Security
NPRecycle is designed so that your data never leaves Atlassian's cloud, and so that it collects as little as possible.
Where your data lives
NPRecycle is an Atlassian Forge app. Forge apps run on Atlassian's infrastructure, and NPRecycle stores everything in Forge-hosted storage for your site:
| What | Where |
|---|---|
| Snapshots of work items (fields, links, attachment details), comments and worklogs | Forge SQL (compressed) |
| Copies of attachment files | Forge Object Store |
| Settings, restore reports, activity log | Forge SQL |
NPRecycle sends no data outside Atlassian. All of its requests go to the Jira REST API and to Forge storage. NPDesigned LLC doesn't run servers that receive your data.
What is stored, and for how long
- Live work items are kept while they exist.
- Deleted work items are kept for the retention period your administrator sets (7 to 180 days, 90 by default), then removed for good, together with their attachment copies.
- Attachment copies are kept within a storage budget your administrator sets (1 to 100 GB). The oldest copies are removed first. Files over the per-file limit (up to 100 MB) aren't copied.
- When NPRecycle is uninstalled, Atlassian deletes the app's stored data according to its data retention policy for Forge-hosted storage.
Personal data
- Account ids only. NPRecycle stores Atlassian account ids, never names, email addresses or time zones. It strips those from every user record before storing it, and looks names up from Jira when it needs to show one. A closed account therefore appears as "a former user".
- Work item content. Restoring a work item requires keeping its content (descriptions, comments, attachments). That content may contain whatever your team wrote in it.
See the privacy policy and the data processing addendum.
Access control
- NPRecycle's pages are a Jira administration page, visible only to Jira administrators.
- Every server-side action checks again that the person has Jira's Administer permission before it runs.
- Restores run as the app. Each restore is recorded with the account id of the administrator who started it.
Permissions NPRecycle asks for
| Scope | Why |
|---|---|
read:jira-work |
Read work items, comments, worklogs and attachments so they can be captured before deletion, receive change events, and check administrator permission |
write:jira-work |
Restore: create work items and sub-tasks, set fields and status, re-post comments, worklogs and attachments, and rebuild links |
read:jira-user |
Look up display names when they're shown, instead of storing them |
storage:app |
Use Forge-hosted storage |
Logs
NPRecycle's operational logs are designed to contain technical identifiers (work item ids and keys, account ids) and error messages, not work item content. An optional troubleshooting mode stores event details inside your site, with names and email addresses removed. It's off by default.
Reporting a vulnerability
Email security@npdesigned.com with a description and steps to reproduce. We'll acknowledge your report within 3 business days and keep you updated while we investigate. Please give us a reasonable chance to fix the issue before disclosing it publicly, and don't access or change data that isn't yours while testing.