License Waste Manager for Jira — Privacy policy
What this app stores inside your Atlassian tenant, what it only reads in memory, who it shares data with, and how everything is deleted.
Last updated: 28 August 2026 · App: License Waste Manager for Jira · Vendor: SynapseOasis
This policy explains what data License Waste Manager for Jira collects, how it is processed and stored, and the choices available to you. License Waste Manager for Jira identifies inactive and unnecessarily licensed users across your Atlassian products, visualises licence utilisation, automates deprovisioning through scheduled rules, and records every action in a compliance-ready audit log.
License Waste Manager for Jira is built on Atlassian Forge. It runs inside Atlassian's infrastructure and stores its data in your own Atlassian tenant. It calls no external service other than the Atlassian APIs of your own site.
1. Data we collect
The data falls into two categories: configuration and results held in app storage, and Atlassian data that is read and processed in memory but not retained.
App storage (persisted inside your Atlassian tenant)
- User snapshots — for each account in scope: Atlassian account ID, display name, email address and email domain, active flag, account type, managed status, whether the account consumes a billable licence, last active date, the date the account was added to the organisation, product and product-access details, licence groups and avatar URL.
- Group records — group IDs, names and kinds, and which accounts belong to which group in a snapshot.
- Automation rules — the deprovisioning rules you define (criteria, action, schedule) and their run state.
- Jobs — scan and action jobs with type, status, phase, who requested them, timings, metrics and error messages.
- Audit log — every action the app performed: what was done, by which rule or administrator, when, and the per-user outcome (account ID, display name, success or failure, error message).
- Configuration — the inactivity threshold, protected users, groups and domains, detected licence groups, and the organisation ID and organisation API key you supply. The key is masked in the interface.
Transient data (read and processed in memory, not retained)
- user, group and product access data read from the Atlassian user management and admin APIs of your own organisation
- activity data used to decide whether an account is inactive
Transient data is read through the standard Atlassian REST APIs, used to produce the result you asked for, and then discarded.
2. Personal data
- This app is about user accounts, so it necessarily processes personal data: account IDs, display names, email addresses, avatar URLs, group membership, product access and last activity dates are stored in the snapshots and in the audit log.
- That data is stored only inside your own Atlassian tenant and is used exclusively to show licence utilisation, evaluate your rules and provide an audit trail of the actions taken.
- The organisation API key is a credential you provide. It grants organisation-admin level access, is stored inside your own tenant, is masked in the interface, and can be removed at any time with Disconnect.
- Snapshots are replaced by newer scans and can be deleted from the app. Audit records — the entry and its per-user detail together — are kept for 180 days and then deleted automatically, so a record is either fully answerable or gone; you can also delete them yourself, and uninstalling erases them.
- Once a day the app sends Atlassian the account IDs it holds, through Atlassian's Personal Data Reporting API, and Atlassian answers with the accounts that have been closed. Nothing else tells an app that a person left. A closed account's snapshot rows — the account, its group memberships and its product access — and its per-user audit detail are deleted. The audit entry itself survives without them: what ran, when, by which rule and how many accounts it affected, which is what the trail is for.
- The app does not collect passwords or payment data.
3. Storage and retention
All persisted data is stored in Forge app storage (key-value store) and Forge SQL, both hosted by Atlassian, provisioned for your installation and located in the Atlassian cloud region of your site. SynapseOasis operates no servers, no databases and no logs outside Atlassian, and has no standing access to your data.
Configuration is retained for the life of the installation. Job data and results are retained until you delete or reset them, until they are replaced by a newer run, or until the app is uninstalled.
4. Data sharing
- SynapseOasis does not share your data with third parties.
- There is no sale or transfer of data to third parties.
- There are no analytics, tracking or telemetry calls to external services.
- The only outbound calls the app makes are to
api.atlassian.com— the Atlassian REST APIs of your own site and the Atlassian organisation admin API. - All data stays within Atlassian.
5. Security
The app runs inside the Atlassian Forge sandbox and is subject to Atlassian's platform security controls. It requests only the scopes it needs:
read:jira-userread:jira-workstorage:appreport:personal-data
Where the app acts on behalf of a user, Atlassian's permission model applies, so it cannot show a user data they could not already see. Administrative functions are restricted to users holding the corresponding Atlassian administration permission. All stored input is validated and size-capped before it is written.
6. Data deletion and retention
Deletion is controlled by the Atlassian platform, not by SynapseOasis. This section describes what actually happens, because the difference matters for a data protection assessment.
- While the app is installed, you can delete data through the app's own screens, and that deletion is immediate.
- When you uninstall the app, it runs an uninstall handler that clears its storage. Independently of that, Atlassian detaches the installation's data: it becomes inaccessible to the app, to your users and to us, right away.
- After uninstalling, Atlassian keeps the detached data for a limited period before destroying it, under Atlassian's own data retention policy. Atlassian's Forge documentation describes the storage as soft deleted on uninstall and retained for 28 days, and separately notes that a re-link request must reach Atlassian within 21 days for previous data to be restored to a new installation. That restore only happens if you ask us to raise the request, with your consent. We never initiate it.
- Atlassian's backups follow Atlassian's own schedule and are outside any app's control.
The practical consequences: we cannot delete this data faster than Atlassian's process allows, and we cannot read it after an uninstall. If you need specific data gone on a specific date, delete it inside the app before you uninstall.
Atlassian documents this in Data lifecycle for Forge-hosted storage. The retention periods are Atlassian's to change, so treat Atlassian's documentation as the current source rather than this page.
7. GDPR
- Data minimisation — only the configuration and results needed for the app's function are stored; everything else is processed in memory and discarded.
- Purpose limitation — data is used solely to provide the app's functionality inside your tenant, and is never sold or transferred to third parties.
- Data residency — all persisted data remains in your Atlassian tenant on Forge infrastructure, in the Atlassian cloud region of your site.
- Right to erasure — data can be deleted through the app while it is installed. On uninstall it is detached immediately and then destroyed by Atlassian under Atlassian’s retention policy, as described in the section above.
- Sub-processors — SynapseOasis uses no sub-processors for app data. Atlassian is the infrastructure provider and processes the data under your existing agreement with Atlassian.
8. Contact
- Email: contact@synapseoasis.com
- Support portal: Customer support portal
9. Changes to this policy
We may update this policy from time to time. When we do, we revise the last-updated date at the top of this page. We encourage you to review it periodically to stay informed about how License Waste Manager for Jira handles your data.