Privacy Policy

End User Privacy Policy · Version 1.0 · June 1, 2026

This End User Privacy Policy (Privacy Policy) applies to Strategy Hub: OKRs, Goals, KPIs & Strategy Planning for Jira (Strategy Hub or App), an Atlassian Forge application provided by caskcode (caskcode, we, us, or our) and available on the Atlassian Marketplace.

This Privacy Policy describes which personal data Strategy Hub collects, how we store, process, and use it, and what happens when you use the App.

Important – Runs on Atlassian architecture. Strategy Hub is built entirely on Atlassian’s Forge infrastructure (Runs on Atlassian). All application logic runs within Atlassian’s secure runtime environment, and all data is stored in Atlassian-managed Forge Storage. Caskcode does not operate any external servers or databases and has no direct access to your data or the data of your Jira instance.

1. About us#

Strategy Hub is provided by caskcode, the trading name of Bartosz Wyszkowski, a sole trader (jednoosobowa działalność gospodarcza) established in Poland (NIP: 7732489961, REGON: 383238029). In this Privacy Policy, “caskcode”, “we”, “us”, and “our” refer to this business.

Our role under data protection law. We are the controller for the limited personal data we collect to operate, support, and improve the App — technical and usage data (section 3.3), feedback you submit (section 3.5), and commercial and licensing data (section 3.6) — meaning we determine the purposes and means of that processing. For the strategic content you create within the App (objectives, key results, KPIs, comments, and related configuration — section 3.4), the customer organisation that installed Strategy Hub is the controller and we act as a processor on its behalf, with Atlassian providing the underlying Forge infrastructure as a sub-processor. Where required, that processing is governed by a Data Processing Agreement between us and the customer. A Data Processing Agreement is available to customers on request at contact@caskcode.io.

2. About you#

When you install and use Strategy Hub, you become our end user (End User).

We categorise End Users so you can easily find the details relevant to your personal data. Please note that you may fall into more than one category depending on how you use the App.

Type of End UserDescription
End UserAny person who installs and uses the App.
Strategy Hub End UserEnd User who creates and manages OKRs, KPIs, Goals, or other strategic items within the App.
Feedback providerEnd User who submits feedback, a support request, or an enquiry via our JSM customer portal.

Please note! We do not knowingly process the personal data of End Users under the age of 16. If you are such an End User, or are a legal representative of such an End User, please contact us using the details in section 1.

3. Personal data#

3.1 Sources of data#

We receive data when you install the App and interact with it, depending on your actions and your Jira instance configuration.

Because Strategy Hub operates on the Runs on Atlassian (Forge) architecture, the data we receive is limited to what Atlassian’s platform exposes to Forge apps. Caskcode does not have direct access to your Jira instance data beyond what is explicitly passed to the App through Atlassian’s Forge APIs.

You may update your personal data through the App’s functionality or by exercising your right to rectification. The same lawful bases and storage terms apply to updated data.

We may also receive data from third parties, as described in section 3.6.

3.2 Lawful bases for processing#

To process your personal data, we rely on the following lawful bases:

  • Performance of the contract — for processing personal data necessary for negotiating, concluding, and performing a contract (primarily, the End Users Terms) with you.
  • Legitimate interest — for processing necessary for the development of our services, taking into account your interests, rights, and expectations.
  • Legal obligation — for processing required by applicable law (for example, to comply with tax regulations) or when requested by a law enforcement agency, court, supervisory authority, or other state-authorised public body.

3.3 Technical End Users data#

We collect limited technical data about End Users to optimise performance, debug issues, and improve the overall user experience. Because the App runs on Atlassian’s Forge infrastructure, most technical data is handled within Atlassian’s environment.

We process the following personal technical data for performance optimisation, debugging, feature improvement, and App analytics, on the basis of our legitimate interest:

  • Coarse location (country derived from IP address)
  • Identifiers (Atlassian user ID) — shared with our analytics and error-monitoring processors (see section 4)
  • Subscription and licence details
  • Usage data (App install and usage dates)
  • Technical information (default settings, HTTP user agent)

Data storage: We store this data for 3 years from its collection.

3.4 Strategy Hub End Users data#

We process certain data when you create and manage strategic items (OKRs, KPIs, Goals, and related content) within Strategy Hub.

Note on data residency: Data created within the App (objectives, key results, KPIs, comments, and related configuration) is stored exclusively in Atlassian Forge Storage and is not accessible to Caskcode.

We process the following data to provide you with the App’s core functionality, on the basis of performance of the contract:

  • Strategic item data (names, descriptions, types, hierarchy)
  • Progress and status values
  • Period and date configurations
  • Team and ownership assignments
  • Comments and activity history
  • Linked Jira work items
  • Labels and custom settings

Data storage: Data is stored until you delete the strategic item or uninstall the App.

3.5 Feedback providers data#

We collect certain data when you voluntarily submit feedback, a support request, or any other enquiry about the App. Feedback is collected via our Jira Service Management (JSM) customer portal. When you submit a request through the portal, we receive and process the data you provide.

We process the following data to respond to your feedback, support request, or enquiry, and to use aggregated feedback for product improvement, on the basis of our legitimate interest:

  • Email address of the submitter
  • Text of the feedback, request, or message
  • Any additional data you voluntarily provide in the submission

Data storage: We store this data for 6 years from the date of submission or from the last communication regarding it.

3.6 Data received from third parties#

We may receive limited personal data from third parties. The scope, purposes, and lawful bases for such processing are governed by the respective privacy documents of those third parties.

Third partyPrivacy documents
Atlassian Marketplacehttps://www.atlassian.com/legal/privacy-policy

We receive data from Atlassian Marketplace to place the App within the platform and provide you with its functionality. We process the following data to provide you with the App’s functionality, on the basis of performance of the contract:

  • Company and representative data
  • Hosting and instance data
  • Number of users in the Jira instance
  • Subscription period (start and end dates)
  • Atlassian licence ID and entitlement number

Data storage: We store this data for the duration of your use of the App.

Where a paid subscription is purchased, Atlassian Marketplace processes payment on our behalf. The data may include payment confirmation, transaction date, purchased subscription details, and billing contacts. We store this data for 6 years from the date you cancel your subscription.

3.7 Cookies and tracking technologies#

Strategy Hub sets no cookies through its own application code. The analytics and error-monitoring tools it uses (PostHog and Sentry — see section 4) store nothing on your device: no cookies, and no data in your browser’s local storage.

The App does use your browser’s local storage, but for strictly necessary, first-party purposes only — remembering your view settings (filters, columns, sorting), preserving your unsaved work, and caching your own preferences. This storage holds no tracking identifiers and no personal data beyond your own settings, is never shared with third parties, and is exempt from consent as strictly necessary storage. Because the App stores no tracking or analytics data on your device, it does not require a cookie consent banner.

Any cookies present in the Atlassian interface are set by Atlassian as part of its platform and are governed by Atlassian’s Privacy Policy.

4. Data sharing with third parties#

We may share your personal data with third parties without harm to you and in full compliance with applicable law. We have implemented organisational and technical measures to ensure the security of personal data during such transfers.

We rely on the following lawful bases for sharing data, depending on the circumstances: consent, compliance with legal obligations, and performance of a contract.

Third partiesDescription
Error monitoring — Sentry (https://sentry.io/privacy/)We use Sentry to capture technical error diagnostics so we can debug and improve the App.
Product analytics — PostHog (https://posthog.com/privacy)We use PostHog to understand aggregate usage patterns and improve the App.
Contractors and service providersWe work with service providers and contractors to operate, develop, and improve the App, fulfil support requests, and manage the Atlassian Marketplace listing.
Internal organisational toolsWe use CRM systems, communication tools, and similar services within our organisation to provide you with our services.
State authorities and law enforcementWe may be required to transfer certain data to tax authorities, courts, law enforcement agencies, or other governmental bodies: to comply with a legal obligation or court order; to prevent unlawful use of the App; to protect against third-party claims; or to help prevent or investigate fraud.

What we send to Sentry and PostHog. We send these tools a limited set of technical identifiers and aggregate metrics: your Atlassian account ID (a pseudonymous identifier), your site (cloud) ID and URL, installation and environment identifiers, licence and usage counts, and a coarse country derived from your IP address (your raw IP address is discarded). Where you voluntarily submit your name and email through the in-App support widget (see section 3.5), we send those so we can respond. We do not send the strategic content you create, the contents of your Jira instance, or any free-text you or your colleagues author — session replays mask all on-screen text, and error diagnostics contain identifiers and technical codes only. Both providers host EEA data within the European Union (see section 6).

To obtain a detailed list of third-party recipients of your personal data, please contact us at contact@caskcode.io.

5. Atlassian Forge data lifecycle and Rovo#

5.1 Forge-hosted storage data lifecycle#

Because all Strategy Hub data is stored exclusively in Atlassian’s Forge-hosted storage, the retention and deletion of that data is governed by Atlassian’s data lifecycle policies — not by caskcode. The key stages are summarised below. For full details, please refer to the Atlassian developer documentation at: https://developer.atlassian.com/platform/forge/storage-reference/hosted-storage-data-lifecycle/

StageWhat happens to your data
App installationAtlassian provisions dedicated Forge storage for the App within your Jira site’s Atlassian app partition. No data exists before installation.
App in active useData is stored within Atlassian’s Forge infrastructure for as long as the App is installed and your Atlassian subscription is active.
App uninstallationData is soft-deleted by Atlassian and retained for a period defined by Atlassian’s internal Standard Data Retention and Disposal policy. Caskcode does not control this retention period.
App reinstallation within 21 daysIf the App is reinstalled within 21 days of uninstallation, the new installation can be relinked to the previous data on request.
App reinstallation after 21 daysReinstallation is treated as a new installation. Previously stored data may no longer be recoverable.
Atlassian subscription cancellationWhen your Jira subscription is cancelled, Atlassian schedules all associated app data for deletion in accordance with its data retention policy.
Site deletionWhen an Atlassian site is permanently deleted, all associated app data is deleted immediately once the soft-delete period has elapsed.

Please note: The retention periods described above are set and controlled by Atlassian. Caskcode is not able to recover data that has been deleted by Atlassian in accordance with its policies. If you require data export before uninstalling the App, please use the Data export functionality within Strategy Hub settings before uninstalling.

5.2 Atlassian Rovo integration#

Strategy Hub may integrate with Atlassian Rovo, Atlassian’s AI-powered assistant platform, to provide AI-enhanced features such as intelligent search, goal suggestions, or conversational interaction with your strategy data.

When the Rovo integration is active, certain data from your Strategy Hub instance — such as objective names, key results, or KPI data — may be accessed by Rovo to generate responses or surfaces within the Atlassian platform. The following applies to such processing:

  • Data accessed by Rovo is processed within Atlassian’s own infrastructure and is subject to Atlassian’s Privacy Policy and AI usage policies.
  • Rovo respects your existing Jira permissions model — it will only surface data to users who already have access to it within Strategy Hub.
  • Rovo may use third-party large language model providers (such as OpenAI, Anthropic, and Google) to generate responses. Atlassian states that these providers do not retain your inputs and outputs or use them to train their models.
  • Atlassian states that Rovo retains inputs and outputs for a limited period (currently 30 days) for safety and security purposes.
  • The specific scope of data accessed depends on how the Rovo integration is configured. We will update this section as the integration is developed and scoped.

Use of Atlassian Rovo is governed by your Atlassian Customer Agreement and Atlassian’s Privacy Policy. For full details of how Rovo processes data, please refer to: https://support.atlassian.com/rovo/docs/rovo-data-privacy-and-usage-guidelines/

6. Data sharing outside the European Economic Area#

Because Strategy Hub runs on the Runs on Atlassian (Forge) architecture, data stored within the App resides in Atlassian’s infrastructure and is subject to Atlassian’s data residency commitments under your Atlassian Customer Agreement.

To the extent that caskcode processes any personal data outside the App (such as support communications or analytics), such data may be stored on servers within the European Union for EEA End Users and in the USA for US End Users.

Where we share personal data with recipients in the USA or other non-EEA countries, we ensure it is protected in accordance with the General Data Protection Regulation. We rely on the adequacy decision of the European Commission or the recipient’s participation in the Data Privacy Framework.

If a recipient does not participate in the Data Privacy Framework and their country is not deemed adequate, we adopt Standard Contractual Clauses, based on appropriate data protection assessments.

7. Data protection#

We apply security measures appropriate to the risks involved in processing your personal data. In addition, because the App runs on Atlassian’s Forge infrastructure, your in-App data benefits from Atlassian’s own enterprise-grade security controls.

Organisational measures

  • Staff training and awareness
  • Internal policies and procedures
  • Non-disclosure agreements (NDA)
  • Access controls and least-privilege principles

Technical measures

  • Two-factor authentication
  • Encrypted data transmission (TLS)
  • Firewalls and network controls
  • Regular backups
  • Atlassian Forge runtime isolation
  • Forge Storage encryption at rest

8. Data subjects rights#

As a data subject, you have the right to interact with your personal data directly or by submitting a request to us. The sections below describe your rights depending on your country of residence.

8.1 European Economic Area and United Kingdom residents#

RightDescription
Right to accessYou may request an explanation of how your personal data is processed.
Right to rectificationYou may request correction of inaccurate or incomplete data.
Right to erasureYou may request deletion of your personal data. We will comply unless retention is required by law.
Right to restrict processingYou may partially or fully restrict our processing of your personal data.
Right to data portabilityYou may request a copy of the data you provided and ask for it to be transferred to another controller.
Right to objectYou may object to the processing of your personal data.
Right to withdraw consentWhere processing is based on consent, you may withdraw it at any time.
Right to file a complaintIf your request is not satisfied, you may file a complaint with the relevant supervisory authority.

To exercise your rights, contact us at contact@caskcode.io.

EEA residents: We will respond to your request within one month. If not satisfied, you may submit a complaint to your local Data Protection Authority. A list is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

UK residents: We will respond within one month. If not satisfied, you may contact the Information Commissioner’s Office at 0303 123 1113 or https://www.ico.org.uk/concerns.

8.2 United States residents#

For the purposes of US state privacy laws such as the CCPA, Caskcode acts as a “business” for the personal data described in this Policy that we process for our own purposes, and as a “service provider” for the strategic content we process on behalf of a customer organisation.

Your privacy rights vary depending on your state of residence, as outlined below.

RightDescriptionStates
Right to accessRequest an explanation of how your personal data is processed.CA; CO; CT; IN; IA; MT; TN; TX; UT; VA
Right to correctRequest correction of inaccurate or incomplete data.CA; CO; CT; IN; MT; TN; TX; VA
Right to deleteRequest deletion of your personal data.CA; CO; CT; IN; IA; MT; TN; TX; UT; VA
Right to portabilityRequest your data and transfer to another controller.CA; CO; CT; IN; IA; MT; TN; TX; UT; VA
Right to opt out of salesOpt out of the sale of personal data to third parties.CA; CO; CT; IN; IA; MT; TN; TX; UT; VA
Right to opt out of profilingOpt out of processing for targeted advertising or profiling.CO; CT; IN; MT; TN; TX; UT; VA
Right against automated decisionsProtection against solely automated decision-making without human input.CA; CO; CT; IN; IA; MT; TN; TX; VA
Private right of actionSeek civil damages for statutory violations.CA

To exercise your rights, contact us at contact@caskcode.io. We will respond within 30 to 60 days depending on your state’s legislative requirements. If your complaint is not resolved, you may contact the Federal Trade Commission at https://www.ftc.gov/about-ftc/contact.

Please note! Some US states do not have comprehensive privacy laws. Residents of such states are governed by applicable federal law. If your state is not listed above, please contact us.

8.3 Do not sell my personal information#

California residents have the right under the California Consumer Privacy Act (CCPA) to opt out of the sale of their personal information.

Caskcode does not sell your personal information to any third party, nor does it use your data as a business model. However, we support the CCPA by allowing California residents to record their preference against any future sale. To do so, please contact us at contact@caskcode.io.

8.4 Do-not-track requests#

California residents using the App may request that we do not automatically gather and track information about their online browsing activities across the Internet.

Such requests are typically made through browser settings that transmit signals or other mechanisms allowing consumers to exercise choice over the collection of personal data across third-party websites and online services over time.

We currently do not have the ability to honour these requests. We will update this Privacy Policy if our capabilities change.

8.5 Canada residents#

Canadian residents have privacy rights under the Personal Information Protection and Electronic Documents Act (PIPEDA), the Personal Information Protection Act of British Columbia, the Personal Information Protection Act of Alberta, and the Act respecting the protection of personal information in the private sector of Quebec.

Under these laws, you have the right to access your personal data, request corrections, and withdraw consent for non-essential processing. To exercise any of these rights, please contact us at contact@caskcode.io. We will respond within 30 days.

9. Privacy Policy updates#

We may update this Privacy Policy from time to time to reflect changes in the App, legal requirements, or our data practices. If changes are material, we will notify you in advance via email or through the App’s Atlassian Marketplace page.

The current version and effective date are shown at the top of this document. Continued use of the App following the effective date of any update constitutes acceptance of the revised Privacy Policy.

For any questions about this Privacy Policy or to exercise your rights, contact us at contact@caskcode.io.


© 2026 Caskcode · All rights reserved · caskcode