Legal
Sprint Reality — Privacy & Data Handling
Last updated: July 2026
This page describes how the Sprint Reality app for Atlassian Jira handles data. It supplements the HelpingBrains Privacy Policy and is intended as the data-handling reference for the Sprint Reality Marketplace listing.
In short: Sprint Reality reads your Jira data live to compute delivery signals. It does not keep copies of your Jira issue content. It persists only configuration, derived aggregates, and audit records inside Atlassian Forge Storage.
1. What Sprint Reality does
Sprint Reality is a Forge app that runs on Atlassian infrastructure. It reads sprint, issue, and board data from your Jira site in real time, computes delivery-intelligence signals (health scores, Go/No-Go verdicts, dependency and capacity insights), and displays them inside Jira. Computation happens on demand; the app persists only the minimum needed to function between runs.
2. What we do NOT store
Sprint Reality does not store copies of your Jira issue content. In particular, we do not persist issue descriptions, comment bodies, or other free-text issue content. Those are read live from Jira at compute time and are not retained in our storage.
3. What we store (in Atlassian Forge Storage)
We persist the following inside Forge Storage, which runs on Atlassian’s infrastructure:
- Configuration: app settings, thresholds, board/project selections, and integration configuration.
- Derived data: computed aggregates, health/credit scores, and historical baselines used for trends and comparisons.
- Audit records: records of significant actions and changes for accountability.
- Personal data: Atlassian account IDs, display names, availability/PTO information, and email addresses used for team, capacity, and digest features.
- Secrets: integration credentials such as webhook URLs and API keys (for example an Anthropic API key), stored securely in Forge Storage and never exposed in the UI.
4. Processing roles
Your organization is the data controller for the personal data processed by Sprint Reality; HelpingBrains acts as a data processor on your behalf. Because Sprint Reality processes personal data, a Data Processing Agreement (DPA) applies and is available on request at privacy@helpingbrains.info.
5. Data that leaves Atlassian (optional integrations)
By default, Sprint Reality operates entirely within Atlassian. Data leaves the Atlassian environment only when an administrator explicitly enables an optional integration. When enabled, the following third-party sub-processors may receive data:
- Slack: digest delivery — sends digest content, which may include issue keys and summaries, to your configured Slack workspace.
- Microsoft Teams: digest delivery — sends digest content, which may include issue keys and summaries, to your configured Teams channel.
- Resend (email): email digest delivery — sends digest content and recipient email addresses to deliver scheduled email digests.
- Anthropic: AI Delivery Advisor — off by default, active only when an admin sets an Anthropic API key. Sends the app’s computed findings to the Anthropic API to be rephrased into a narrative. It does not send raw Jira issue content.
6. AI Advisor details
The AI Delivery Advisor is optional and disabled unless an administrator provides an Anthropic API key (ANTHROPIC_API_KEY). When enabled, only the computed findings and metrics produced by Sprint Reality are sent to the Anthropic API for narrative generation; no issue descriptions or comment bodies are transmitted. The feature is read-only and does not modify your Jira data.
7. Permissions and scopes
Sprint Reality requests the minimum Jira scopes required to read the sprint, issue, and board data needed for its computations, plus storage scopes to persist the configuration and derived data described above. It does not request write access to modify your issues for its core analytics.
8. Data residency and security
Configuration and derived data are stored in Atlassian Forge Storage and inherit Atlassian’s platform security and residency model. Secrets are stored securely and access follows least-privilege principles. Data sent to enabled integrations is transmitted over encrypted connections.
9. Retention and deletion
We retain configuration, derived data, and audit records for as long as the app is installed and needed to provide the service. When you uninstall Sprint Reality, associated app data in Forge Storage is removed in accordance with the Atlassian Forge lifecycle. You may also request deletion of specific data by contacting us.
10. Your rights and contact
Data-subject rights are handled through your organization as controller and, where applicable, directly by HelpingBrains as processor. For privacy questions, DPA requests, or to exercise rights relating to Sprint Reality, contact privacy@helpingbrains.info. This page supplements the HelpingBrains Privacy Policy.
