Data & Privacy Statement

This statement covers the Questlog app for Jira Cloud.

Where data is stored

Questlog uses Forge-hosted storage (Forge SQL) within the customer's Atlassian environment. The app does not operate external servers or make external data egress calls.

What is stored

Questlog stores Atlassian account IDs, Jira issue and project IDs, the game actions earned (such as “comment” or “log work”) with timestamps, XP, gold and counts, and game state: characters (the game name and look each player chooses), items, parties and their settings, away days, expedition progress, the daily brew and its tries, toasts, tavern progress, and the Crier feed (which stores account IDs, not names). It also stores the app's rule settings.

What is not stored

Questlog does not store comment text, issue titles or descriptions, attachment names or content, worklog durations or worklog comments, or issue link details. Issue event payloads are trimmed to the fields the game needs before they reach the app. Comment text is read only to check its length and is then discarded, and worklog duration is read only to check the 15-minute minimum.

Who sees what

Personal XP, gold and daily limits are visible only to the player. A player's level is private unless they choose to show it. Members of a party see each other's characters, “away” status (never a reason), brew tries (name and time) and toasts given inside the party. Admins see party totals only, never per-person data. Time logged is never shown anywhere, and shared feeds never show issue keys or titles.

Personal data

Questlog processes Atlassian account IDs. It does not store email addresses, display names or avatars from Atlassian; players choose their own game name. Questlog uses Atlassian's personal data reporting API to check stored accounts at least every 7 days.

Retention

When Atlassian reports an account as closed, Questlog deletes that person's character, items, away days, daily records, unclaimed chests and the Crier lines naming them, and replaces their account ID with a one-way token in remaining party records, so party totals stay intact. Other game data is kept while the app is installed. Uninstalling Questlog removes its Forge-hosted application data.

Access and permissions

Questlog only has read access to Jira (read:jira-work, read:board-scope:jira-software, read:sprint:jira-software, read:issue-details:jira and read:jql:jira) plus report:personal-data. It cannot change issues. All game actions are validated on the server, and the admin settings check the signed-in user's Jira admin permission.

Data sharing

Questlog does not sell or share customer data with third parties.

About this website

This section is about the website questlog.umaylabs.com, not the Questlog app.

The website is static. It uses no analytics and no tracking cookies. It stores only a few things in your browser's localStorage, and they never leave your device: your theme choice (light or dark) and your progress in today's Daily Brew.

Questions

For privacy questions, email contact@umaylabs.com.