Wake Privacy and Security
Related policies
Hosting and data flow
Wake is an Atlassian Forge app for Jira Cloud. The reviewed manifest declares no external network egress and no Totesoft-hosted remote backend.
Wake requests Jira data as the current user. Depending on the selected filter and fields, it processes:
- saved-filter identifiers, names, JQL, owner/share metadata, and descriptions;
- Jira field identifiers, names, and schema metadata;
- issue IDs, issue keys, and selected issue-field values;
- helper fields needed for links and display;
- groupings, counts, sums, averages, charts, paging status, and errors; and
- Atlassian installation and license context.
Wake does not intentionally create, update, transition, or delete Jira issues.
Field minimization
Wake requests configured fields plus a small helper set. It does not offer Description, Attachments, Comments, Worklogs, and similar heavy fields as gadget columns.
Configuration and storage
The active gadget UI submits its configuration through Atlassian's dashboard gadget configuration mechanism. Any Forge hosted storage used by the app is retained within Atlassian's platform under the customer's Atlassian relationship.
Logs
Authorized Totesoft personnel with access to the Forge app environments can access Forge application logs for support, security, and operations.
Logs can include limited diagnostic data such as issue keys, filter identifiers, JQL text, and truncated Jira error responses. This diagnostic content is used for support, security, and operations, and is retained within Atlassian's Forge platform. See the Wake App Privacy Notice for details on logging and retention.
CSV files
Paid/trial CSV files are created from loaded issues in the user's browser and downloaded directly to the device. They are not sent to a Totesoft server. The customer controls the downloaded file after creation.
External sharing
The reviewed implementation does not send Jira data to third-party analytics, advertising, monitoring, or AI services. Atlassian provides Jira Cloud, Forge execution, Marketplace licensing context, Forge logs, and any retained Forge hosted storage.
Security controls
- Jira access is performed as the current user.
- Selected fields are minimized.
- Heavy fields are blocked.
- Expected Jira throttling is handled as an operational condition.
- Free caps reduce large-query resource consumption.
- No external egress is declared.
Customer responsibilities
Customers are responsible for:
- controlling dashboard and saved-filter access;
- selecting fields appropriate for dashboard viewers;
- recognizing partial-result warnings;
- protecting downloaded CSV files; and
- independently verifying results used for material decisions.
Security reports
Until Totesoft publishes a dedicated security address, send reports to info@totesoft.com with the subject Wake Security Report. Do not include customer production data or secrets in the initial message.