Permissions & Privacy Policy
Jira for Chrome • Last updated: October 2026
This policy covers both the Jira for Chrome browser extension and this website: what each one accesses, how that information is handled, and how it is protected — from Atlassian Jira APIs to the support form below.
Disclosure
Use of information received from Atlassian Jira APIs will adhere to the Atlassian Developer Terms and Google Chrome Web Store Developer Program Policies, including the Limited Use requirements.
Authentication & Data Flows
-
OAuth 2.0 (3LO) Authentication: This extension authenticates via Atlassian's official OAuth 2.0 (3LO) authorization protocol using
chrome.identity.launchWebAuthFlow. The extension never handles, prompts for, or stores your Atlassian password. -
Secure Token Proxy: Authorization code exchanges and token refreshes are routed through a dedicated, stateless serverless proxy (
https://jira-for-chrome.vercel.app/api/token) where OAuth client secrets are injected server-side. The proxy does not log or persist user tokens. -
Local Storage (chrome.storage.local): Access tokens, refresh tokens, active filters, and recent issue previews are cached locally in your browser's
chrome.storage.localto enable instantaneous 1-second load times. All local data can be cleared at any time by logging out or uninstalling the extension. -
Direct Jira API Communication: Issue details, filters, and user profile data are fetched directly from Atlassian's REST APIs (
https://api.atlassian.com/*). Your Jira content is never transmitted to or stored on third-party servers. -
Background Toolbar Badge Sync: When the toolbar badge is enabled, the background service worker uses Chrome's
alarmspermission to periodically query Atlassian's lightweight approximate count endpoint (POST /rest/api/3/search/approximate-count) for your active Jira filter. All requested OAuth scopes (read:issue:jira,read:me,offline_access, etc.) are strictly scoped to retrieving issue summaries and counts requested by your selected filter. All issue previews remain exclusively in local browser storage (chrome.storage.local). - Anonymous Telemetry & Diagnostics: Anonymous crash and performance telemetry is collected via Sentry strictly to optimize extension reliability. Telemetry never includes Jira ticket content, passwords, or personal credentials.
This Website & Support Form
-
Google Analytics 4: This website uses Google Analytics 4 (measurement ID
G-D8343NBF7J) to count page views and Chrome Web Store link clicks. Website analytics are separate from the extension, contain no Jira data, and are governed by Google's Privacy Policy. - Support Form: The support form collects your name, email, and message and forwards them by email to the developer solely to answer your inquiry. Messages are not stored in a database.
Permissions
The permissions you agree to when installing the extension (such as storage, identity, and alarms) are the minimum requirements necessary for the extension to perform its core functions.
Questions or Security Vetting?
Reach out directly if you have specific compliance or permission questions.