Sync Sentinel

Privacy policy

Sync Sentinel for GitHub & Jira ("Sync Sentinel", "the app") is published by Elektraset, s.r.o. ("we", "us"). This policy explains which data the app processes and how. Last updated: 9 October 2026.

Summary

Data that the app processes

DataSourcePurposeWhere it is stored
GitHub artifact metadata: commit SHA, first 1,000 characters of the commit message, branch names, pull request numbers, titles and states, deployment IDs, environments and states, author logins or names, URLs and timestampsGitHub webhooks and the GitHub REST API, for the repositories that an administrator selectsSync ledger, reconciliation, diagnoses and replayForge app storage of your site
Jira issue keys, issue summaries and the counts of the Jira Development fieldJira REST APIComparing what GitHub has with what Jira showsForge app storage of your site
Webhook delivery log: delivery ID, event name, time, resultGitHub webhook deliveriesWebhook health checksForge app storage, deleted after 14 days
Audit log: time, Atlassian account ID of the administrator, actionActions in the appChange-management recordsForge app storage of your site
Credentials: GitHub App private key or GitHub token, webhook secret, Slack webhook URL, report link tokenEntered by an administrator or created by the appConnecting to GitHub and SlackEncrypted Forge secret storage of your site
Alert recipients: Atlassian account IDs and group IDsChosen by an administratorE-mail alerts through Jira notificationsForge app storage of your site

The app does not process source code or file contents, and it does not use cookies or tracking in Jira.

Data sent to third parties

We do not sell data and we do not use it for advertising or for training AI models.

Retention and deletion

Website

The website https://sync-sentinel.apps.elektraset.com shows the product, documentation and legal pages. It does not use cookies or analytics. The hosting server keeps standard technical access logs (IP address, time, requested page) for up to 30 days for security.

Your rights

Under the GDPR you have the right to access, correct, delete or restrict the processing of personal data, and to complain to a supervisory authority (in the Czech Republic: Úřad pro ochranu osobních údajů). Because the app's data stays in your Atlassian site, most requests are handled by your Jira administrator; we will help. For data that the app processes in your site, your organization is the controller and Atlassian acts as hosting processor.

Security

Requests to GitHub use HTTPS and least-privilege, read-only permissions. Webhook deliveries are verified with HMAC-SHA256 signatures. Secrets are kept in Forge's encrypted secret storage and are never shown in logs. Only Jira administrators can open the app's settings.

Contact

Elektraset, s.r.o. · https://elektraset.com/ · help@elektraset.com