Skip to content

Privacy policy

Effective date: 30 August 2026

This policy explains what personal data is involved when you use the Atlassian Marketplace apps Mail for Jira (app key ovh.atlasinc.jira.jira-mail) and Mail for Confluence (app key ovh.atlasinc.confluence.confluence-mail), together “the apps”, and what we do and do not receive.

It covers the Forge versions of the apps only. It does not cover Jira or Confluence themselves, the Atlassian Marketplace, or any other product.

1. Who we are

ProviderKamil Zarychta IT Consulting
Trading name on the Atlassian MarketplaceAtlas Cloudlet
Addressul. Bluszczańska 34/12, PL-00-712 Warszawa, Poland
Responsible person for privacy mattersKamil Zarychta
Contact for all privacy requestssupport@atlas-cloudlet.atlassian.net

We are established in Poland, inside the European Union, so we act through the contact above rather than through an Article 27 representative. The same contact handles requests made under the UK GDPR and under California law.

2. Summary

Unlike a browser-only app, these apps have a backend: email cannot be received without a server. Inbound mail addressed to your issues and pages is received and processed on infrastructure we operate on Cloudflare, and then stored in your own Jira or Confluence site, which remains the permanent home of your mail history. Our infrastructure keeps mail only transiently, except where a message could not be delivered and is held for retry or replay.

QuestionAnswer
Does mail content pass through our infrastructure?Yes. Every inbound message (sender address, subject, body, and attachments) transits our backend so it can be attached to your issue or page.
Do we keep a copy of your mail?Not after successful delivery: the raw message is deleted immediately once it is stored in your site. Undeliverable mail is held for up to 30 days so it can be retried or replayed, then deleted.
Where does the mail history live permanently?In your own Jira or Confluence site, as attachments and a per-item history file, under your organisation’s control.
Do we run analytics or advertising trackers?No. We keep operational logs (metadata such as job and site identifiers and error reasons, never message bodies) to run and debug the service.
Does the panel set cookies or store data in your browser?No.
Do we sell or share personal information?No. We never have.
What else do we hold?An installation registry (which sites have the app installed, with an encrypted access token per site), support correspondence you send us, and licence records Atlassian makes available to us.

3. How the apps handle your data

The path of an inbound mail

Each Jira issue and each Confluence page or blog post is given an email address on our domains (jira.mailbox.atlassian-apps.com and confl.mailbox.atlassian-apps.com). When a message arrives:

  1. The recipient address is checked against the installation registry. Mail to an address that does not correspond to an installed site is rejected at delivery time and is not stored.
  2. The accepted raw message is written to temporary storage and queued for processing.
  3. The message is parsed; its attachments are uploaded to the issue or page, and the message (sender, subject, date, body, attachment references) is appended to that item’s mail history: a JSON file stored as an attachment on the issue or page itself, in your Atlassian site. In Jira, the plain-text body is also written to an issue property so your organisation can search mail through JQL.
  4. On success, the raw message and all temporary parsing data are deleted from our storage immediately.

If a message cannot be processed (for example the site’s access token is not yet available, the message is malformed, or your site persistently rejects the write), it is held so delivery can be retried or manually replayed: mail waiting for a newly installed site is held for up to 14 days, and mail that ultimately failed is held for up to 30 days, after which it is deleted.

What the apps store, and where

DataWhere it livesHeld by
Mail history (sender, subject, body, dates, attachment links) and mail attachmentsAttachments and an issue property on your issue / pageAtlassian, inside your own site
Raw inbound messageOur Cloudflare storage, transientlyDeleted on success; up to 14 days (waiting) or 30 days (failed) otherwise
Installation registry: site identifier, site name and URL, installation identifier, timestampsOur database (hosted in the EEA)Us
Per-site access token issued by Atlassian, used to write into your siteSame database, encrypted (AES-256-GCM) at restUs
Operational logs: job and site identifiers, issue or page reference, processing outcome and error reasons, never message bodies or attachmentsCloudflare’s logging serviceCloudflare’s standard log retention (days, not months)

Email inherently contains personal data: at minimum the sender’s name and address, and whatever the message says. Senders are therefore data subjects of this processing even though they are not users of your Atlassian site.

The panel that displays the mail history requests no data beyond that history, reads it through Atlassian’s authenticated app mechanisms, and sanitises the mail HTML before display. Images inside a mail are loaded through our proxy with short-lived signed URLs; sender-hosted images are fetched by our server rather than by your browser, so the sender’s server does not see the viewer’s IP address. Proxied images may be cached on our infrastructure for up to one hour. The apps send no outbound mail and no auto-replies.

4. What we receive directly

4.1 Mail in transit

As described in section 3, inbound mail transits our infrastructure and is held transiently.

  • Purpose: delivering the mail into your Jira or Confluence site, which is the service itself.
  • Legal basis: performance of a contract with your organisation, and our legitimate interest in operating a reliable mail pipeline (GDPR Article 6(1)(b) and 6(1)(f)).
  • Retention: deleted immediately on success; up to 14 days for mail awaiting a new installation; up to 30 days for undeliverable mail; then deletion.

4.2 Support correspondence

If you contact support@atlas-cloudlet.atlassian.net, we receive whatever you choose to include: typically your name, email address, organisation, Atlassian site, and a description of the problem, along with any screenshots, message extracts, or log extracts you attach.

Our support address is an Atlassian Jira Service Management address, so support tickets are stored in Atlassian’s systems on our behalf.

  • Purpose: answering your request and fixing the reported problem.
  • Legal basis: performance of a contract, or our legitimate interest in supporting and improving the apps (GDPR Article 6(1)(b) and 6(1)(f)).
  • Retention: two years from the last message in the conversation, then deletion.

Please do not send us personal data you do not need us to see. A redacted reproduction is usually enough.

4.3 Licence and installation records

Atlassian makes licence, installation, and evaluation records for the apps available to us as their Marketplace provider. These typically include the Atlassian site, the licence tier and status, and the technical or billing contact that the customer supplied to Atlassian.

Atlassian holds these records and determines how long they are kept. We view them in Atlassian’s Marketplace partner tools to administer licences and provide support. We do not maintain a separate copy of them, load them into any system of ours, or use them for advertising or profiling.

5. Roles under data protection law

DataYour organisationAtlassianUs
Mail content in transit through our backend, and undeliverable mail held for retryControllerNot involvedProcessor to you (with Cloudflare as our sub-processor)
Mail history, attachments, and issue properties stored in your siteControllerProcessor to youNo access after delivery, except when you open it in the panel
Installation registry and per-site access tokensNot applicableNot involvedController, as technical data needed to operate the service
Support correspondence you send usNot applicableProcessor to us (Jira Service Management)Controller
Licence and installation recordsNot applicableController of its own recordsRecipient with access, for licensing and support

Because mail content passes through and can transiently rest on our infrastructure, we act as a processor for your organisation for that data. If your organisation requires a data processing agreement with us, contact support@atlas-cloudlet.atlassian.net and we will put one in place. The processing agreement for content stored in your Atlassian site remains the one between your organisation and Atlassian.

Under California law: we act as a service provider for mail content in transit, and we do not sell, share, or use for cross-context behavioural advertising any personal information at all.

6. Recipients and sub-processors

RecipientRoleWhat it involves
Atlassian (Atlassian Pty Ltd and affiliates)Platform, Marketplace, and support-desk providerHosts Jira/Confluence and the Forge apps, stores your mail history and attachments as site content, issues the per-site access tokens, holds licence records, and stores our support tickets
Cloudflare, Inc.Infrastructure provider for our backendReceives inbound email for our domains, runs the processing service, and hosts our temporary mail storage, database, queues, and operational logs

We use no other processors for the apps. There is no analytics provider, no error tracking provider, no advertising network, and no data broker in these apps.

7. International transfers

We are established in Poland and handle support correspondence from within the European Economic Area. Our database, including the encrypted access tokens, is hosted in Cloudflare’s EEA region.

Cloudflare operates a global network, so the servers that receive and process a given mail may be located outside the EEA and the United Kingdom, closest to where the mail arrives. These transfers are covered by our data processing agreement with Cloudflare, which incorporates the European Commission’s standard contractual clauses.

Atlassian may process data outside the EEA and the United Kingdom under its own transfer mechanisms. Those transfers are governed by your agreement with Atlassian and by Atlassian’s privacy policy, not by us.

8. Retention

DataRetention
Mail history, attachments, and issue properties in your siteFor as long as they exist in your Jira or Confluence site. Governed by your own retention settings; your users can also delete individual mails or a whole history in the panel.
Raw inbound message (successful delivery)Deleted immediately after the mail is stored in your site.
Mail awaiting a newly installed siteUp to 14 days, then treated as undeliverable.
Undeliverable mailUp to 30 days, for replay, then deleted.
Installation registry and encrypted access tokensThe access token is deleted at uninstall; the registry entry is removed 90 days after uninstall.
Operational logsCloudflare’s standard log retention: days, not months.
Support correspondenceTwo years from the last message.
Licence and installation recordsHeld and retained by Atlassian.

Uninstalling an app stops mail delivery to that site: subsequent mail to its addresses is rejected. Uninstalling does not delete the mail history already stored in your site, because that is part of your site content and is held by Atlassian, not by us.

9. Cookies and browser storage

The panel sets no cookies and writes nothing to localStorage, sessionStorage, or any other browser store.

Jira, Confluence, and the Forge platform set their own cookies to run the page and the app frame. Those are Atlassian’s, and Atlassian’s privacy policy and cookie notice describe them.

10. Your rights under the GDPR

For the personal data we control, which in practice is your support correspondence and the installation registry, you have the right to:

  • request access to it, and a copy of it;
  • have inaccurate data corrected;
  • have it erased;
  • have its processing restricted;
  • object to processing based on our legitimate interests;
  • receive it in a portable, machine-readable form.

We do not rely on consent for any of this processing, and we carry out no automated decision-making or profiling.

Write to support@atlas-cloudlet.atlassian.net to exercise any of these rights. We answer within one month, and will tell you if we need longer, as Article 12 permits. We may need to confirm who you are before acting, so that we do not disclose one person’s data to another.

You may also complain to a supervisory authority. Ours is:

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl

You can instead complain to the authority where you live or work.

Requests about mail stored in a Jira or Confluence site

If your request concerns personal data inside a delivered mail (for example, you sent a message to an issue address and want it removed), the controller is the organisation that operates that Atlassian site, and the request belongs with them. Their users can delete individual mails or the whole history in the panel; their administrators can also delete the underlying attachments, the issue property, or the page itself. We have no standing access to that content after delivery.

If your request concerns undeliverable mail still held on our infrastructure (section 4.1), we are the processor holding it and can delete it: contact us with enough detail to identify the message, and we will act on the instruction of the controller or, where the mail never reached any customer, on your request directly.

11. Your rights in California

We honour the rights below for California residents, whether or not our processing meets the thresholds that make the CCPA and CPRA mandatory for a business.

Categories of personal information involved. Through the apps: the contents of email sent to issue and page addresses (identifiers such as sender names and email addresses, and whatever the messages themselves contain), held transiently as described in section 3. Through support requests: identifiers such as your name and email address, professional information such as your organisation and role, and the contents of your messages to us. We collect no biometric information, no precise geolocation, and no information knowingly about anyone under 16.

Sources. Senders of email to issue and page addresses. You, when you contact us. Atlassian, for licence and installation records.

Purposes. Delivering mail into your Atlassian site, providing support, administering licences, and fixing defects. Nothing else.

Disclosure. We do not sell personal information. We do not share it for cross-context behavioural advertising. We have not done either in the preceding twelve months. Disclosures are to Atlassian and Cloudflare in their roles described in section 6.

Your rights. You may request to know what we hold and how we use it, request a copy, request correction, and request deletion. You may not be discriminated against for exercising these rights. Rights to opt out of sale or sharing and to limit the use of sensitive personal information have nothing to opt out of here, because we do neither.

Send requests to support@atlas-cloudlet.atlassian.net. An authorised agent may act for you if they provide your written permission; we may still ask you to confirm the request directly.

12. Children

The apps are business tools for Jira and Confluence and are not directed at children. We do not knowingly collect personal data from anyone under 16.

13. Security

  • Access tokens are encrypted at rest. The per-site tokens Atlassian issues to the apps are stored AES-256-GCM encrypted; the decryption key lives only in the service’s protected configuration.
  • Every backend call from Atlassian is authenticated. Requests are verified against Atlassian’s signed invocation tokens before anything is read or written.
  • Mail images are served through signed, short-lived URLs. The panel can only load an image the viewer was just authorised to see, and sender-hosted images are fetched server-side with guards that block requests into private networks.
  • Mail HTML is sanitised before display. Scripts and unsafe markup are stripped when the history is rendered in the panel.
  • No outbound mail. The apps never reply to, forward, or send email, so a mistyped address cannot cause your content to be mailed anywhere.
  • Logs carry metadata only. Operational logs identify jobs, sites, and error reasons, never message bodies or attachments.

One responsibility remains with the organisation that runs the site: a delivered mail becomes site content. Anyone who can see the issue or page can see its mail history, so apply the same permission care you apply to any other content there.

14. Changes to this policy

If we change how the apps or our support process handle personal data, we update this page and change the effective date at the top. Material changes will also be noted in the apps' Marketplace release notes.

15. Contact

Kamil Zarychta IT Consulting
ul. Bluszczańska 34/12, PL-00-712 Warszawa, Poland
support@atlas-cloudlet.atlassian.net