Privacy Policy

Last updated: 2026-09-25

In short: ArtUp Trace runs entirely on Atlassian's infrastructure. Its data is stored by Atlassian in your Jira site's data residency region, ArtUp Labs operates no servers that receive it, and the app sends nothing to third parties. This website uses no cookies and no analytics.

1. Who we are

ArtUp Labs is the trade name of Artyom Karpets, an individual entrepreneur (sole proprietor) registered in the Republic of Kazakhstan ("ArtUp Labs", "we", "us").

2. Scope

This policy covers:

Your use of Jira Cloud itself is governed by Atlassian's own privacy policy and terms. This policy does not cover Atlassian's processing.

3. Controller and processor roles

For data the App processes within your Jira site, the customer (the organisation that installed the App) is the data controller, and ArtUp Labs acts as a processor on the customer's behalf. The App processes this data only to provide its features, on Atlassian's infrastructure.

For email correspondence you send us (for example, a support request), ArtUp Labs is the controller of that correspondence.

4. What data ArtUp Trace processes

4.1 Data the App reads from Jira

The App reads Jira data as the current user, so it can only see what that user is already permitted to see. It reads issues, issue links, statuses and basic user information needed to display them. The App never writes to Jira issues.

The App requests only these Atlassian scopes:

4.2 Data the App stores

The App stores the following in Forge SQL and Forge storage:

Data stored by ArtUp Trace
CategoryContents
Project settingsWhich issue types and link types count as requirements and verification.
Requirement recordsIssue id, issue key, summary, status, and a fingerprint hash of the summary and description (used to detect changes).
Link recordsLink type, the other issue's key and status, confirmation timestamp, and the Atlassian account id of the user who confirmed the link.
BaselinesFrozen snapshots of the requirement and link records above.
Sync job metadataTechnical information about background synchronisation jobs (for example, progress and timing).

The App does not store names or email addresses. It stores Atlassian account ids only to record who confirmed a link. It does not store passwords, access tokens or payment data. The full description text of issues is not stored; only a hash of it is.

4.3 CSV export

When a user exports to CSV, the file is generated and downloaded directly to that user's device. ArtUp Labs does not receive a copy.

4.4 Logs

The Atlassian Forge platform keeps logs of errors raised by the App. By design, the App does not log issue content; logs contain error messages only. ArtUp Labs can view these logs in the Atlassian developer console to diagnose problems.

5. Why we process it

Data is processed only to provide the App's features: showing coverage of requirements, detecting suspect links, creating and comparing baselines, producing exports, and diagnosing errors. We do not use App data for advertising, profiling, selling, or training machine-learning models.

Where the GDPR applies, the customer as controller determines the legal basis for processing its Jira data. Our processing of App data is on the customer's instructions, as expressed by installing and using the App. Our processing of support correspondence is based on our legitimate interest in answering your request.

6. Where the data is stored

ArtUp Trace is an Atlassian Forge app with the "Runs on Atlassian" designation. It has no external servers and makes no outbound network calls (no egress). All stored data remains in Forge SQL and Forge storage on Atlassian's infrastructure, in the customer's data residency region as handled by Atlassian. ArtUp Labs does not copy App data to its own systems.

7. Retention and deletion

8. Sub-processors

Sub-processors for App data
Sub-processorPurposeLocation
AtlassianHosting and running the App (Forge), storage (Forge SQL and Forge storage), platform logs, Marketplace licensing and billingCustomer's data residency region as handled by Atlassian

We use no other sub-processors for App data. We will update this list before adding one.

9. This website

The Website is a set of static pages. It sets no cookies, uses no analytics, and loads no third-party scripts, fonts or trackers. Pages are served through Cloudflare, which as our hosting and DNS provider may process technical request data (such as IP addresses) to deliver and protect the site.

10. When you email us

If you email hello@artuplabs.com or security@artuplabs.com, we receive your email address, name (if included) and whatever you choose to send, such as screenshots. Please do not send more Jira content than needed. We use this only to answer you. Email is handled by our email provider, Zoho Mail (Zoho Corporation).

11. Payments

Purchases, licensing and payments are handled by Atlassian through the Atlassian Marketplace. ArtUp Labs does not receive or store payment card data. Atlassian may share with us licence and billing contact information for the purposes described in Atlassian's Marketplace terms.

12. Security

See our Security page for the App's architecture, access scopes, and how we handle vulnerabilities and incidents.

13. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability, and to complain to a data protection authority.

14. Children

The App and Website are business tools and are not directed at children.

15. Changes to this policy

We may update this policy, for example when the App gains new features or we add a sub-processor. We will change the "Last updated" date above and, for material changes, notify customers through the Marketplace listing or by email to the technical contact before the change takes effect.

16. Contact

ArtUp Labs (Artyom Karpets, individual entrepreneur), Protozanov Street 119, apt. 33, Ust-Kamenogorsk (Oskemen), East Kazakhstan Region, Republic of Kazakhstan
Email: hello@artuplabs.com