Privacy Policy — TriageLight (Semáforo por prioridad)
Last updated: 2026-08-06
Placeholders in [brackets] must be filled in before publishing. Suggested values in italics.
1. Who we are
This app ("TriageLight", the "App") is provided by Heero S.A. ("we", "us"), located in Argentina. Contact: hola@heero.la.
The App is a Runs on Atlassian Forge application. It runs entirely on Atlassian's cloud infrastructure and adds a custom queue view to Jira Service Management that colors ticket rows by priority and offers inline triage actions.
2. Scope
This policy explains what data the App accesses, what it stores, and how it is handled. It covers the App only — not Atlassian's own products, which are governed by Atlassian's privacy policy.
3. Data the App accesses (but does NOT store)
To render the queue and perform the actions you request, the App reads the following data transiently, at the moment you view or act on the queue, using your own Atlassian permissions:
- Jira issue fields returned by the queue's JQL search: key, summary, status, priority, assignee, reporter, created date.
- The current user's identity (account ID and display name) — used to power the "assign to me" action and "my tickets" filter.
- Where configured by a project admin: the value of a Jira Assets (CMDB) object field used to display a "Client" name, and a Service Management SLA field ("Time to resolution") used to display SLA status.
- Available Jira fields and issue types (for the configuration panel), and the project's priority scheme (to color rows).
This data is fetched on demand and rendered in your browser. It is not persisted by the App and is never transmitted outside your Atlassian environment.
4. Data the App stores
The App stores only per-project configuration in Atlassian Forge storage (storage:app), which resides inside your own Atlassian cloud environment:
- The custom field IDs a project admin maps for "Client" and "SLA".
- Issue types to exclude from the queue.
- Optional priority color overrides.
This configuration contains no personal data and no ticket content. It persists until an admin changes it and is removed when the App is uninstalled.
5. Where data is processed
The App is a Runs on Atlassian app: all execution (backend functions and stored configuration) happens within Atlassian's cloud infrastructure. The App makes no calls to any external or third-party service, uses no third-party sub-processors, and performs no data egress. Data residency therefore follows your Atlassian instance.
6. Actions the App performs on your behalf
When you use the inline controls, the App writes to Jira as you (using your own permissions): change an issue's priority, transition its status, or assign it to yourself. The App never acts autonomously and never uses stored credentials — it holds none.
7. Security
The App relies on the Atlassian Forge platform security model. It uses no passwords, API keys, or shared secrets; it does not use Basic authentication; and it opens no external network connections. All access is scoped to the following granted permissions: read:jira-work, read:jira-user, write:jira-work, read:servicedesk-request, read:cmdb-object:jira, storage:app.
8. Data retention and deletion
The App retains only the per-project configuration described in Section 4, for as long as the App is installed. Uninstalling the App removes its stored configuration. No backups of your data are kept by us.
9. Children's privacy
The App is a workplace tool and is not directed at children.
10. Changes to this policy
We may update this policy; the "Last updated" date reflects the latest version. Material changes will be reflected on the app's listing.
11. Contact
Questions about this policy or your data: hola@heero.la.