Data Access and Privacy

Understand how JetTime stores and protects your data.

JetTime is designed with privacy and security as core priorities. By leveraging Atlassian Forge and its robust infrastructure, JetTime ensures that all app data, including your work logs and their metadata, is protected, remaining securely within Atlassian's environment. As the vendor, we have no access to this data, so we are offering you a true privacy-first solution.

How JetTime Protects Your Data

Runs on Atlassian

JetTime is built with Atlassian Forge and adheres to the industry's highest standards as part of the Runs on Atlassian program — an official Atlassian program where Atlassian itself verifies that qualifying apps use only Atlassian-hosted compute and storage. Here's how your data is protected:

  • Runs on Atlassian: JetTime operates entirely on Atlassian's secure cloud infrastructure, meaning Atlassian fully manages the app's backend.
  • Data Privacy: All app data, including work logs and their metadata, is securely stored either within your Jira instance using the Jira APIs or in Forge's secure storage service. The data never leaves Atlassian's infrastructure.
  • No Vendor Access: As the vendor, we do not have access to your data at any point. It stays fully within Jira's environment, where Jira's permissions decide who can reach it — and inside JetTime, what someone sees is decided by JetTime's own grants on top of those.
  • Data Residency: Atlassian Forge automatically enforces your Jira instance's data residency settings, ensuring compliance with your organization's policies regarding where its data is stored.
  • Certified Security: Atlassian's platform adheres to various security and compliance certifications like ISO/IEC 27001, SOC 2, GDPR, HIPAA, and more, offering you enterprise-grade security and peace of mind.

Important Notes on Work Log Access

Two sets of rules decide who can see and change a work log, and only one of them is Jira's.

JetTime has its own permissions, configured inside the app under Settings > Roles and Permissions: app-wide Global Permissions, and per-object Permission Schemes attached to a team, an account, or a workstream. Both sides have to allow an action — Jira's permission on the space, and JetTime's on the team or account. See Managing App Permissions for the model.

It works the other way too. JetTime's checks govern JetTime. Work logs in JetTime are ordinary Jira work logs, so someone holding Jira's work log permissions can still change them from Jira's own screens or its REST API, bypassing JetTime's controls. That is expected, not a limitation or a bug — it is how Jira handles work log data within its platform. Jira's own permission schemes stay the place to lock the underlying data down, so configure Jira's built-in permissions for work log management correctly, and consult your Jira administrator if you need help.

Setting JetTime as your Jira time tracking provider is what puts JetTime's form, and the rules behind it, on Jira's work log surfaces — so time logged from a work item goes through JetTime rather than around it. See Setting JetTime as Time Tracking Provider in Jira.

Additional Resources

To learn more about Atlassian's security standards and certifications, refer to the official Atlassian Trust Center.

JetTime combines privacy, security, and compliance to provide a seamless and reliable time-tracking experience, ensuring all your app data, work logs, and metadata remain protected within Atlassian's environment.

On this page