Privacy Policy
Samurai Labs
Effective Date: March 5, 2026
Last Updated: March 5, 2026
This Privacy Policy describes how Samurai Labs ("we," "us," or "our") collects, uses, stores, and protects information in connection with our Atlassian Marketplace applications (collectively, the "Apps"):
- CostLens - FinOps for Jira
- GuardRail - Security Analytics for Jira
- SmartTag - AI Labeler for Jira
- SmartTag - AI Labeler for Confluence
- PagePulse - Content Health for Confluence
- ServiceCost - Cost Intelligence for Compass
1. Architecture and Data Residency
All Apps are built on Atlassian Forge, Atlassian's cloud-native app development platform. This means:
- All data remains within Atlassian's infrastructure. Our Apps do not operate external servers or databases.
- Data residency is managed by Atlassian. Your data resides in the same region as your Atlassian Cloud instance, in accordance with Atlassian's data residency policies.
- "Runs on Atlassian" eligible. All Apps qualify for Atlassian's "Runs on Atlassian" trust badge, meaning code execution and data storage occur entirely within Atlassian's managed environment.
2. Data We Collect
2.1 Data Collected Per App
| App | Data Collected | Contains PII |
|---|---|---|
| CostLens | Project metadata, license counts, cost configurations, department mappings, calculated cost metrics, alert thresholds | No |
| GuardRail | Audit log entries (from Jira Audit API), security rules, alert configurations, compliance framework settings, risk scores | No |
| SmartTag for Jira | Issue keys, summary snippets, label names, confidence scores, duplicate pair references, project configurations | No |
| SmartTag for Confluence | Page IDs, page titles, label names, classification scores, taxonomy configurations, knowledge graph node references | No |
| PagePulse | Page IDs, health scores, link status, content age metrics, space configurations, review timestamps, Atlassian account IDs and display names for contributors, owners, reviewers, lifecycle actors, archival rule creators, and rating submitters | Yes |
| ServiceCost | Component metadata (from Compass), cost entries, budget configurations, team rollups, cost history | No |
2.2 Data We Do Not Collect
- No user credentials. Authentication is handled entirely by Atlassian Forge. We never access, store, or transmit user passwords or tokens.
- No browsing behavior. We do not track page views, clickstreams, or user navigation patterns outside the Apps.
- No cookies. Our Apps run within Atlassian's Forge iframe sandbox. We do not set or read any cookies.
2.3 User Identifiers and Activity Tracking
PagePulse stores Atlassian account IDs and display names to track content ownership, review activity, and lifecycle changes. This data is processed under the legitimate interest of providing content health monitoring functionality. Specifically, we store account identifiers for:
- Page contributors and editors: To track who has modified content
- Page owners: To associate ownership and send owner notifications
- Reviewers: To track review cycles and approval status
- Lifecycle actors: To record who initiated archival or restoration actions
- Archival rule creators: To track who created automatic archival rules
- Rating submitters: To associate user feedback with ratings
This account data is retained for the lifetime of the App installation to support historical activity reporting and audit trails. Upon receiving a GDPR deletion request through Atlassian's Privacy API, account data is anonymized or deleted in accordance with data subject rights.
3. How Data Is Stored
3.1 Forge SQL
Structured application data is stored in Forge SQL (managed MySQL), a fully managed database service provided by Atlassian as part of the Forge platform. Data is:
- Encrypted at rest and in transit per Atlassian's security standards
- Isolated per Atlassian site (tenant isolation)
- Subject to Atlassian's infrastructure security controls
3.2 Forge Key-Value Storage (KVS)
Configuration settings and cached values are stored using Forge's Key-Value Storage API (@forge/api). This storage is:
- Scoped to the specific app installation
- Managed entirely within Atlassian's infrastructure
- Subject to the same security controls as other Forge storage
4. External Data Transfers
4.1 Sentry (Error and Performance Monitoring)
Our Apps use Sentry for application error monitoring and performance analytics. This is the only external service our Apps communicate with.
- Endpoint:
*.ingest.us.sentry.io - Category: Analytics
- Data sent: Error stack traces, performance metrics, and app diagnostic information only
- No PII transmitted: Sentry integration is configured with
inScopeEUD: falsein all App manifests. No user data, account identifiers, email addresses, or any personally identifiable information is included in Sentry payloads. Error tracking uses envelope-based transport with plugin identifiers only.
4.2 No Other External Services
Beyond Sentry, our Apps make no external network requests. All Atlassian API calls (Jira, Confluence, Compass) are internal to the Forge runtime and do not leave Atlassian's infrastructure.
5. Data Retention and Deletion
5.1 Default Retention
Application data (cost metrics, health scores, labels, audit entries, etc.) is retained for the lifetime of the App installation to support historical reporting and trend analysis.
5.2 Manual Data Clearing
Site administrators can clear all App data at any time through each App's administrative interface. This permanently removes all stored data for that App.
5.3 App Uninstallation
When an App is uninstalled from an Atlassian site, all associated Forge SQL databases and Key-Value Storage data are deleted by Atlassian in accordance with Forge platform policies.
6. Atlassian Privacy API Compliance
All Apps implement Atlassian's Privacy API to handle data subject requests:
6.1 Weekly Poll
A scheduled trigger runs weekly on each App to report any stored account identifiers to Atlassian's Privacy API. If accounts require action (update or deletion), they are queued for processing.
6.2 Daily Processing Queue
A scheduled trigger runs daily on each App to process queued privacy actions:
- Update requests: Refreshes any stored references to the account
- Delete requests: Removes or anonymizes all data associated with the account
6.3 Manifest Declaration
All Apps declare the report:personal-data scope in their Forge manifests, enabling Atlassian's Privacy API integration.
7. GDPR Compliance
We are committed to compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
7.1 Lawful Basis for Processing
Data processing is based on the legitimate interest of providing the contracted service functionality (cost management, security analytics, content organization, content health monitoring) to our customers.
7.2 Rights of Data Subjects
- Right to Access (Article 15): Site administrators can view all stored data through each App's dashboard and administrative interfaces.
- Right to Rectification (Article 16): Data can be corrected through the App's administrative interface or via Atlassian's Privacy API.
- Right to Erasure (Article 17): Atlassian's Privacy API automatically routes deletion requests to our Apps. Additionally, administrators can manually clear all data at any time.
- Right to Data Portability (Article 20): Apps that support data export (CostLens, GuardRail, PagePulse, ServiceCost) provide CSV export functionality for all stored data.
- Right to Restriction of Processing (Article 18): Apps can be disabled by site administrators at any time, which halts all data processing.
- Right to Object (Article 21): Administrators can disable automated processing features (scheduled triggers, auto-labeling) through each App's settings.
7.3 Data Protection Impact Assessment
Given that our Apps process no personal data (only project metadata, content metrics, and configuration data), and all data remains within Atlassian's infrastructure, the risk to data subjects is minimal.
8. Sub-Processors
| Sub-Processor | Purpose | Data Processed |
|---|---|---|
| Atlassian Pty Ltd | Infrastructure provider (Forge platform, SQL database, Key-Value Storage, runtime execution) | All application data |
| Sentry (Functional Software, Inc.) | Error monitoring and performance analytics | Error stack traces and diagnostic data only (no PII) |
We do not use any other sub-processors. We will notify customers of any changes to sub-processors via our marketplace listing and documentation.
9. Cookie Policy
Our Apps do not use cookies.
All Apps run within Atlassian Forge's sandboxed iframe environment. We do not set, read, or rely on any cookies, local storage, or similar browser-based tracking mechanisms. Any cookies present in the user's browser session are set by Atlassian's platform, not by our Apps.
10. Children's Privacy
Our Apps are business productivity tools intended for use by organizations and their authorized users. We do not knowingly collect information from children under the age of 16.
11. International Data Transfers
Our Apps do not transfer data outside of Atlassian's infrastructure. Data residency and any international transfers are governed by Atlassian's own data processing agreements and infrastructure decisions. Please refer to Atlassian's Privacy Policy for details on how Atlassian handles data residency and transfers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the "Last Updated" date and, where appropriate, through our Atlassian Marketplace listings. Continued use of our Apps after changes constitutes acceptance of the updated policy.
13. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Samurai Labs
Email: support@banhidy.hu
Website: apps.szamuraj.com
For data protection inquiries specifically:
Email: support@banhidy.hu
*This Privacy Policy applies to all Apps published by Samurai Labs on the Atlassian Marketplace.*
Last updated: March 5, 2026