Toolbox4Jira Privacy Policy
29 Aug 2026
Effective date: August 30, 2026
This Privacy Policy explains how information is handled when you use Toolbox4Jira, including its browser extension, website, and configuration service (the “Service”).
1. Who Is Responsible
Toolbox4Jira is maintained by independent maintainers and is not offered by a company. The independent maintainers are responsible for the processing described in this Policy.
For privacy questions or requests, contact paddelkraft+tb4j@gmail.com.
2. Information Processed
Configuration requests
The extension creates SHA-256 hashes of the Jira instance origin and Jira username and sends those hashes to the self-hosted configuration server. They are used as lookup keys for static configuration files. The original Jira origin and username are not sent to that server.
These hashes are pseudonymous identifiers. Hashing reduces identifiability but does not guarantee anonymity because the same input produces the same hash and may be matched against known values.
HTTP request logs
The configuration server logs HTTP requests. Those logs may contain an IP address, request timestamp, requested path (including the hashed lookup identifiers), and browser user-agent string.
Usage analytics
The extension uses Google Analytics to understand feature usage and improve the Service. Analytics events may include:
- Page title and page location
- Selected view, perspective, and feature interactions
- A session identifier
- A SHA-256 hash of the Jira user email or username
- The Jira instance hostname, which may identify an organization
- Extension environment and version-related information
Google Analytics does not receive Jira credentials or Jira issue content from Toolbox4Jira. Google processes analytics information under its Privacy Policy.
Jira credentials and content
If Jira credentials are required for Atlassian API access, they can be stored in browser extension storage on your device. Base64 encoding is used to obfuscate those credentials; Base64 is not encryption. Credentials are sent only from your browser to your Jira instance and are never sent to the Toolbox4Jira configuration server or Google Analytics.
Jira issue details, comments, attachments, project data, and other Jira content are processed in your browser and are not sent to the Toolbox4Jira configuration server or Google Analytics.
3. Why Information Is Processed
Information is processed to:
- Select and provide the appropriate static configuration
- Operate, secure, monitor, and diagnose the configuration server
- Understand how features are used
- Maintain and improve the Service
- Meet applicable legal obligations
The maintainers rely on legitimate interests in operating, securing, diagnosing, and improving the free Service, balanced against the limited and pseudonymous nature of the information processed. Where applicable law requires consent for analytics, analytics will be subject to that requirement.
4. Sharing and Third Parties
The maintainers do not sell personal information. Information is disclosed only as described here:
- The self-hosted configuration server processes configuration lookup requests and HTTP request logs.
- Google Analytics processes the usage analytics described above.
- Information may be disclosed when required by applicable law.
Toolbox4Jira does not use cookies for advertising. Google Analytics data handling is governed by Google’s own policies.
5. Storage and Retention
- Configuration-server logs are retained only for as long as reasonably necessary for operation, security, and diagnostics.
- Jira credentials remain in browser extension storage until you remove them, clear the extension’s data, or uninstall the extension.
- Google controls the retention of information it receives through Google Analytics under its own settings and policies.
The maintainers do not retain Jira issue content.
6. Security
Reasonable technical and organizational safeguards are used to protect information handled by the Service. These include limiting configuration requests to pseudonymous lookup identifiers and keeping Jira credentials and Jira content out of the configuration server. No method of storage or transmission can be guaranteed completely secure.
7. International Processing
Google may process analytics information outside the European Economic Area. Google’s applicable safeguards and privacy policies govern that processing.
8. Your Rights
Where applicable under the GDPR or other data-protection law, you may have rights to:
- Access personal information about you
- Correct inaccurate information
- Request deletion or restriction of processing
- Object to processing
- Receive portable information where applicable
- Withdraw consent where processing relies on consent
Because some information is pseudonymous, a request may require enough information to locate and verify the relevant data. The maintainers will not request more identifying information than reasonably necessary for that purpose.
To exercise a right, contact paddelkraft+tb4j@gmail.com. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.
9. Changes to This Policy
This Policy may be updated when the Service or its data handling changes. The effective date at the top identifies the latest revision. Please review this page periodically.