Hill Chart for Jira (Shape Up Board)
Privacy Policy
Effective Date: August 31, 2022
Last Updated: December 1, 2025
1. Introduction
Curious Lab Group (a trading name of Gani Software Pty Ltd) ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information when you use Hill Chart for Jira (Shape Up Board) ("the App"), our Jira application available through the Atlassian Marketplace.
By installing and using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, please do not use the App.
2. Information We Collect
2.1 Jira Data
The App interacts with your Jira instance to provide its functionality. The App accesses the following types of Jira data:
Issue Information: Issue summaries, descriptions, issue types, and statuses for Epics, Stories, and Subtasks
User Information: Account IDs, display names, and avatar URLs (to show assignees and track who positioned items on hill charts)
Issue Hierarchy: Parent-child relationships between Epics, Stories, and Subtasks
Project Information: Project IDs and project names
Status and Transitions: Issue statuses and available workflow transitions
2.2 App-Specific Data
To provide the App's hill chart visualization and Shape Up methodology features, the App stores certain configuration data:
Hill Chart Data:
Hill chart snapshots (positions of Stories and Subtasks on the hill chart at specific timestamps)
Issue keys associated with hill charts
Creation timestamps for hill chart snapshots
Rankings Data:
Relative positioning and order of Epics, Stories, and Subtasks within the App's interface
References to issue keys for maintaining sort order
Note: The App does not store:
Your personal user preferences or settings
Individual user activity tracking or behavior analytics
Complete copies of Jira issues
For information about where this data is stored, see Section 4.1 (Data Residency).
2.3 Personal Information
We may collect personal information when you:
Contact our support team (name, email address, support inquiries)
Provide feedback or feature requests
Participate in surveys or promotional activities
2.4 Usage Data and Analytics
Our Standards: The App is designed to meet very strict privacy standards:
Minimize use of Personal Information: The only user data handled by the App is username (display name) and avatar URLs, which are used to let you conveniently assign people to Stories and Subtasks and display them within the App
Keep all data on Atlassian's system: All data handled by the App remains within Atlassian's Forge platform and network, without sending any data to external services
No 3rd party analytics: The App does not use any third-party analytics solutions
Note: We do not collect:
Individual user activity tracking
User behavior analytics
Browser fingerprinting
Device identifiers
3. How We Use Your Information
We use the collected information solely to:
3.1 Provide and Maintain the App
Display hill chart visualizations showing progress of work items
Track positions of Stories and Subtasks on hill charts
Show assignee information (display names and avatars) for work items
Enable sorting and ranking of Epics and Stories
Provide historical snapshots
3.2 Improve the App
Analyze usage patterns to enhance features and user experience
Identify and fix bugs and technical issues
Develop new features based on user needs
3.3 Provide Customer Support
Respond to your support requests and inquiries
Troubleshoot technical problems
Send important updates about the App
3.4 Security and Compliance
Detect, prevent, and address security threats
Ensure compliance with our Terms of Service
Protect the rights and safety of our users
3.5 Legal Obligations
Comply with applicable laws and regulations
Respond to legal requests and prevent fraud
4. Data Storage
4.1 Data Residency
The App stores app-specific data using Atlassian's Forge persistent hosted storage. This means:
Automatic Data Residency: When your Jira administrator pins your Jira instance to a specific geographic location, the App's data is automatically pinned to the same location. If your administrator migrates your Jira data to a different location, the App's data will be migrated along with it.
For more information:
5. Data Sharing and Disclosure
5.1 No Sale of Data
We do not sell, trade, rent, or otherwise monetize your personal data or Jira data.
5.2 Third-Party Service Providers
We share limited data with trusted third-party service providers who assist us in operating the App:
Atlassian Cloud Infrastructure: The App is hosted on Atlassian's Forge platform
Support Platform: When you contact support via our service desk, your inquiry is processed through Atlassian's Jira Service Management
All third-party providers are contractually obligated to protect your data and use it only for the purposes we specify.
5.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, or government regulations).
5.4 Atlassian Marketplace
The App is distributed through the Atlassian Marketplace. Your installation and usage of the App are also subject to Atlassian's privacy practices. Please review Atlassian's Privacy Policy for more information.
6. Data Retention
Data retention for the App is managed by Atlassian's Forge platform in accordance with Atlassian's Standard Data Retention and Disposal policy.
6.1 Active Users
Your app-specific data (hill charts, rankings, and analytics) is retained in Forge persistent hosted storage for as long as the App remains installed on your Jira instance.
6.2 App Uninstallation
When you uninstall the App:
Jira Data: The App immediately loses access to your Jira data since it only accesses data in real-time through Atlassian's APIs
App-Specific Data (Hill Charts and Rankings): Forge-hosted data follows Atlassian's data retention policy. After uninstallation, data is "soft deleted" and retained for a period. If you reinstall the App within 21 days of uninstallation, your data can be relinked to the new installation.
6.3 Learn More
For detailed information about how Forge manages data lifecycle and retention:
7. Your Rights and Choices
Under applicable data protection laws (including GDPR, CCPA, and Australian Privacy Principles), you have rights regarding the personal data the App stores.
7.1 What Personal Data We Store
The App stores the following personal data in Forge persistent hosted storage:
Account IDs: Jira user account identifiers (for users who are assigned to Subtasks and Stories)
Display Names: User display names retrieved from Jira for display purposes
Avatar URLs: References to user avatar images for display in the application
This data is stored to:
Display assignee information in the hill chart interface
Show user-friendly names and avatars in the application
Enable proper user assignment for work items
7.2 Right to Access
You have the right to request a copy of the personal data we hold about you. We will provide:
Hill charts and rankings where your user information appears
Cached user information associated with your account
Historical snapshots of hill charts where you were an assignee
7.3 Right to Rectification
If your display name or avatar has changed in Jira, the App will retrieve the updated information automatically from Jira when accessed. You can also request manual verification by contacting us.
7.4 Right to Erasure ("Right to be Forgotten")
You have the right to request deletion of your personal data. However, please note:
Limitations: Because the App uses Forge persistent hosted storage, data deletion follows Atlassian's data retention policy.
7.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. We can provide:
A JSON export of hill chart data where your user information appears
7.6 Right to Object
You have the right to object to processing of your personal data.
Important: The App requires account IDs, display names, and avatar URLs to function. These are necessary to:
Display assignee information in the application
Track which users are responsible for which work items
Show user avatars in the hill chart interface
If you object to the collection and processing of this personal data, you will not be able to use the App's assignee features. In such cases, you should consider uninstalling the app from your Jira instance.
We do not use personal data for:
Direct marketing
Profiling or automated decision-making
Third-party advertising
Any purpose beyond the core functionality of the App
7.7 Exercising Your Rights
To exercise any of these rights, please contact us at:
Email: [email protected]
Subject: Privacy Rights Request - Shape Up Board
Please include:
Your Jira site URL
Your Jira account ID or email address
The specific right you wish to exercise
Any relevant details to help us process your request
Response Time: We will respond to your request within 30 days in accordance with applicable data protection laws. For complex requests, we may require up to 60 days and will notify you of any extension.
7.8 Complaint to Supervisory Authority
If you are located in the European Economic Area and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
8. Third-Party Links and Services
The App may contain links to third-party websites, services, or resources. This Privacy Policy applies only to the App. We are not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third-party sites you visit.
9. Compliance and Certifications
We are committed to maintaining the highest standards of data protection and privacy:
GDPR Compliance: We comply with the EU General Data Protection Regulation
Australian Privacy Principles: We adhere to the Privacy Act 1988 (Cth)
Atlassian Marketplace Requirements: We meet all Atlassian data privacy guidelines
Security Standards: Our infrastructure providers are SOC 2 Type II certified
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Email: [email protected]
Response Time
We aim to respond to all privacy-related inquiries within 5 business days.
11. Data Protection Officer
For GDPR-related inquiries, you may contact our Data Protection Officer at:
Email: [email protected]
Subject: Attention: Data Protection Officer
Last Updated: December 1, 2025