Privacy Policy — Intercom Attachment Sync for Jira

Last updated: 6 August 2026

Provider: IDEAL WORKS (Japan)

Contact: support@conduitworks.dev


1. Scope of This Policy

This Privacy Policy describes how the Atlassian Forge app **Intercom Attachment Sync for

Jira** (the "App"), published by IDEAL WORKS (the "Provider", "we", "us"), handles data.

The App links Intercom customer support conversations to Jira issues and synchronises

attachments from Intercom — for example screenshots, images, and videos sent by end

customers — into the linked Jira issue as native Jira attachments.

The App is built on the Atlassian Forge platform and runs entirely on Atlassian's

infrastructure. The Provider does not operate its own servers, databases, or hosting

environment for the App.

This policy covers only the App. It does not cover Atlassian's own products and services,

Intercom's services, or any other software you use.


2. Data the App Stores

The App stores the following in Forge key-value storage, within the Atlassian environment

associated with your Jira Cloud site.

DataPurposeStorage
Intercom access tokenAuthenticating API calls to IntercomEncrypted (kvs.setSecret)
Intercom client secretVerifying that incoming webhooks really come from IntercomEncrypted (kvs.setSecret)
Jira issue key ↔ Intercom conversation ID mappingDetermining which issue an attachment belongs to (stored in both directions)Forge app storage
Synchronisation recordsShowing sync status in the issue panel and supporting troubleshootingForge app storage

Synchronisation records contain, for the most recent sync of each issue:

Two consequences are worth stating plainly:

Data in transit

When a synchronisation runs, attachment content and the conversation data needed to locate

it pass through the App's execution context in memory only. This content is not written

to the App's storage and does not persist after the operation completes.

The issue panel reads Intercom on every view

Separately from synchronisation, the Jira issue panel fetches the linked conversation from

Intercom each time the panel is displayed, and shows its state and attachment metadata

(file name, size, content type) to the Jira user viewing the issue. This metadata is not

stored, but it is visible to any Jira user who can view that issue.

Webhook endpoint

The App exposes a Forge web trigger URL that receives notification payloads from Intercom.

This URL is reachable without authentication, so every payload is verified by HMAC-SHA1

signature before anything else happens (see §4). Verified payloads are parsed in memory to

extract the conversation ID and are then discarded — only the conversation ID and the linked

Jira issue key are passed to the App's internal queue.

Jira permissions requested

The App requests these Jira scopes and no others:

The App does not request Jira administrator permissions, nor permission to modify

project configuration.

External endpoints

The App communicates only with the following hosts, as declared in its Forge manifest:


3. Data the App Does Not Store

The App does not transmit any of this data to the Provider, and the Provider has no facility

to receive it.


4. Where Data Is Stored and How It Is Protected


5. Disclosure to Third Parties

The App transfers data only between the two services it exists to connect:

The App sends no data to the Provider, to analytics or advertising services, or to any other

third party. We do not sell, rent, or trade any data.

We may disclose information only where required by applicable law. Because the Provider has

no access to data stored by the App, such a request would in practice need to be directed to

Atlassian or Intercom as the parties actually holding the data.


6. Data Retention and Deletion


7. Role Under the GDPR

The App is designed to minimise processing: it stores no attachment content and no

conversation bodies, and the Provider has no access to data held in your Forge storage.

Data subject requests. Because the Provider holds no customer data, requests from data

subjects (access, erasure, rectification, restriction, portability, or objection) should be

directed to you as the controller and fulfilled within Jira and Intercom. We will provide

reasonable assistance if you contact us at support@conduitworks.dev.

International transfers. Where App data is stored is determined by the Atlassian Forge

platform and your Jira Cloud site's configuration. Attachment retrieval involves connections

to the Intercom endpoints listed in §2.


8. Sub-processors

Sub-processorRole
Atlassian Pty LtdHosts the App and stores all App data (Atlassian Forge, Jira Cloud)
Intercom, Inc.Source system for conversations and attachments, accessed with the credentials you supply

Both are services you already have a relationship with as a condition of using the App. We

will update this section if any additional sub-processor is introduced.


9. Changes to This Policy

If this policy changes materially, we will update the "Last updated" date above and publish

the revised policy at the URL listed on the App's Atlassian Marketplace listing.


10. Contact

IDEAL WORKS

Email: support@conduitworks.dev