Toolbox4Jira Privacy Policy

29 Aug 2026

Effective date: August 30, 2026

This Privacy Policy explains how information is handled when you use Toolbox4Jira, including its browser extension, website, and configuration service (the “Service”).

1. Who Is Responsible

Toolbox4Jira is maintained by independent maintainers and is not offered by a company. The independent maintainers are responsible for the processing described in this Policy.

For privacy questions or requests, contact paddelkraft+tb4j@gmail.com.

2. Information Processed

Configuration requests

The extension creates SHA-256 hashes of the Jira instance origin and Jira username and sends those hashes to the self-hosted configuration server. They are used as lookup keys for static configuration files. The original Jira origin and username are not sent to that server.

These hashes are pseudonymous identifiers. Hashing reduces identifiability but does not guarantee anonymity because the same input produces the same hash and may be matched against known values.

HTTP request logs

The configuration server logs HTTP requests. Those logs may contain an IP address, request timestamp, requested path (including the hashed lookup identifiers), and browser user-agent string.

Usage analytics

The extension uses Google Analytics to understand feature usage and improve the Service. Analytics events may include:

Google Analytics does not receive Jira credentials or Jira issue content from Toolbox4Jira. Google processes analytics information under its Privacy Policy.

Jira credentials and content

If Jira credentials are required for Atlassian API access, they can be stored in browser extension storage on your device. Base64 encoding is used to obfuscate those credentials; Base64 is not encryption. Credentials are sent only from your browser to your Jira instance and are never sent to the Toolbox4Jira configuration server or Google Analytics.

Jira issue details, comments, attachments, project data, and other Jira content are processed in your browser and are not sent to the Toolbox4Jira configuration server or Google Analytics.

3. Why Information Is Processed

Information is processed to:

The maintainers rely on legitimate interests in operating, securing, diagnosing, and improving the free Service, balanced against the limited and pseudonymous nature of the information processed. Where applicable law requires consent for analytics, analytics will be subject to that requirement.

4. Sharing and Third Parties

The maintainers do not sell personal information. Information is disclosed only as described here:

Toolbox4Jira does not use cookies for advertising. Google Analytics data handling is governed by Google’s own policies.

5. Storage and Retention

The maintainers do not retain Jira issue content.

6. Security

Reasonable technical and organizational safeguards are used to protect information handled by the Service. These include limiting configuration requests to pseudonymous lookup identifiers and keeping Jira credentials and Jira content out of the configuration server. No method of storage or transmission can be guaranteed completely secure.

7. International Processing

Google may process analytics information outside the European Economic Area. Google’s applicable safeguards and privacy policies govern that processing.

8. Your Rights

Where applicable under the GDPR or other data-protection law, you may have rights to:

Because some information is pseudonymous, a request may require enough information to locate and verify the relevant data. The maintainers will not request more identifying information than reasonably necessary for that purpose.

To exercise a right, contact paddelkraft+tb4j@gmail.com. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority.

9. Changes to This Policy

This Policy may be updated when the Service or its data handling changes. The effective date at the top identifies the latest revision. Please review this page periodically.