CRA Reporting Copilot / Privacy policy
Last updated: 20 July 2026
This Privacy Policy explains how the Atlassian Forge app CRA Reporting Copilot (the "App"), provided by Kazunari Itagaki, handles data. The App is a compliance-support tool that assists manufacturers in meeting the reporting obligations under Article 14 of Regulation (EU) 2024/2847 (the Cyber Resilience Act, "CRA"). It is not legal advice, and the customer (the manufacturer) remains solely responsible for determining whether and when to report, for preparing submissions, and for meeting statutory deadlines.
The App runs entirely on the Atlassian Forge platform inside your own Atlassian Cloud tenant. As a result:
The App requests only the following Forge scopes, and nothing more:
read:jira-work — read-only access to Jira work items so the App can analyze product/asset information relevant to CRA reporting. The App does not modify your Jira data through this scope.storage:app — the App's own storage area inside your Atlassian tenant, used to hold the App's working data, classification results, drafts, and usage metrics.The App does not request access to user account credentials, email contents, billing information, or any scope beyond the two listed above.
Reference datasets used for analysis (for example, a Known Exploited Vulnerabilities / "KEV"-type catalog) are shipped inside the App as a static snapshot. The App does not make any live external connection to fetch or refresh this data. Because the snapshot is fixed at the time of each App release, it may not reflect the most current published state of the source; the snapshot's as-of date is always shown in the App so its freshness is never overstated.
Any usage measurement the App performs (for example, counts of analyses run, feature usage, or error events) is written only to storage:app inside your Atlassian tenant. Metrics are not transmitted to us or to any external analytics provider. We do not have a mechanism to read your in-tenant metrics remotely.
** Separately from in-App metrics: as an Atlassian Marketplace vendor, the Provider receives from Atlassian** certain Marketplace-level information about installations and licenses (e.g., licensing/transaction reports used for billing and support). That information originates in Atlassian's Marketplace systems, not inside your tenant, and does not include your Jira content or the App's in-tenant metrics.
storage:app for as long as the App is installed, or until you delete it, whichever is earlier.storage:app becomes immediately unavailable to the App — a reinstall does not automatically restore prior data; it starts empty. At the Atlassian platform level, the data is soft-deleted and retained for 28 days, after which it is disposed of under Atlassian's data retention and disposal policy. Recovery of the prior data is possible only via a manual Atlassian support request to re-link the data to a reinstalled App, submitted within 21 days of uninstallation and with the customer's consent; if no such request is made within that window, the data cannot be recovered. (The 28-day platform retention window and the 21-day deadline to *request* re-linking are two distinct periods.)We do not sell, rent, or share your data, and we do not use it for advertising. Because the App does not transmit your data out of your tenant, there is no data for us to sell or share.
Because processing occurs inside your Atlassian tenant, you (the customer) act as the controller of any personal data contained in your Jira work items that the App reads. The App is a tool operating within your environment rather than a service to which you transfer data.
When you contact support, information you choose to share with us (e.g., screenshots, exported files, log excerpts) may contain personal data. We process such information solely to handle your support request, and delete it after 90 days after the request is resolved. This is separate from in-product processing, in which we do not receive your tenant content.
Questions about this Policy: support@complydraft.com.
We may update this Policy when the App changes. Material changes will be reflected in the version and date above.
---