dsplugins

Scope Planner — Privacy Policy

Last updated: 7 October 2026

Scope Planner is a Jira Cloud app built on Atlassian Forge. It runs entirely on Atlassian’s infrastructure and has no servers, storage, or network egress outside Atlassian. The app’s manifest declares no external permissions, so the Forge platform itself blocks any outbound call — this is enforced by Atlassian, not merely promised by us.

In short: the app stores your estimation drafts and preferences inside your own Atlassian site, identifies people only by their Atlassian account ID, sends nothing anywhere, uses no analytics or cookies, and deletes a person’s private data automatically when their Atlassian account is deleted.

Who we are

Scope Planner is developed and published on the Atlassian Marketplace by DSPlugins (“we”, “the developer”). Contact: dsplugins@gmail.com.

Roles

For data protection purposes, the customer operating the Atlassian site remains the controller of all data the app touches. Atlassian hosts and processes that data on its infrastructure under the customer’s existing agreements with Atlassian. The developer operates no infrastructure of its own and receives no copies of customer data.

What data the app processes

Who can see a team draft

Anyone who can browse every Jira project the draft’s scope touches. They do not have to have opened that scope, and they do not have to have a draft of their own.

⚠️ What this widens is the scope description, and it is worth being explicit about. Sharing a draft makes its name and its JQL text — both free text you typed — readable by that whole group, not only by people who had already worked on the scope. The app tells you this on the review screen before you share.

Two things are unchanged:

Because a JQL string can name a person (assignee = "alex@example.com"), the retention period is the control that limits how long that text is exposed — see “Data retention and deletion” below.

What the app does NOT do

CSV export (Pro)

The CSV export is generated inside your own browser and saved directly to your device when you explicitly request it. The app transmits nothing anywhere in the process; what you then do with the exported file is under your control and your organisation’s policies.

Sub-processors

Atlassian is the only party that hosts or processes data for the app: Forge compute, Forge hosted storage and the Jira APIs, under your organisation’s agreements with Atlassian. The developer uses no other sub-processor, hosting provider or service.

Data retention and deletion

Data residency

All data the app stores lives in Atlassian Forge hosted storage, so it follows the data residency location of your Atlassian site, and moves with it if your site’s data is migrated to another location. The app stores no data anywhere else.

In scope for data residency: private drafts, team drafts, publish records, user preferences, site settings, the velocity cache and the permissions cache — that is, everything listed under “What data the app processes” that the app stores. Out of scope: nothing the app stores is out of scope. Jira issue data itself is held by Jira, under Jira’s own data residency.

Security

Permissions

The app requests the minimum Jira scopes needed to read issues, boards, and sprints, write estimate fields, and store drafts (read:jira-work, write:jira-work, read:jira-user, read:board-scope:jira-software, read:board-scope.admin:jira-software, read:project:jira, read:sprint:jira-software, storage:app). All Jira writes happen as the acting user, so Jira’s own permission scheme always applies.

read:board-scope.admin:jira-software is used for a single read: the app compares the board’s own estimation field against the field an administrator configured, so it can warn you when the two disagree. It reads board configuration only — no issue content, no user data, and nothing is written with it.

Your rights

Because your organisation is the controller, requests to access, correct, export or erase personal data are best made to your Jira site administrator, who has control over your Atlassian site and the accounts on it. Deleting or anonymizing an Atlassian account triggers the app’s automatic erasure described above. You can also delete your own private drafts at any time from the app’s 🗂 Drafts screen. If you need help with a request, contact us.

The app is a business tool for Jira users and is not directed at children.

Changes to this policy

This policy may be updated when the app’s functionality changes. The “Last updated” date above reflects the current revision; material changes will be noted in the app’s release notes on the Atlassian Marketplace. Continued use of the app after a change constitutes acceptance of the updated policy.

Contact

Questions about this policy or your data: dsplugins@gmail.com