Privacy policy
Sync Sentinel for GitHub & Jira ("Sync Sentinel", "the app") is published by Elektraset, s.r.o. ("we", "us"). This policy explains which data the app processes and how. Last updated: 9 October 2026.
Summary
- Sync Sentinel is an Atlassian Forge app. It runs on Atlassian's cloud platform inside your Jira Cloud site.
- The data that the app processes is stored in your site's Forge app storage, hosted by Atlassian. Elektraset does not receive, copy or store your Jira or GitHub data on its own servers.
- The app contacts only two outside services, and only for the purposes below: the GitHub REST API (
api.github.com) and, if you turn on Slack alerts, your Slack incoming webhook (hooks.slack.com).
Data that the app processes
| Data | Source | Purpose | Where it is stored |
|---|---|---|---|
| GitHub artifact metadata: commit SHA, first 1,000 characters of the commit message, branch names, pull request numbers, titles and states, deployment IDs, environments and states, author logins or names, URLs and timestamps | GitHub webhooks and the GitHub REST API, for the repositories that an administrator selects | Sync ledger, reconciliation, diagnoses and replay | Forge app storage of your site |
| Jira issue keys, issue summaries and the counts of the Jira Development field | Jira REST API | Comparing what GitHub has with what Jira shows | Forge app storage of your site |
| Webhook delivery log: delivery ID, event name, time, result | GitHub webhook deliveries | Webhook health checks | Forge app storage, deleted after 14 days |
| Audit log: time, Atlassian account ID of the administrator, action | Actions in the app | Change-management records | Forge app storage of your site |
| Credentials: GitHub App private key or GitHub token, webhook secret, Slack webhook URL, report link token | Entered by an administrator or created by the app | Connecting to GitHub and Slack | Encrypted Forge secret storage of your site |
| Alert recipients: Atlassian account IDs and group IDs | Chosen by an administrator | E-mail alerts through Jira notifications | Forge app storage of your site |
The app does not process source code or file contents, and it does not use cookies or tracking in Jira.
Data sent to third parties
- GitHub (GitHub, Inc.): the app sends authenticated read-only API requests for the selected repositories. GitHub's privacy statement applies to GitHub.
- Slack (optional): alert texts (counts and problem titles, no source code) are sent to the Slack incoming webhook that an administrator enters.
- Atlassian: as the hosting platform (Forge), and for e-mail alerts, which Jira sends as issue notifications. When an administrator runs a replay with "Publish missing artifacts to Jira", the app writes the artifact metadata above to Jira's development information store of your site.
We do not sell data and we do not use it for advertising or for training AI models.
Retention and deletion
- Webhook delivery logs are deleted after 14 days.
- An administrator can delete the GitHub credentials and the whole ledger at any time with Connection > Disconnect and delete ledger.
- When the app is uninstalled, Atlassian deletes the app's Forge storage and the development information that the app published, according to Atlassian's Forge data retention rules.
Website
The website https://sync-sentinel.apps.elektraset.com shows the product, documentation and legal pages. It does not use cookies or analytics. The hosting server keeps standard technical access logs (IP address, time, requested page) for up to 30 days for security.
Your rights
Under the GDPR you have the right to access, correct, delete or restrict the processing of personal data, and to complain to a supervisory authority (in the Czech Republic: Úřad pro ochranu osobních údajů). Because the app's data stays in your Atlassian site, most requests are handled by your Jira administrator; we will help. For data that the app processes in your site, your organization is the controller and Atlassian acts as hosting processor.
Security
Requests to GitHub use HTTPS and least-privilege, read-only permissions. Webhook deliveries are verified with HMAC-SHA256 signatures. Secrets are kept in Forge's encrypted secret storage and are never shown in logs. Only Jira administrators can open the app's settings.
Contact
Elektraset, s.r.o. · https://elektraset.com/ · help@elektraset.com