Gitea Integration for Jira

Legal

Privacy policy

Vendor: WEB solutions Ltd / WEB rješenja d.o.o., Markuševečka cesta 115, HR-10000 Zagreb, Croatia. Contact: gitea-jira@wsagency.io. Effective date: 2026-08-31 (takes effect on Marketplace publication).

What data the app stores

Gitea Integration for Jira (“the app”) is an Atlassian Forge app that connects a Jira Cloud site to a customer-operated Gitea instance. All app data is stored per installation in Forge hosted storage (Forge SQL), which is operated by Atlassian and encrypted at rest.

connections
Gitea connection settings, including OAuth client credentials and access/refresh tokens.
repos
Linked repository metadata for display and linking.
webhook_secrets
Webhook HMAC secrets, to verify that webhook calls originate from the customer's Gitea instance.
links
Issue ↔ commit/branch/PR links used by the issue panel and Development panel.
oauth_states
Short-lived OAuth CSRF nonces. Automatically expired and deleted.
webhook_deliveries
Replay markers. Automatically expired and deleted.
webhook_events
Processing verdicts for idempotent webhooks. Age-deleted by a scheduled job.
meta
Per-installation operational flags (schema/version).

Installations that upgraded through app version 0.3.x may also contain orphaned legacy Forge Key-Value entries from before the SQL migration. Nothing reads these entries; they follow the same storage lifecycle as the rest of the app's data.

What data the app transmits

  • From the app (running on Atlassian Forge infrastructure) to the customer's own Gitea instance over HTTPS: API calls to read repositories, commits, branches and pull requests, and to create branches on request.
  • To Jira's own REST APIs: development information (commits, branches, pull requests) pushed to the site's Development panel, and issue comments created via smart-commit commands.

What the app does not do

  • No data is sent to the vendor or any third party. The app runs entirely on Atlassian Forge; there is no vendor-operated backend, no external analytics, and no tracking.
  • The app stores no personal data beyond what the customer's Jira site and Gitea instance already contain (for example commit author names as they appear in Gitea).
  • Secrets (OAuth tokens, webhook secrets) are never written to logs and are never sent to the app frontend.

Data retention and deletion

The app relies on the Forge hosted-storage data lifecycle:

  • Uninstall: data is soft-deleted and then deleted according to Atlassian's Standard Data Retention and Disposal policy (see the Atlassian SOC 2 report).
  • Reinstall: treated as a new installation. If requested within 21 days of uninstallation, Atlassian can relink the new installation to the previous data.
  • License suspension/deactivation (for example a missed payment): the app becomes inactive but stored data is kept unchanged until the license is resolved.
  • Site deletion: app data is deleted together with the site after the site's soft-delete period.

See the data retention statement for the full table.

Changes to this policy

Material changes are announced on the Marketplace listing. The policy history is versioned in the app's source repository.

WEB rješenja d.o.o. · gitea-jira@wsagency.io