TextToJQL.
TextToJQL for Jira

Privacy Policy

Last updated: 5 September 2026

This policy describes how TextToJQL ("the app"), provided by Clipper IT Services Ltd ("we," "us," "our"), handles data when it's installed on your Atlassian Jira Cloud site through the Atlassian Marketplace.

Jump to a section
  1. Data this app processes
  2. What is sent to the AI model
  3. What we don't do
  4. Where data is stored
  5. Your rights
  6. Contact

TextToJQL runs entirely on Atlassian's Forge platform. We don't operate any servers, databases, or infrastructure of our own — everything the app does happens inside Atlassian's cloud, under Atlassian's own security and data-handling commitments to you as their customer.

01 Data this app processes

  • The natural-language text you type (e.g. "overdue tasks assigned to me"), capped at 500 characters. It's sent to Atlassian's own hosted AI model, via Forge's LLM API, to be converted into a JQL query. We don't separately log, store, or retain it — it exists only for the duration of that one request.
  • The JQL query generated. It's checked against your Jira site's own search parser to confirm it's valid, running as you rather than as the app — so the check also reflects your own Jira permissions, not a broader view the app itself might have. Nothing about your issues, projects, or search results is sent anywhere outside your Jira instance.
  • Custom field names. To help the AI recognize your site's custom fields by name, the app caches a mapping of field names to their internal IDs (e.g. "Story Points" → customfield_10016) — names only, never the values on your issues. This refreshes automatically once a day, or on demand if a site admin requests it.
  • A single per-user preference: whether search results open in the same browser tab or a new one, tied to your Atlassian account ID.
  • A per-user request timestamp. To guard against runaway usage, the app records when you last generated a query and briefly declines a repeat request sent less than a few seconds later. Only that one timestamp is kept, and it's overwritten the next time you use the app.
  • Admin-permission checks. When a site admin refreshes the field cache, the app checks — in real time, acting as that specific person rather than as the app — whether they hold Jira's "Administer Jira" permission. This check isn't stored anywhere.

02 What is sent to the AI model, and why

Only your typed request (capped at 500 characters) is sent to the model, along with your site's own custom field names and IDs — never field values or issue content. This is what lets the model recognize a field like "Story Points" by name instead of guessing at it.

The model call runs entirely through Atlassian's own Forge LLM API, hosted inside the Forge platform itself. This app doesn't hold a separate API key or vendor relationship for it — there's no third-party AI vendor your data passes through outside of Atlassian's own infrastructure.

03 What we don't do

  • We don't collect or store your Atlassian password, API tokens, or any other authentication credentials.
  • We don't use any AI provider other than Atlassian's own Forge-hosted models — your data never leaves Atlassian's ecosystem to reach a third party.
  • We don't run any tracking, analytics, or advertising scripts. The app has no code outside what Jira itself renders inside your site.
  • We don't share, sell, or otherwise disclose any data to third parties.
  • We don't let data cached for one Jira site be read by a different site — each installation's cached data is isolated to that site.
  • We don't retain the text of your requests or the JQL generated from them beyond the single request that produced them.

04 Where data is stored, and for how long

Everything is stored using Forge's own per-installation storage — never a database this app operates itself.

WhatRetention
Your site's custom-field names/IDs (cached to speed up repeat conversions)Refreshed daily; deleted immediately if the app is uninstalled
Your "open results in new tab" preferenceKept until you change it or the app is uninstalled
Your last-request timestamp (for pacing repeat requests)A few seconds — overwritten the next time you use the app

If a site admin uninstalls TextToJQL, the app automatically deletes that site's cached field mapping and every user's saved preference as part of the uninstall process. Nothing is retained after uninstall.

05 Your rights

Depending on where you're located, you may have rights to access, correct, or delete personal data we process. Given how little the app stores — a field-name cache and two small per-user values, all deleted automatically on uninstall — most requests can be satisfied simply by uninstalling the app. For anything else, or if you'd like confirmation of what's currently held for your site, contact us below.

06 Contact

Clipper IT Services Ltd
Email: privacy@clipperitservices.co.uk

This policy may be updated from time to time; the date at the top reflects the most recent revision.