Privacy

Privacy Policy

Last updated: July 2026

Who we are

EthicGuard ("EthicGuard", "we", "us") provides the EthicGuard app for Atlassian Jira and the website at ethicguard.ai. For the limited data described below, the data controller is EthicGuard, operated by Rostyslav Chabria, Kraków, Poland. For any privacy question or data request, contact admin@ethicguard.ai.

The short version

EthicGuard is a Jira-native QA tool that reviews acceptance criteria for ambiguity, missing edge cases, and untestable assertions. To do that it reads your issue content and sends it to our analysis engine for a single inference call — then discards it. We never store your issue content. The only things we keep are structured coordinates and metadata (anchors, scores, message keys, verdict labels). If you uninstall the app, there is nothing left to recover, because your content was never written to disk.

What we process, and why

When you run a review on an issue — manually from the issue panel, or via the Rovo agent — EthicGuard assembles a normalized payload (the issue summary, description, acceptance-criteria field, and anchors to linked issues) and sends it to the EthicGuard backend, which runs the AI analysis. The payload exists in memory for the duration of that one call and is then discarded. We process this data solely to produce the QA findings and verdict you asked for.

What we store vs. never store

We store

  • • Issue keys and numeric ids
  • • Span anchors — { field, start, end } coordinates, never the text they point at
  • • Severity, score, and stable message keys (resolved from a static catalog)
  • • Per-installation configuration (chosen issue types, defect types, settings)
  • • Audit metadata — who ran an analysis, when, and the resulting verdict label

We never store

  • • Issue titles and summaries
  • • Descriptions and acceptance-criteria text
  • • Comments and attachments
  • • Linked-issue body text
  • • AI prompts built from any of the above, or AI responses that quote them
  • • Any paraphrase or summary that could reconstruct your content

This boundary is enforced in code: the backend's storage layer cannot persist issue text, and an input validator rejects any analysis result that carries free-form message text. Only the stable message key is stored.

Where your data goes (sub-processors)

  • Atlassian (Forge). The app runs on Atlassian Forge inside your Jira Cloud tenant. Reads and writes to Jira happen through Atlassian's APIs under the permissions you grant.
  • EthicGuard backend. Our analysis service receives the normalized issue payload, runs inference, and returns findings. It persists only the structured metadata listed above. Hosted in the EU (Frankfurt).
  • AI provider. Analysis is powered by Atlassian Rovo by default; on an opt-in basis an admin may configure a bring-your-own key for another provider (Anthropic, OpenAI, or Google). The issue payload is sent to the selected provider to generate the review. Network egress is restricted to a fixed allowlist of these hosts.
  • Google Analytics (website only). The marketing site at ethicguard.ai uses Google Analytics 4 for aggregate traffic measurement — see "Website analytics" below. The product does not use it: no Jira content, roast submission, or in-app activity is ever sent to Google Analytics.

Website analytics (ethicguard.ai)

This website uses Google Analytics 4 to understand aggregate traffic: pages visited, referral source, approximate region, and device type. Google Analytics sets cookies to distinguish repeat visits. We use this data solely to measure and improve the site — never for advertising or profiling — and we do not join it with any product data. Your Jira content and anything you paste into the roast tool are never sent to Google Analytics. Google LLC processes this data on our behalf under its privacy policy; you can opt out with a standard content blocker or Google's browser opt-out add-on without affecting anything on the site.

Permissions we request

EthicGuard is an active QA tool, not a read-only viewer. It requests both read and write permissions on Jira so it can stamp verdict labels, provision the EthicGuard Acceptance Criteria field, mount the coverage and defect dashboards, and move unverified stories back to the backlog. Each permission and its justification is listed on the Atlassian Marketplace listing, and every write is scoped to the issue types you select during setup.

Security & isolation

Each installation is cryptographically isolated with a per-install shared secret used to authenticate the app to our backend. Traffic is encrypted in transit. Prompts and issue payloads are never written to logs above debug level. We keep an audit record of each analysis run (actor, time, verdict) — containing metadata only, never issue content.

Retention & deletion

Issue content has no retention period because it is never stored. The structured metadata we keep persists for the life of the installation and is removed when you uninstall the app, which revokes the installation's shared secret and deletes its associated records.

Your rights

Because we do not store personal data or issue content, there is no customer content to export or erase on request beyond uninstalling the app. For any privacy question or data request, contact us below.

Legal basis & GDPR

Where the GDPR applies, we process the limited data described above on the basis of (a) performance of our agreement with you and your organization (to provide the service you requested) and (b) our legitimate interest in operating, securing, and improving the service. We do not sell personal data, and we do not use it for advertising or profiling. If you are in the EEA/UK you have the rights of access, rectification, erasure, restriction, portability, and objection; because we hold almost no personal data and never your issue content, most requests are satisfied by uninstalling the app. To exercise a right, contact us at the address above.

International transfers & sub-processor terms

Our backend is hosted in the EU (Frankfurt). Where data is processed by a sub-processor outside your region (for example an AI provider), that transfer is covered by the provider's standard contractual clauses and data-processing terms. A data processing addendum (DPA) is available on request for organizations that require one.

Children

EthicGuard is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.

Governing law

This policy is governed by the laws of Poland and the applicable laws of the European Union, without prejudice to mandatory consumer protections in your country of residence.

Changes to this policy

If our data handling ever changes, this page and the in-app disclosures change in the same release. The "last updated" date above reflects the current version.

Contact

Questions about this policy or EthicGuard's data handling: admin@ethicguard.ai.