ReplyTurn

Privacy Policy

How ReplyTurn processes and protects information inside Atlassian Cloud.

Effective and last updated: 4 September 2026

1. Scope and provider

This policy applies to ReplyTurn, provided by Sovereign World Labs. Privacy questions and data-subject requests can be sent to support@sovereignworldlabs.com.

2. Architecture

ReplyTurn runs entirely on Atlassian Forge. It has no external backend, Remote, advertising, external analytics, tracking pixels, or external customer-data egress. Atlassian provides the hosting, platform, and Marketplace billing infrastructure.

3. Data processed

ReplyTurn reads Jira request identifiers, project type, creation and update timestamps, request/channel markers, public or private comment flags, comment identifiers, author account identifiers, service-agent authorization data, and limited issue metadata such as summary, project, assignee, and priority.

Atlassian comment APIs may return comment bodies even though ReplyTurn needs only metadata. Bodies exist transiently in Forge function memory and are immediately discarded. They are not persisted, logged, analyzed, or displayed by ReplyTurn.

4. Data stored

Jira stores four app-owned read-only fields: Reply State, Waiting Since, Last Customer Reply, and Last Agent Reply. Forge hosted storage contains derived per-request state, update timestamps, installed field IDs, machine-safe diagnostics, and onboarding progress and deduplication records.

ReplyTurn does not persist comment text, descriptions, email addresses, display names, attachments, participant lists, authentication credentials, or payment data.

5. Purpose and control

Processing is limited to classifying public request conversations, showing whose turn it is, supporting Jira queues and JQL, onboarding active requests, diagnosing failures safely, and maintaining idempotent event handling. The customer controls its Jira data and determines its lawful basis for using the app.

6. Hosting and sharing

Compute and persistence use Atlassian-hosted Forge and Jira services. ReplyTurn does not sell personal data, use it for advertising, or send it to Provider-operated or third-party external systems. Hosting location follows the customer’s applicable Atlassian Cloud and Forge data-residency configuration.

7. Retention and deletion

  • Deduplication markers expire after 30 days.
  • Derived per-request records and code-only diagnostics have a rolling 90-day upper bound and are removed earlier when an issue-deleted event is received.
  • Jira field data follows the Jira issue lifecycle.
  • After uninstall, Atlassian currently retains Forge hosted storage for 28 days; recovery must be requested within Atlassian’s recovery window.

A fresh installation reconstructs active request state from Jira. Authorized access, correction, export, or deletion requests can be sent to the privacy contact above.

8. Security and logs

ReplyTurn uses tenant-isolated Forge storage and least-privilege Jira scopes. Application logs exclude comment bodies, descriptions, email addresses, display names, account identifiers, complete event payloads, and REST response bodies. Operational failures use request identifiers and machine-safe error codes.

9. Sensitive data and children

ReplyTurn is a business productivity app, is not directed to children, and does not intentionally collect special-category or sensitive personal data. Customers should avoid placing unnecessary sensitive information in Jira fields.

10. Changes

Material changes will be published on this page with a revised effective date. Security reports should use security@sovereignworldlabs.com.