Privacy Policy
This policy explains what data the MarginRadar app for Jira Cloud processes, where it lives, why, and what you can do about it.
Draft of 9 October 2026. Legal review pending.
Draft pending legal review. The description of what the app stores and does was checked against the app's source code. Legal wording may still change before the app is listed publicly.
Summary
- MarginRadar is a Forge app that Runs on Atlassian. All app data is stored in Atlassian's Forge hosted storage (Forge SQL and Key-Value Store), and it follows your Jira site's data residency.
- MarginRadar makes no calls to servers outside Atlassian, and Radrly receives none of your Jira data.
- Atlassian is the only sub-processor (hosting). No external AI or LLM service is used.
- You can delete MarginRadar data in the app at any time.
- Radrly acts as a data processor for the personal data in the app, and your organisation is the controller.
Who we are
MarginRadar is developed and operated by Radrly Sp. z o.o., a company established in Poland (“Radrly”, “we”). Registered office: ul. Tarczyńska 68, 05-831 Krakowiany, Poland. KRS 0001215510, NIP 5342706013, REGON 543658680.
This policy covers the MarginRadar app. “Customer” means the organisation that installs MarginRadar on its Jira Cloud site. “Users” means the people in the Customer's Jira site.
Data we process
MarginRadar processes only the data needed to calculate cost, revenue, margin and budget forecasts.
| Data | Examples | Purpose |
|---|---|---|
| Atlassian account IDs | The ID of a worklog author, a person with a rate, a role or an audit-log entry | Attribute worklogs, rates, roles and changes to the right person |
| Worklog-derived data | Issue key, date, hours, calculated cost and billable value | Calculate cost, revenue, margin, burn rate and forecasts |
| Rates and rate assignments | Cost and billable rates by role, user or project, with effective dates | Price worklogs |
| Budgets and settings | Budget amounts or hours, periods, thresholds, revenue model, issue and project keys, the alert work item, client names, the display currency and the exchange rate you enter | Budget tracking and alerts |
| Roles and audit log | Finance / PM / Viewer assignments; who (account ID) changed which budget, rate, role or setting and when, with the values before and after | Role-based visibility and accountability |
Account IDs are the only user identifiers we store. Names and email addresses are not stored by the app. User names are read from Jira (read:jira-user) only to show people in rate cards and roles. The app does not store worklog comments, issue summaries, issue descriptions or attachments.
We do not use this data for advertising, profiling or sale, and we do not combine it with other data.
Where data is stored
All MarginRadar data is stored in Atlassian Forge hosted storage: Forge SQL and the Forge Key-Value Store, on Atlassian's infrastructure. MarginRadar stores no End-User Data outside Atlassian products and services, and does not process it outside Atlassian or the user's browser.
Data residency. Forge SQL and Key-Value Store support data residency. The app's data is kept in the location chosen for your Jira site and moves with it if you migrate between residency locations. Radrly does not run any servers that hold your data.
No egress, no sub-processors
MarginRadar declares no remote hosts, uses no Forge Remote and no Connect, and does not call external APIs. It exposes no public REST API of its own; the Rovo actions and Rovo MCP tools are Forge modules that run inside Atlassian.
We do not share End-User Data with third parties. Atlassian provides the hosting platform (Forge, Jira and Rovo) under its own terms and, for GDPR purposes, is a sub-processor. Other than Atlassian, we use no sub-processors.
AI and Rovo
MarginRadar does not call any external AI or LLM service. The optional MarginRadar Rovo agent (Advanced edition) runs inside Atlassian Rovo. Rovo's processing is provided by Atlassian under Atlassian's terms and AI trust policies, and the agent's actions read MarginRadar data inside Forge. Nothing is sent by MarginRadar to third-party AI services.
The same four actions are also published as Rovo MCP tools. If your organisation lets people connect an MCP client (for example an AI assistant) to Atlassian, that client can call these tools with the person's own permissions, and the results are returned to that client. That is your organisation's choice and is governed by your agreement with Atlassian and with that client's provider, not by MarginRadar. The tools respect the person's MarginRadar role.
Permissions (scopes)
Jira asks you to approve the following scopes when the app is installed. No other scopes are requested.
| Scope | Why MarginRadar needs it |
|---|---|
read:jira-work | Read projects, issues, epics and worklogs, and receive worklog created, updated and deleted events, to calculate cost, revenue, margin and budget usage. |
write:jira-work | Used only to post budget alert comments on issues and epics (Advanced). A comment is only posted on the alert work item you choose for a project budget, or on the epic of an epic budget. MarginRadar never edits issues, fields or worklogs. |
read:jira-user | Read user names and roles so that people can be identified in rate cards and role assignments. User names are shown in the interface and not stored. |
storage:app | Store the app's data (budgets, rates, roles, audit log, calculated figures) in Forge hosted storage. |
Retention and deletion
- While installed: data is kept for as long as the app is installed, so that history and forecasts remain available. Worklog data follows your Jira data; deleting or changing a worklog in Jira updates MarginRadar.
- In-app deletion: admins can delete MarginRadar data in the app at any time. Finance users can delete a single project's data or all MarginRadar data. The app has no setting for a custom retention period.
- After uninstall: the Forge platform soft-deletes the app's data and destroys it at the end of the retention period described in Atlassian's SOC 2 report. A reinstall within 21 days can be relinked to the old data. This period is set by Atlassian. Radrly itself keeps no copy.
Logs
The app writes very little to the Forge developer console: the status of database schema migrations and error messages. The code does not log account IDs, worklog data or comments. Logs stay in Atlassian's environment.
GDPR
Roles. For the personal data in MarginRadar (account IDs, worklog-derived time, cost and billable values, user rate assignments and audit-log entries), the Customer is the controller and Radrly is a processor acting on the Customer's documented instructions. A Data Processing Agreement is available.
Legal basis. The Customer decides the legal basis for tracking time and cost of its personnel (for example legitimate interests or contract). Radrly does not decide the purposes of the processing.
Your rights. If you are a person whose data is in a Customer's MarginRadar, you have rights of access, rectification, erasure, restriction, portability and objection under the GDPR. Please contact the organisation that runs your Jira site first. We will support the Customer in answering such requests. You also have the right to complain to a supervisory authority (in Poland: the President of the Personal Data Protection Office, UODO).
Security. See Security.
International transfers
Radrly does not transfer data itself. Data is hosted by Atlassian in the location set by the Customer's data residency choice, and Atlassian's own transfer mechanisms apply.
CCPA
Radrly does not sell personal information. Radrly is an EU company; any California consumer personal information processed through the app is handled only within Atlassian's platform under Atlassian's terms.
This website
This site is static. It uses no cookies, no analytics, no trackers and no third-party scripts, fonts or CDNs. Our web server keeps standard access logs (IP address, time, requested page) for security and operations. The logs are rotated daily and kept for 14 days.
Changes
We will update this page when the app's data handling changes and show the date of the latest update at the top. For material changes we will notify customers, for example through Atlassian Marketplace.
Contact
Privacy questions and data requests: support@radrly.com. Security contact: security@radrly.com. We have not appointed a Data Protection Officer; privacy questions go to the contact above.