atlassian” programme, Atlassian’s designation for apps with no data egress.
Uninstalling
When Sumline is uninstalled from a site, Atlassian deletes all of its storage. We hold no copy of your data, so there is nothing for us to delete or return; your Atlassian admins control it entirely.
Questions
For a security questionnaire or anything this page does not answer, contact our support site at https://sumline.atlassian.net/servicedesk/customer/portal/1 or by email at [email protected].