Privacy Policy

Last updated: September 2026

Release scope: These details describe the current major-4 release of Sprint Scope Guard, available on Atlassian Marketplace. Existing customers should check their installed version and approve any required major update. Earlier versions supported webhook tests and different logging; the current release removes external backend destinations and webhook support. See the administrator guide for installation and upgrade instructions.

Sprint Scope Guard

Sprint Scope Guard is a Jira Cloud Forge app. It reads Jira sprint, issue, and changelog data for the current-sprint scope audit and uses Forge-hosted storage for application state.

  • Forge-hosted storage: Forge KVS stores app settings and minimal governance data. Removed-item audit entries contain only the Jira issue key, action reason, and action date; approval and swap bookkeeping retains issue keys and timestamps without descriptive issue fields. Jira summary, priority, status, and story points are fetched from Jira as the current user reads the record; inaccessible or deleted issues are omitted. Jira remains the source of truth, and no external Neural Void database stores these records. Older records written by previous releases may remain in Forge storage, but their legacy descriptive fields are normalized away before use and are never returned. The settings migration in the current major-4 release never returns or uses a legacy webhook URL, and attempts to delete the old secret after an authorized administrator loads or saves project settings; failed best-effort cleanup is retried on a later administrator access. See Atlassian's Forge storage reference.
  • Exports and operations: CSV, JSON, and Markdown exports are generated in the browser and remain local to the user. The current major-4 release has no external backend destination or usage analytics. Minimal failure diagnostics remain in Atlassian Forge logs. Forge operational logs, metrics, and alerts are Atlassian-managed platform services and may include platform site, version, and invocation metadata, governed by customer log-sharing settings.
  • Retention and residency: After uninstallation, Forge-hosted data is retained for up to 28 days. A new installation can be linked to the old data only when recovery is requested within 21 days; a reinstall does not automatically restore it. Forge documents hosted-storage residency behavior in its data-residency documentation.
  • Operational logs: Our application messages contain only an allowlisted operation and code, a release label, a random per-request UUID, and duration. They do not contain Jira content, user data, site data, webhook data, or hashes. Forge also adds platform metadata such as installation site, app version, environment, and invocation identifiers, so logs are not anonymous. Developer access depends on the customer's log-sharing settings and the applicable Atlassian cloud offering. Forge app logs are available for 30 days; see Forge app logs and logging guidelines. No external telemetry vendor, session replay, or Forge frontend-log EAP is configured.
  • Use of customer data: We do not sell customer data or use it for advertising.

Neural Void Website

This website (neural-void.com) is served through Cloudflare Pages and loads fonts from Google Fonts. Those providers may process request data under their own terms and policies.

Cloudflare Hosting

See Cloudflare's Privacy Policy and Google's Privacy Policy for their respective handling of website requests.

Contact Inquiries

If you contact us via email (hello@neural-void.com), we receive your email address and message content. We use this to respond to your inquiry and investigate the reported issue. Contact inquiry emails are kept only as long as needed to handle the request and any follow-up questions and are then deleted, unless a legal retention obligation applies. Start with the error code, approximate time, and reproduction steps. Do not send passwords, API tokens, webhook URLs, or unrelated Jira content; redact screenshots before sharing them.

Privacy and security contact

For privacy questions contact hello@neural-void.com; report suspected security issues to security@neural-void.com.

Controller

The controller is Vladimir Evseev, operating as Neural Void, Germany. Contact for privacy requests: hello@neural-void.com.

Legal bases

Contact inquiries and support: Art. 6(1)(b) GDPR where needed to answer a request about a contract or pre-contractual steps, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering inquiries). Website delivery through Cloudflare Pages and font delivery through Google Fonts: Art. 6(1)(f) GDPR (secure and efficient delivery of the website).

Your rights

You may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and may object (Art. 21); write to the privacy contact above. You may complain to a supervisory authority (Art. 77 GDPR), for example the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.